This product has charges associated with it for seller support. Elyxia Global Limited offers a pre-configured Matomo 5 image running on AlmaLinux 10. Matomo, formerly Piwik, is the leading open source web analytics platform for organizations that put privacy first: it shows you how visitors find and use your site, and the data stays on your own instance rather than being shared with a third party.
Elyxia Global Limited brings you a fully configured Matomo 5 image on AlmaLinux 10. This ready-to-deploy AMI gives you working analytics in minutes rather than an afternoon spent assembling PHP, a database, a web server and a scheduled processing job.
Matomo shows you how visitors find and use your site, which pages hold their attention, where they leave, and which campaigns actually convert. The difference from hosted analytics is where the data lives: it stays on your own instance, so it is never sold on, never shared with a third party and never used to build a profile of your visitors elsewhere. That is what makes Matomo a practical answer to GDPR and similar obligations rather than a risk to be managed. The AlmaLinux 10 base ensures your system runs on a secure, enterprise-grade Linux distribution known for stability and long-term support.
Whether you are measuring one site or many, Matomo gives you the reports without the trade-off, and its open-source licence means you keep full control of your data with no per-visit fee.
Pre-bundled with this AMI:
Matomo 5.13.0,
AlmaLinux 10,
MariaDB 11.4,
PHP 8.2,
Apache web server,
Caddy reverse proxy,
Docker and Docker Compose
The application runs in containers. Matomo and its database are managed by Docker Compose on the instance, which means application updates can be delivered without replacing the AMI, and the database runs on an isolated internal network with no port exposed to the internet. Your configuration and your downloaded geolocation data are kept in separate storage that an application update does not touch.
Your Matomo is installed and ready when the instance finishes starting. There is no setup wizard to work through. The administrator account is created for you and its password is shown once, in the summary at the end of installation.
A first site is already created, named My website. Rename it to your own site under Administration, Websites, Manage, and Matomo gives you the tracking code to paste into your pages.
The exact Matomo version is fixed in the image. An installation that downloads whatever release is current on the day gives you an instance nobody can describe afterwards. This image names the version, so every instance of a given build is running exactly the same code as every other.
Scheduled report processing is already running. It is what keeps your dashboard fast as traffic grows, it is pointed at your own instance, and it keeps working after you associate a domain name.
Exclusive Fixes and Resolutions by Elyxia Global Limited:
Ready to Use the Moment You Sign In: Matomo is installed, your administrator account exists and your first site is created before you open the page. Matomo publishes no command line installer, so images built the usual way hand you an eight step browser setup wizard instead.
Your Database Is Closed to the Internet: the database runs on a private network inside the instance with no published port. Images built the usual way leave it listening on every network interface, with only a firewall rule between it and the internet.
Report Processing Points at Your Own Site: scheduled report processing runs against your instance and keeps running after you attach your own domain name. Built the usual way, the scheduled job is written with the address of the machine that built the image, which is not yours.
Private Files Stay Private: your configuration file, which holds the database password and the key that signs every sign-in, is refused over the web, along with the cache and internal directories. Only your pages and the tracking endpoint answer.
Attaching Your Domain Does Not Take the Site Down: Matomo refuses any request arriving under a name it has not been told to trust. Our domain tool adds your domain to that list and keeps the internal name, so the site stays reachable and your reports keep processing.
Use your own domain name with a free SSL certificate. One command requests a Let`s Encrypt certificate, renews it automatically, and redirects HTTP to HTTPS.
The instance needs only three inbound ports: 22 for SSH, 80 and 443 for Matomo and certificate issuance. This image does not include a local mail server, so Matomo sends through an SMTP server that you provide, configured under Administration, System, General settings.
Disclaimer: The respective trademarks mentioned in the offering are owned by the respective companies. We do not provide the commercial license of any of these products. Many of the products have a free, demo, or open source license as applicable. Elyxia Global Limited provides image-related support, migration and plugin development, drop us an email at support@elyxia.uk.
Highlights
Full Data Ownership and Privacy: Analytics that answer the same questions as hosted tools, with the data held on your own instance, never shared with a third party and never used to profile your visitors elsewhere. Self-hosted and GDPR-ready.
Five Fixes You Would Otherwise Make Yourself: Matomo already installed with no browser setup wizard, a database closed to the internet, scheduled report processing pointed at your own site, configuration files refused over the web, and a domain tool that does not take the site off the air.
Containerized and Maintainable: Matomo and MariaDB run as Docker containers on AlmaLinux 10, so the database is not exposed to the internet and application updates do not require rebuilding the instance. A Caddy reverse proxy handles HTTPS and your free SSL certificate.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for the EC2 instance type you run this software on. The listing covers hundreds of instance choices across general purpose, compute, memory, storage, GPU, and machine learning families. Larger instances within a family carry a higher hourly rate than smaller ones, so your cost scales with the compute, memory, and hardware you select. There are no tiers or feature levels to choose from. The software is the same across every instance; you pick the size that fits your workload, and billing tracks the hours you use.
Top-of-mind questions for buyers
What does one hourly unit cover, and what software comes bundled on the instance?
One unit is one running EC2 instance-hour for the instance type you select. Each instance runs a pre-built image with the analytics software, a hardened Linux OS, a database engine, PHP, an Apache web server, and firewall management. You pick the instance size; the bundled software is the same everywhere.
Am I charged for the software when my instance is stopped or paused?
Hourly software charges track running time. A fully stopped instance does not accrue the per-hour software fee. Stopped instances may still incur separate AWS storage charges for attached volumes. Billing resumes when you start the instance again.
Can I switch to a different instance type if my workload grows?
Yes. Pricing is not tiered, so no upgrade path is locked in. You choose any listed instance type and pay that type's hourly rate. Moving to a larger instance changes your hourly cost to match the new compute, memory, and hardware. The software stays identical across sizes.
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Release Notes for Containerized Matomo 5 on Alma Linux 10 (EGL Build 260915.1)
This version supersedes the existing EGL Build 260629.1.
What is New:
(NEW) Containerized build on AlmaLinux 10, replacing AlmaLinux 9. Matomo and its database run as containers, so application updates can be delivered without replacing the AMI, and your configuration and downloaded geolocation data are kept in storage that an update does not touch.
(NEW) Matomo is already installed when the instance finishes starting. Your administrator account and your first site are created for you, so there is no browser setup wizard to complete. The previous build delivered the web stack only and left you to work through Matomo's own eight step installer.
(NEW) The exact Matomo version is fixed in the image. The previous build downloaded whatever release was current on the day each instance was launched, so no two instances were alike. Every instance of a given build now runs Matomo 5.13.0.
(NEW) Use your own domain name with a free SSL certificate. Run one command, sudo egl-setup-domain.sh.x, and enter your domain. A free Let's Encrypt certificate is requested automatically and renews itself from then on. No email address is required and no configuration files need editing.
(NEW) Automatic HTTP to HTTPS redirect once a domain is associated, so visitors reach the secure address whichever they type.
(NEW) Reverse proxy included. TLS is handled by a Caddy proxy in front of Matomo, so certificates survive application updates and container restarts instead of needing to be reinstalled.
(FIXED) Scheduled report processing now points at your own instance. The previous build wrote the scheduled job using the public address of the machine that built the image, which is not your address, so the job pointed somewhere else entirely.
(FIXED) Associating a domain no longer risks taking the site off the air. Matomo refuses any request arriving under a name it has not been told to trust, and the domain tool adds your domain to that list. It also keeps the internal name in place, so your report processing continues uninterrupted.
(FIXED) Private files are no longer reachable over the web. Your configuration file, which holds the database password and the key that signs every sign-in, is refused, along with the cache and internal directories. Only your pages and the tracking endpoint answer.
(FIXED) The listing no longer claims a firewall the image does not contain. Firewalld was named as pre-bundled and was not installed.
(IMPROVED) Matomo 5.13.0 on PHP 8.2 and MariaDB 11.4, all pinned in the image.
(IMPROVED) The database is no longer reachable from outside the instance. It runs on an isolated internal network with no published port, and the recommended inbound ports are now only 22, 80 and 443. Port 3306 no longer needs to be open, and neither do ports 465, 587, 993 and 995: Matomo connects out to your mail server and the reply is already permitted.
(IMPROVED) Two mistyped port ranges have been removed from the recommended security group. They opened more than a thousand ports between them.
(IMPROVED) Installation no longer depends on a single image source. If one source is unavailable the installer falls back to others automatically, so a new instance can still be built.
(IMPROVED) Clearer installation messages, including a check that your domain points at the instance before a certificate is requested. This avoids the Let's Encrypt rate limit that follows repeated failed attempts.
(IMPROVED) A first site named My website is created during installation, so Matomo has something to show you and the tracking code is one screen away. Rename it to your own site under Administration, Websites, Manage.
(IMPROVED) Outbound mail is configured in one place. This image does not include a local mail server, so Matomo sends through an SMTP server that you provide, set under Administration, System, General settings.
The installer installs Matomo, creates your administrator account and your first site, and prints the username and password once, at the end. Write the password down before closing the terminal. It is generated for your instance and is not stored anywhere you can read it back.
Open Matomo at http://YOUR-INSTANCE-PUBLIC-IP/ and sign in with those details. You arrive at your dashboard, not at a setup screen, because there is no browser setup wizard to complete.
A site named My website is already created so Matomo has something to show you. Rename it to your own site under Administration, Websites, Manage, then copy the tracking code from Administration, Websites, Tracking Code into your pages.
To use your own domain name with a free SSL certificate, run: sudo /usr/local/bin/egl-setup-domain.sh.x
Set your outgoing mail server under Administration, System, General settings. This instance cannot send email until you do, so password resets and scheduled report emails will not be delivered.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for seller support. Elyxia Global Limited offers a pre-configured and optimized Mautic 6 image running on AlmaLinux 10. Mautic 6 is an industry-leading open-source marketing automation platform, designed to empower businesses with tools for email marketing, social media management, lead nurturing, and more.
This product has charges associated with it for seller support. Elyxia Global Limited offers a pre-configured and hardened Odoo 18 Community image running on AlmaLinux 10. Odoo is an open source suite of business applications that share one database, covering sales, invoicing, inventory, purchasing, manufacturing, projects and HR, so the same customer and product record is used everywhere.
This product has charges associated with it for seller support. Elyxia Global Limited offers a pre-configured and optimized Mautic 7 image running on AlmaLinux 10. Mautic 7 is an industry-leading open-source marketing automation platform, designed to empower businesses with tools for email marketing, social media management, lead nurturing, and more.
This product has charges associated with it for seller support. Elyxia Global Limited offers a pre-configured and hardened OpenCart 4.1.0.4 image running on AlmaLinux 10. OpenCart is a widely used open source e-commerce platform that runs a complete online shop from a single administration area, with multi-store support, multiple currencies and languages, and a large extension marketplace.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.