This product has charges associated with it for hardening, security configuration, and support.
Apache Solr is an open-source enterprise search platform built on Apache Lucene - schema-driven full-text search, faceting, and rich document handling on the JVM. Unlike bare Solr AMIs that ship with no authentication, an admin API open on every interface, and no TLS, this Lynxroute build is ready out of the box: a unique admin password at first boot, dual-layer Basic Auth (TLS reverse proxy plus Solr's native BasicAuthPlugin), the search server bound to loopback only, UFW firewall pre-configured, and a CIS Level 1 hardened Ubuntu 24.04 LTS base.
Apache-2.0 license - fully auditable, no vendor lock-in.
This is a repackaged software product wherein additional charges apply for hardening, security configuration, and support.
WHAT IS APACHE SOLR
Apache Solr is an open-source enterprise search platform from the Apache Software Foundation, built on the Apache Lucene library and running as a Java (JVM) service. It provides schema-driven full-text search with hit highlighting, faceting, dynamic clustering, geospatial and range queries, rich document (PDF, Office) handling, near-real-time indexing, and result ranking over a REST-like HTTP API plus the classic Solr Admin UI. Solr indexes and configuration sets are persisted on the local filesystem and queried with sub-second latency; it scales from a single node to large clusters. This image runs Solr standalone (single node, user-managed) on OpenJDK 21. Apache-2.0 license - a self-hosted alternative to hosted search services and a Lucene-based peer to Elasticsearch and OpenSearch, with no per-query fees and no vendor lock-in.
WHAT THIS AMI ADDS
Security hardening:
Unique admin password generated per instance at first boot
Dual-layer Basic Auth: an nginx TLS reverse proxy plus Solr's native BasicAuthPlugin, both gating the Admin UI and REST API with the same credential
Solr bound to 127.0.0.1 only - never exposed directly; nginx terminates TLS on 443
UFW firewall - ports 22 (SSH) and 443 (HTTPS) only
fail2ban, AppArmor
CVE scan - every image is scanned for vulnerabilities before release
OS hardening (CIS Level 1):
CIS Ubuntu 24.04 LTS Level 1 benchmark applied via ansible-lockdown
CIS Conformance Report at /etc/lynxroute/cis-report.html
CIS Tailored Profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
Highlights
Solr security baked in: unique admin password at first boot, dual-layer Basic Auth (TLS reverse proxy plus Solr's native BasicAuthPlugin), and the search server bound to loopback only behind a TLS perimeter - unlike bare Solr AMIs that ship with authentication disabled, the admin API open on every interface, and no TLS.
CIS Level 1 hardened Ubuntu 24.04 LTS: auditd, fail2ban, AppArmor, SSH key-only, IMDSv2 enforced. CVE-scanned before every release. SBOM (CycloneDX) and CIS Conformance Report included.
Enterprise search on Apache Lucene: schema-driven full-text search, faceting, hit highlighting, rich-document and geospatial queries via a REST API and the Solr Admin UI. Apache-2.0 license - fully auditable, no vendor lock-in.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 5 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
You pay by the hour based on the EC2 instance size you launch. Five instance choices let you match compute to your workload. The t3.small, t3.medium, and t3.large run on burstable instances suited to variable traffic. The m6i.large and m6i.xlarge run on general-purpose instances for steadier demand. Larger instances add more CPU and memory, so hourly cost scales with the capacity you pick. All options deliver the same hardened Apache Solr image. You choose the size; billing follows your actual running hours.
Top-of-mind questions for buyers
What do the t3 and m6i instance labels mean for the compute I get?
Each label is an AWS EC2 instance type. The t3 sizes (small, medium, large) use burstable CPUs that ramp up during traffic spikes. The m6i sizes (large, xlarge) use general-purpose CPUs for steady loads. Larger sizes add more vCPU and memory, which raises the hourly rate.
Am I charged when the instance is stopped or paused?
The software charge meters running hours only. A fully stopped instance stops accruing the hourly software fee. Note that stopped instances may still incur AWS storage charges for attached volumes, which the marketplace bills separately from this software rate.
Does the hardening and compliance content differ between the instance sizes?
No. Every size runs the same hardened image. Each includes CIS Level 1 hardening, CVE scanning, a bundled software bill of materials, a conformance report, and unique credentials generated at first boot. Only compute capacity and hourly rate change with the size you pick.
lynxroute.com
Helpful?
Vendor refund policy
We do not offer refunds for this product. AWS infrastructure charges (EC2, EBS, data transfer) are billed separately by AWS and are not refundable by us.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Open https://<PUBLIC_IP>/solr/ in your browser - accept the self-signed certificate warning
Log in with the admin username and password from the credentials file (Basic Auth gates both the Admin UI and the REST API)
Query and index via the REST API over TLS, for example:
curl -k -u admin:<password> 'https://<PUBLIC_IP>/solr/sample/select?q=:'
Solr runs standalone (single node) and listens on 127.0.0.1:8983 only; nginx is the TLS and Basic Auth perimeter on 443. Do not expose 8983 directly.
The admin password is saved to /root/solr-credentials.txt at first boot.
Replace the self-signed TLS certificate with a CA-signed certificate (certbot is pre-installed) for production use.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for technical support with a 24-hour response time. This AMI provides OpenSearch 2.19 on a Rocky Linux 9 minimal installation with the latest updates, repackaged by Easycloud with continuous support.
This is a repackaged open source software product wherein additional charges apply for technical support. Softwares included: Ubuntu and Apache Web Server
Bansir offers this software product repackaged where additional charges apply for technical support provided by Bansir Cloud email support@bansircloud.com.
Enterprise-grade Kafka UI and API for deep visibility, precise control, and instant action across your ecosystem. Kpow is secure, vendor-agnostic, and trusted by Fortune 500s for managing Apache Kafka at scale.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.