This is a repackaged open source software product wherein additional charges apply for image hardening, maintenance, and support. OpenBao secrets management on Amazon Linux 2023, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, listener on loopback until you configure TLS, uninitialized at launch (your keys never leave you), and continuously patched images.
OpenBao (Hardened) on Amazon Linux 2023 is a production-ready, security-hardened image of OpenBao, the Linux Foundation's open-source secrets-management server (API-compatible fork of HashiCorp Vault under an open license), maintained and supported by Derek Coleman & Associates Inc.
This is repackaged open-source software. OpenBao is a Linux Foundation project distributed under the Mozilla Public License 2.0. OpenBao is a trademark of The Linux Foundation; this listing is not endorsed by or affiliated with The Linux Foundation. This product builds OpenBao from unmodified upstream source with the current Go toolchain (so known standard-library vulnerabilities in prebuilt binaries are absent) on a hardened Amazon Linux 2023 base; the charges associated with this listing are for image hardening, continuous patching, vulnerability scanning, and business-day support - not for the underlying open-source software, which remains free.
Hardening baseline: minimal package footprint, SSH key-only access (password authentication disabled), IMDSv2 enforced, the server ships UNINITIALIZED (no unseal keys or root token exist until you run bao operator init, so your key material never touches our build), the listener binds to 127.0.0.1 until you configure TLS, and the process holds only the IPC_LOCK capability as a dedicated non-root user. Images are rebuilt, scanned for HIGH and CRITICAL vulnerabilities, and republished on a regular cadence so that new launches start current.
Highlights
Ships uninitialized: no unseal keys, no root token, no state - run bao operator init yourself so key material never exists outside your control.
Continuously patched: rebuilt, vulnerability-scanned, and republished on a regular cadence; Vault-compatible API under an open license (MPL-2.0).
Security-hardened at build time: minimal packages, key-only SSH, IMDSv2-only, non-root service user with IPC_LOCK only, listener on loopback until TLS is configured.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for the instance size you run. Three EC2 sizes are available: c7i.xlarge, c7i.2xlarge, and c7i.4xlarge. They differ by compute capacity, so pricing scales with the vCPU and memory you choose. The larger the instance, the higher the hourly software charge. Billing is usage-based with no subscription and no minimum. Charges stop when you terminate the instance. AWS infrastructure charges are separate and billed by AWS. These software charges cover image hardening, patching, vulnerability scanning, and business-day support.
Top-of-mind questions for buyers
What compute do I get with each instance size, and how do they differ?
Each option maps to an EC2 instance size. The c7i.xlarge gives 4 vCPU and 8 GiB memory. The c7i.2xlarge gives 8 vCPU and 16 GiB. The c7i.4xlarge gives 16 vCPU and 32 GiB. You pick the size that matches your workload's compute needs.
Am I charged the hourly software fee when the instance is stopped or terminated?
Software charges accrue only while the instance runs. Charges stop when you terminate the instance. There is no subscription and no minimum. Stopped instances may still incur separate AWS storage fees for the attached volume, but those are billed by AWS, not as software charges.
What do these hourly software charges actually pay for, since OpenBao is open source?
The charges cover image hardening, continuous patching, vulnerability scanning, and business-day support. They do not pay for the underlying open-source software, which remains free under its open license. AWS infrastructure charges are billed separately by AWS.
products.dcassociatesgroup.com
Helpful?
Vendor refund policy
Usage-based hourly billing; charges stop when instances are terminated. Contact support@dcassociatesgroup.com for billing questions.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
[Security] Refreshed image: rebuilt on the latest hardened Amazon Linux 2023 baseline; all OS packages current at build.
Additional details
Usage instructions
Launch from AWS Marketplace (1-Click or EC2 console).
Connect via SSH with your EC2 key pair: ssh -i <key> ec2-user@<public-ip>. Root login is disabled; use sudo.
Initialize locally: export BAO_ADDR=http://127.0.0.1:8200 && bao operator init, then bao operator unseal. Store the unseal keys and root token securely - they exist only with you.
To serve clients, configure a TLS listener in /etc/openbao/config.hcl, restart with: sudo systemctl restart openbao, and open port 8200 to trusted CIDRs only.
Verify: sudo systemctl status openbao.
Sensitive data: the image ships uninitialized - no unseal keys, no root token, no state. All key material is created by you at init time and is never stored by the seller.
Backup: snapshot the EBS volume (it contains all configuration and data).
Resources: a single instance uses 1 EC2 instance and 1 gp3 EBS volume; no other AWS resources are created.
Support by Derek Coleman & Associates Incorporated. Email: support@dcassociatesgroup.com. Business-day response. Covers image operation, hardening baseline, and launch issues.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.
This product has charges associated with it for providing seller premium support. The Amazon Linux 2023 instance is pre-configured and hardened to the Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) standard, delivering enhanced security over a baseline image. Benefit from a fully maintained hardened image with regular STIG updates, security patches, and hotfixes, along with limited premium OS support to assist with troubleshooting, optimization, and compliance guidance. This makes it an ideal choice for companies that require a secure, compliance-ready, production-quality OS backed by expert assistance.
This product has charges associated with it for hardening, update maintenance, and seller support. Docker on Hardened Amazon Linux 2023 is rigorously secured following STIG guidelines, recognized through a consensus-driven process as the industry benchmark for secure configuration, optimizing both security and efficiency.
This is a repackaged software product wherein additional charges apply for a pre-hardened, SI Core STIG Hardened image and seller support. The Amazon Linux 2023 AMI is designed for developers looking to build and deploy applications on the AWS cloud quickly and securely. This AMI offers improved performance, enhanced security features, and a familiar development environment, making it an ideal choice for various workloads. With the Amazon Linux 2023 AMI, users benefit from seamless integration with AWS services and optimized access to the AWS ecosystem. Whether running microservices, web applications, or containerized workloads, the Amazon Linux 2023 AMI provides the necessary tools for efficient cloud operations.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.