Listing Thumbnail

    Milvus - Hardened Vector Database for AI Search and RAG

     Info
    Sold by: Lynxroute 
    Deployed on AWS
    Free Trial
    This product has charges associated with it for hardening, security configuration, and support. Milvus is an open-source vector database for similarity search over embeddings, deployed here in its standalone configuration: the Milvus engine plus etcd for metadata and MinIO for object storage on a single instance. This Lynxroute build is hardened and ready out of the box: authentication enabled before the database first starts with a unique password generated at first boot, the management console published only over TLS behind its own credentials, the metrics port and object store bound to loopback only, UFW firewall pre-configured, and a CIS Level 1 hardened Ubuntu 24.04 LTS base. Apache-2.0 license - fully auditable, no vendor lock-in.

    Overview

    This is a repackaged software product wherein additional charges apply for hardening, security configuration, and support.

    WHAT IS MILVUS

    Milvus is an open-source vector database purpose-built for similarity search over embeddings. It stores high-dimensional vectors alongside scalar metadata and returns nearest-neighbour results across very large collections in milliseconds, which makes it the storage layer for retrieval-augmented generation, semantic search, recommendation, deduplication and image or audio similarity. Written in Go and C++ with a SIMD-accelerated search core, it supports multiple index types and distance metrics (COSINE, L2, inner product), hybrid search combining vector similarity with scalar filtering, sparse and dense vectors, and full-text search. Clients connect over gRPC or a RESTful API, with official SDKs for Python, Java, Go, Node.js and C#. This AMI runs the standalone configuration - the Milvus engine with etcd for metadata and MinIO for object storage - persisting vectors, indexes and the write-ahead log to the instance's EBS volume. Milvus is a graduated project of the LF AI and Data Foundation. Apache-2.0 license, no vendor lock-in.

    WHAT THIS AMI ADDS

    Security hardening:

    • Authentication is enabled before the database first starts, and a unique 24-character database password is generated on your own instance at first boot - the documented upstream default password never exists on your instance
    • The object-storage credential and the management-console password are generated at first boot as well, and written to a root-only credentials file. Nothing is baked into the AMI
    • The management console is published only through an nginx TLS reverse proxy protected by its own credentials, and only the console path is proxied - the rest of the management port is not reachable from outside
    • The metrics and management port is bound to 127.0.0.1 only
    • MinIO object storage is bound to 127.0.0.1 only, and the etcd metadata store publishes no host port at all
    • Container confinement is left at the platform default rather than relaxed
    • Container log rotation capped so a chatty or restarting container cannot fill the root volume
    • UFW firewall pre-configured - only 22, 80, 443 and the database API on 19530 reachable; object storage and metadata ports blocked externally
    • fail2ban, auditd and AppArmor pre-configured
    • HTTPS enabled by default with a self-signed certificate; Certbot and the nginx plugin are pre-installed so a trusted certificate is one command away
    • CVE scan - every image is scanned for vulnerabilities before release

    OS hardening (CIS Level 1):

    • CIS Ubuntu 24.04 LTS Level 1 benchmark applied via ansible-lockdown
    • auditd, SSH hardening, Kernel hardening, IMDSv2 enforced

    Compliance artifacts:

    • SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json
    • CIS Conformance Report at /etc/lynxroute/cis-report.html
    • CIS Tailored Profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md

    Milvus holds its indexes in RAM and requires a CPU with AVX2, so the recommended instance type is m6i.xlarge (4 vCPU, 16 GB) and no burstable tier is offered.

    Highlights

    • Milvus security baked in: authentication enabled before the database first starts with a unique password generated at first boot on your instance, the management console reachable only over TLS behind separate credentials, the metrics port and MinIO object storage bound to loopback only, etcd with no host port at all, UFW firewall pre-configured.
    • CIS Level 1 hardened Ubuntu 24.04 LTS: auditd, fail2ban, AppArmor, SSH key-only, IMDSv2 enforced. CVE-scanned before every release. SBOM (CycloneDX) and CIS Conformance Report included.
    • The storage layer for RAG and semantic search: hybrid search combining vector similarity with scalar filtering, sparse and dense vectors, multiple index types, gRPC and REST APIs with official Python, Java, Go, Node.js and C# SDKs. Apache-2.0 license - fully auditable, no vendor lock-in.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Ubuntu 24.04

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free for 5 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    Milvus - Hardened Vector Database for AI Search and RAG

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (3)

     Info
    Dimension
    Cost/hour
    m6i.xlarge
    Recommended
    $0.05
    m6i.2xlarge
    $0.05
    m6i.large
    $0.03

    Vendor refund policy

    We do not offer refunds for this product. AWS infrastructure charges (EC2, EBS, data transfer) are billed separately by AWS and are not refundable by us.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    Milvus 3.0.0 - Initial release (August 2026)

    • Milvus 3.0.0 on Ubuntu 24.04 LTS, standalone configuration (Milvus engine, etcd, MinIO)
    • CIS Level 1 hardening applied (ansible-lockdown/UBUNTU24-CIS)
    • CVE-scanned before every release
    • Authentication enabled before the database first starts; the database password, object-storage credential and management-console password are all generated at first boot - nothing baked into the AMI
    • Management console published over TLS behind its own credentials; only the console path is proxied
    • Metrics/management port and MinIO object storage bound to 127.0.0.1 only; etcd publishes no host port
    • HTTPS enabled by default with a self-signed certificate; Certbot and the nginx plugin pre-installed
    • Container log rotation capped so runtime logging cannot fill the root volume
    • UFW firewall pre-configured (ports 22, 80, 443, 19530 only)
    • fail2ban, auditd, AppArmor pre-configured
    • SBOM (CycloneDX 1.6) at /etc/lynxroute/sbom.json
    • CIS Conformance Report (OpenSCAP) at /etc/lynxroute/cis-report.html
    • IMDSv2 enforced

    Additional details

    Usage instructions

    1. Launch instance (m6i.xlarge recommended - Milvus holds its indexes in RAM and requires a CPU with AVX2)
    2. Open Security Group - allow TCP 19530 and TCP 443 from your IP, and TCP 22 for SSH
    3. SSH: ssh -i key.pem ubuntu@<PUBLIC_IP>
    4. Read credentials: sudo cat /root/milvus-credentials.txt
    5. Connect a client to <PUBLIC_IP>:19530 using the token root:<password from the credentials file>
    6. Open https://<PUBLIC_IP>/ in your browser - accept the self-signed certificate warning, then sign in to the management console with the console user and password from the credentials file

    The instance takes 1-3 minutes to finish initialising on first launch; a loading page is served until Milvus is ready.

    Create a collection, insert vectors and run a similarity search over the REST API, substituting your public IP and password:

    curl -X POST "http://<PUBLIC_IP>:19530/v2/vectordb/collections/create"
    -H "Authorization: Bearer root:<password>"
    -H "content-type: application/json"
    -d '{"collectionName":"demo","dimension":8,"metricType":"COSINE"}'

    curl -X POST "http://<PUBLIC_IP>:19530/v2/vectordb/entities/insert"
    -H "Authorization: Bearer root:<password>"
    -H "content-type: application/json"
    -d '{"collectionName":"demo","data":[{"id":1,"vector":[0.1,0.2,0.3,0.4,0.5,0.6,0.7,0.8]}]}'

    curl -X POST "http://<PUBLIC_IP>:19530/v2/vectordb/entities/search"
    -H "Authorization: Bearer root:<password>"
    -H "content-type: application/json"
    -d '{"collectionName":"demo","annsField":"vector","limit":1,"data":[[0.1,0.2,0.3,0.4,0.5,0.6,0.7,0.8]],"outputFields":["id"]}'

    Python clients install the official SDK with: pip install "pymilvus>=3.0.1"

    In Milvus 3.x the default database is named "default" - examples written for Milvus 2.x that pass "_default" will fail.

    After a restart your data is retained, but Milvus reloads each collection into memory before it can answer searches; a search issued in the first few seconds may return an empty result while loading completes.

    Change the database password after first sign-in: curl -X POST "http://<PUBLIC_IP>:19530/v2/vectordb/users/update_password"
    -H "Authorization: Bearer root:<password>" -H "content-type: application/json"
    -d '{"userName":"root","password":"<password>","newPassword":"<new password>"}'

    All generated credentials are saved to /root/milvus-credentials.txt on first launch. Restrict inbound 19530 and 443 to your own address range before putting the instance into service. Replace the self-signed TLS certificate with a CA-signed one for production use: sudo certbot --nginx -d yourdomain.com

    Resources

    Vendor resources

    Support

    Vendor support

    Visit us online: https://lynxroute.com 

    For Milvus documentation:

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.