Overview
Charges for this image cover the security hardening, optimization, and pre-integration work Hanwei performs on top of the upstream CentOS Stream project. No application software is added. This image provides a minimal, EC2-ready CentOS Stream 9 base that is patched to the build date and configured to a consistent hardening and tuning profile, so instances launch ready for use without a further baseline pass.
What Hanwei Adds to Upstream CentOS Stream 9
- Linux 6.1 LTS kernel: The distribution kernel is replaced with Linux 6.1 LTS built from kernel.org sources; matching kernel headers and a build tree are installed so out-of-tree modules (such as DKMS drivers) can be compiled on the instance. The distribution kernel is kept as a fallback boot entry.
- 64-bit Arm build: The image targets aarch64 and runs on AWS Graviton instance families.
- Hardening beyond distribution defaults: SSH is restricted to a modern key-exchange, cipher and MAC allow-list, root login and password authentication are disabled, MaxAuthTries is lowered, auditd ships with an expanded rule set, and kernel network parameters are set for a hardened posture.
- A uniform tuning baseline: The soft open-file limit is raised from 1024 to 65536 (hard limit 524288), vm.max_map_count is raised from 65530 to 262144, the device receive backlog and TCP SYN backlog are enlarged, socket buffer ceilings are increased, tcp_slow_start_after_idle is disabled, and journald is capped at 500 MB. The profile raises ceilings only and does not alter protocol semantics or application behaviour.
- AWS operational integration: The Amazon SSM Agent is installed and enabled, and chrony is pointed at the Amazon Time Sync service at 169.254.169.123.
- Build dependencies preinstalled: gcc, make, pkgconf and openssl-devel are present, so software can be compiled on the instance without adding a toolchain.
- Pinned patch level and reproducible build: Packages are updated to the build date and the image is produced by a reproducible build that is validated on EC2 before release.
Access and Security Posture
- SELinux is in enforcing mode.
- The default login is the ec2-user account over SSH using key-based authentication.
- Direct root login over SSH is disabled and password authentication is turned off.
- No application credentials or SSH keys are baked into the image; host keys are generated on first boot.
Operational Impact on EC2
- The instance boots the Linux 6.1 LTS kernel by default, with the distribution kernel available as a fallback boot entry.
- The Amazon SSM Agent allows shell access through Session Manager without opening inbound SSH.
- Time is synchronized through the Amazon Time Sync service reached at the link-local address.
- cloud-init handles first-boot initialization: hostname, user data, and the login SSH key.
- The patch level is fixed at build time, so launches from this version are reproducible.
Where This Image Fits
- A general-purpose CentOS Stream 9 base for services, application hosts and build agents.
- Container and CI hosts, with gcc, make, pkgconf and openssl-devel already present.
- Fleets managed through cloud-init and AWS Systems Manager.
- Workloads that need a newer LTS kernel than the distribution default for hardware or feature support, including building out-of-tree modules.
About CentOS Stream 9
CentOS Stream 9 is the continuously delivered distribution that tracks the next Red Hat Enterprise Linux 9 minor release, providing a current, RHEL-compatible userland and kernel. In this image the distribution kernel is replaced with Linux 6.1 LTS, a long-term-support kernel built from kernel.org sources, while the distribution kernel is retained as a fallback.
Highlights
- WHAT IS PACKAGED - A minimal CentOS Stream 9 image for 64-bit Arm (Graviton) running the Linux 6.1 LTS kernel built from source, with matching kernel headers and build tree plus gcc, make, pkgconf and openssl-devel, so out-of-tree modules and other software can be built on the instance.
- HOW THE BASELINE IS HARDENED AND TUNED - SSH uses a modern algorithm allow-list with key-only login and root login disabled, auditd is active and SELinux is enforcing; the soft open-file limit goes from 1024 to 65536, vm.max_map_count is raised from 65530 to 262144, and socket backlogs and buffers are enlarged without changing protocol behaviour.
- HOW IT FITS AWS OPERATIONS - The Amazon SSM Agent enables Session Manager access, chrony uses the Amazon Time Sync service, cloud-init handles first-boot setup, and the root filesystem expands to the EBS volume on first boot.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Free trial
- ...
Dimension | Cost/hour |
|---|---|
t4g.small Recommended | $0.10 |
c6gd.2xlarge | $0.30 |
m8g.24xlarge | $0.05 |
c7gn.12xlarge | $0.05 |
c6gn.xlarge | $0.20 |
m6g.metal | $0.50 |
a1.2xlarge | $0.30 |
m8g.12xlarge | $0.05 |
m7g.metal | $0.05 |
c7gn.xlarge | $0.05 |
Vendor refund policy
no refunds
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (Arm) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
- Rebuilt on the latest CentOS Stream 9 for 64-bit Arm and fully patched at build time.
- Hanwei security hardening and EC2 resource/network tuning baseline applied.
- Amazon SSM Agent and Amazon Time Sync integrated.
- Default login user is ec2-user; direct root login and password authentication are disabled.
- Root filesystem is XFS.
- Kernel replaced with Linux 6.1 LTS built from kernel.org source; matching kernel headers and build tree are included so out-of-tree modules (e.g. DKMS drivers) can be compiled on the instance; the distribution kernel is retained as a fallback boot entry.
Additional details
Usage instructions
SSH to the instance and login as 'ec2-user' using the key specified at launch. Additional information may be found at : https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/AccessingInstancesLinux.html
Resources
Vendor resources
Support
Vendor support
In the event you have a problem you can try:
- visit our Knowledge Base page, Knowledge Base articles usually contain FAQs: https://support.proimage.cloud/
- Create a support ticket in the work order system, which will be handled by our technical support staff, usually within 24 hours (or longer if there is a time difference): https://support.proimage.cloud/support
- Contact our customer service manager by e-mail: prosupport@hanweie.com
If you subscribe to the free product, you can only access the Knowledge Base page, thank you for subscribing.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.