Ubuntu is a registered trademark of Canonical Ltd. Imaxe.cloud has no association or agreement of any kind with Canonical: this AMI is built from Ubuntu 22.04 LTS under its free software licenses, and support is provided by us independently.
Description #
Imaxe Hardened Ubuntu 22.04 LTS is a production-ready, hardened AMI built for organizations that need to keep their Ubuntu 22 fleets running securely well beyond the standard maintenance window. We monitor security advisories, apply critical patches and publish updated AMIs on a regular cadence, so your workloads stay protected without a disruptive OS migration.
The image ships hardened out of the box: default-deny firewall, hardened SSH, AppArmor in enforce mode, auditing with auditd, file integrity with AIDE, rootkit detection with rkhunter, ClamAV antivirus and brute-force protection with fail2ban. All of it verified on every release with a Lynis audit whose full report you can read below.
Quick start: up and running in 5 minutes #
Everything you need to go from zero to a hardened instance in production.
| Step | Action | Where | Time |
|---|---|---|---|
| 1 | Subscribe and launch the AMI — any arm64 (Graviton) instance, e.g. t4g.small to start. Includes a 7-day free trial. | AWS Marketplace → EC2 | ~2 min |
| 2 | Open port 22 in the security group, restricted to your IP or CIDR. | EC2 console | 1 min |
| 3 | Connect over SSH — ssh ubuntu@<instance-ip> with the keypair chosen at launch. | Your terminal | 1 min |
| 4 | Done — hardening is already active. Explore the state with the bundled imaxe tool. | The instance | — |
There’s no setup wizard and no mandatory post-launch steps: the image ships hardened from the factory. The rest of this page is optional. If something goes wrong, jump straight to troubleshooting.
Features #
Everything the image includes, grouped by what’s standard and what’s ours.
General
- Ubuntu 22.04 LTS base (jammy, arm64), updated on every build, with automatic security patches (
unattended-upgrades) enabled. ufwfirewall in default-deny: only port 22 open out of the box.- Hardened SSH: no root, no passwords, public key only, modern cryptography (ed25519, chacha20-poly1305, post-quantum kex sntrup761x25519).
- AppArmor with extra profiles installed and all of them in enforce mode.
- Kernel hardened via sysctl (restricted ptrace, unprivileged BPF disabled, link and FIFO protections, full ASLR).
- Hardened mounts:
/tmp,/var/tmpand/dev/shmwithnoexec,nosuid,nodev;/procwithhidepid=2. - Full auditing with
auditd(identity, sudoers, sshd, logins) and accounting withsysstat. - PAM with a strong password policy (14-character minimum) and account lockout via
faillockafter 5 failures.
Extras
- Extended Lifecycle Support: we keep publishing patched Ubuntu 22.04 AMIs when standard maintenance runs out — support until 2032.
- File integrity (AIDE): database baked at build time, ready to detect changes from the very first boot.
- Anti-malware built in: rkhunter with its own baseline and ClamAV with baked-in signatures and automatic updates (24 checks a day).
- fail2ban integrated with ufw: 5 failed SSH attempts in 10 minutes = 1 hour ban, reading directly from the journal.
- Package integrity verification with debsums, on cron.
- Bundled
imaxetool: a CLI to operate the hardening, firewall, auditing and the rest of the modules without editing files by hand. - Lynis audit on every release, with the full report published on this page.
imaxe modules
Modules of the imaxe tool baked into this AMI, with their documentation:
| Module | What it does | Documentation |
|---|---|---|
| os | System base: unattended upgrades, locale, timezone, hostname and time. | View docs → |
| ssh | Authorized keys, host keys, active sessions and sshd hardening from a single command. | View docs → |
| firewall | ufw status, blocking/unblocking IPs and opening or closing ports. | View docs → |
| audit | auditd events and CIS audit rules without fighting auditctl. | View docs → |
| aide | File integrity monitoring (FIM) with AIDE. | View docs → |
| rkhunter | Server scanning for rootkits. | View docs → |
| clamav | ClamAV antivirus at runtime. | View docs → |
| lynis | System hardening audit with an actionable report. | View docs → |
| fail2ban | Jail status, banned IPs, manual ban and unban. | View docs → |
| secrets | Generates, reads and rotates the instance’s local secrets. | View docs → |
| info | AMI inventory in /etc/imaxe/info.yaml, no secrets. | View docs → |
| global-alerts | Cross-cutting alert bus for the instance (SNS). | docs in progress |
Sizing and costs #
It’s a base operating system image: it runs on any arm64 (Graviton) AWS instance, from t4g.nano to metal — pick the size for your workload, not for the AMI. Builds and tests of this image run on t4g.medium.
| Item | Price |
|---|---|
| Hourly subscription | $0.008/h per instance |
| Annual subscription | $60/year per instance |
| Free trial | 7 days |
On top of the subscription price you pay the usual AWS cost (EC2 instance, EBS disk and traffic), billed directly by AWS at your rate. The image disk is 8 GB, expandable at launch.
Lynis reports #
Result of the Lynis hardening audit for each published version: hardening index, warnings and suggestions, with the full line-by-line report.
The hardening index is computed by Lynis from the tests passed. We re-run the audit on every release; any open warnings are resolved before the image goes up on the Marketplace.
Available versions #
Versions of this AMI published on AWS Marketplace:
| Version | Ubuntu | Architecture | Status | Published |
|---|---|---|---|---|
| v1.0 | 22.04 LTS (jammy) | arm64 | ✓ active | 2026-07 |
Lifecycle
The reason this product exists, at a glance: when Canonical’s standard support for Ubuntu 22.04 ends, our maintenance carries on.
Regions and AMI IDs
Version v1.0 is published in these 31 AWS regions. If you launch from the Marketplace, AWS picks the right ID automatically.
| Region | Location | AMI ID (v1.0) |
|---|---|---|
| af-south-1 | Cape Town | ami-0c0fc690298a3b001 |
| ap-east-1 | Hong Kong | ami-0b95004e814cf7882 |
| ap-east-2 | Taipei | ami-056227049121913ba |
| ap-northeast-1 | Tokyo | ami-0521df48aadd24098 |
| ap-northeast-2 | Seoul | ami-0ca3a46c793880118 |
| ap-northeast-3 | Osaka | ami-0afdc6b6274f262a4 |
| ap-south-1 | Mumbai | ami-0c3c5aaa11ffcdb1e |
| ap-south-2 | Hyderabad | ami-0f1e93453cd9dcda5 |
| ap-southeast-1 | Singapore | ami-04c7b97bb948a3b45 |
| ap-southeast-2 | Sydney | ami-00de9f6eab9802988 |
| ap-southeast-3 | Jakarta | ami-0e772bffc352b606e |
| ap-southeast-4 | Melbourne | ami-08c38b2c186977100 |
| ap-southeast-5 | Kuala Lumpur | ami-07eccea55afed16fd |
| ap-southeast-7 | Bangkok | ami-03f9aeb4da0e88d4e |
| ca-central-1 | Montreal | ami-09691d988f365f21f |
| ca-west-1 | Calgary | ami-0596b2452d6c212b8 |
| eu-central-1 | Frankfurt | ami-04cfe6082ff824925 |
| eu-central-2 | Zurich | ami-0c023a2715e77e64f |
| eu-north-1 | Stockholm | ami-03adc89e226066ce9 |
| eu-south-1 | Milan | ami-0c7659ddbb197cb1e |
| eu-south-2 | Spain | ami-0c4bc66463aa38368 |
| eu-west-1 | Ireland | ami-0d5d0e8a90a30bf86 |
| eu-west-2 | London | ami-04b9d315eedd97fb2 |
| eu-west-3 | Paris | ami-0bf55d735789c1397 |
| il-central-1 | Tel Aviv | ami-01c2782a4433e7d4f |
| mx-central-1 | Querétaro | ami-0cca55138d045cfc1 |
| sa-east-1 | São Paulo | ami-04bb062fd427f4ab6 |
| us-east-1 | Virginia | ami-0f374e9b3d09bfc7d |
| us-east-2 | Ohio | ami-02b569a7f3d276a0a |
| us-west-1 | California | ami-0c2c699b1f7f8672e |
| us-west-2 | Oregon | ami-0e99e2234c7702526 |
Pending publication: me-central-1 and me-south-1.
How to launch the AMI #
The AMI follows the standard EC2 launch flow on arm64 (Graviton) instances. The security group only needs one port:
| Type | Protocol | Port | Source |
|---|---|---|---|
| (*) SSH | TCP | 22 | your CIDRs |
Restrict SSH to your own CIDRs or a bastion — never 0.0.0.0/0. The image’s internal firewall also denies everything except 22, so any additional port you need has to be opened in both places: the security group and ufw.
v1.0 is published for arm64 architecture: pick a Graviton family (t4g, m7g/m8g, c7g/c8g, r7g/r8g…). It won’t boot on x86_64 instances.
Once it’s running — SSH: user ubuntu with the keypair chosen at launch. There’s no accessible root user and no password authentication.
ssh -i my-keypair.pem ubuntu@<instance-ip>The image from the inside # expert
Everything that runs inside the AMI, where each piece lives and the commands you’ll use day to day.
Services and ports
| Service | systemd unit | Port | What it does |
|---|---|---|---|
| OpenSSH | ssh.service | 22 | Hardened remote access (drop-in 99-imaxe-harden.conf) |
| ufw | ufw.service | — | Default-deny firewall |
| auditd | auditd.service | — | System auditing (identity, sudoers, sshd, logins) |
| fail2ban | fail2ban.service | — | SSH brute-force banning via ufw, reading the journal |
| AppArmor | apparmor.service | — | Mandatory access control, all profiles in enforce |
| freshclam | clamav-freshclam.service | — | ClamAV signature updates, 24 times a day |
| unattended-upgrades | apt-daily-upgrade.timer | — | Automatic security patches |
| sysstat | sysstat.service | — | Process and performance accounting |
The resident clamd daemon ships disabled in the base image to avoid consuming 1–2 GB of RAM: scanning is on demand with clamscan, with signatures always up to date.
Key paths
| Path | What it is |
|---|---|
| /etc/ssh/sshd_config.d/99-imaxe-harden.conf | sshd hardening (drop-in, doesn’t touch the main file) |
| /etc/sysctl.d/99-zz-imaxe-harden-kernel.conf | Kernel hardening via sysctl |
| /var/log/sudo.log | Log of every sudo use |
| /var/log/audit/ | auditd events |
| /etc/imaxe/ and /var/lib/imaxe/ | Configuration and state of the imaxe tool |
| /usr/local/bin/imaxe | imaxe CLI binary |
Useful commands
| Task | Command |
|---|---|
| Firewall status | sudo ufw status verbose |
| IPs banned by fail2ban | sudo fail2ban-client status sshd |
| File integrity check | sudo aide –check |
| Rootkit scan | sudo rkhunter –check |
| On-demand antivirus scan | sudo clamscan -r /path |
| Local Lynis audit | sudo lynis audit system |
| AMI inventory and modules | imaxe |
Each of these subsystems has its own module in the imaxe CLI, with a friendlier interface than the underlying command — see imaxe modules.
Backups and updates #
- Automatic patches:
unattended-upgradesapplies Ubuntu security updates daily, hands-off. - Antivirus signatures: freshclam updates the ClamAV database 24 times a day.
- New AMIs: we publish updated versions of the image on the Marketplace on a regular cadence; each version passes its own Lynis audit before release.
- Backups: the image doesn’t impose any system of its own — use EBS snapshots or your usual tool.
The AIDE database is baked at build time. If you install or modify software, regenerate the baseline (sudo aideinit or via imaxe’s aide module) so the integrity check doesn’t flag your own changes.
Troubleshooting #
The issues behind almost every ticket, with their usual cause and the fix.
| Symptom | Likely cause | Fix |
|---|---|---|
| The instance won’t even launch | x86_64 instance type | The AMI is arm64: use a Graviton family (t4g, m7g, c7g…) |
| Can’t connect over SSH | Port 22 closed in the security group, or IP outside the allowed CIDR | Check the SG — see how to launch the AMI |
Permission denied (publickey) | Password authentication is disabled | Connect as ubuntu with the launch keypair: ssh -i key.pem ubuntu@<ip> |
| SSH stops responding after several attempts | fail2ban has banned your IP (5 failures in 10 min = 1 h) | Wait an hour or, from another IP: sudo fail2ban-client set sshd unbanip <ip> |
| A new service isn’t reachable | The internal firewall denies everything except 22 | Open the port in ufw and in the security group |
| A binary won’t run in /tmp | /tmp is mounted with noexec (hardening) | Run it from another path or adjust the mount if you accept the risk |
Frequently asked questions #
What exactly does the subscription include?
The hardened AMI, new patched versions throughout the extended lifecycle (until 2032), and support from the team that builds it. Billed per instance: $0.008/h or $60/year, with a 7-day free trial.
Does it work on x86_64 instances?
No. v1.0 is published for arm64 (AWS Graviton): the t4g, m6g–m8g, c6g–c8g, r6g–r8g families, etc.
Can I log in as root or with a password?
No: root login and password authentication are disabled by hardening. Log in as ubuntu with your keypair and use sudo (it’s logged to /var/log/sudo.log).
Can the hardening break my application?
In most cases no, but there are two limits to be aware of: /tmp, /var/tmp and /dev/shm are mounted with noexec, and compilers are restricted to root. If your application needs any of that, adjust it deliberately.
How do I upgrade to a new version of the AMI?
Security patches arrive on their own via unattended-upgrades. To jump to a new version of the image, launch instances with the new AMI and retire the old ones — the usual immutable-AMI pattern (works the same with Auto Scaling).
Why stay on Ubuntu 22.04 instead of migrating to 24.04?
An OS version migration is a project with risk. This product exists so you don’t have to do it in a rush: we keep 22.04 patched and audited until 2032, and you migrate when it suits you.
Changelog #
History of the AMI. Dates correspond to when each version was published on AWS Marketplace.
Initial release
First public version on AWS Marketplace, on Ubuntu 22.04 LTS arm64.
imaxe tool with 12 operational modules baked into the image.Need help with this AMI?
You'll hear back from the same team that builds the image — real engineers, no bots, no first-level tier.