Launcher Products Bitnami Documentationimaxe CLI Blog Contact
Operating system ubuntu22.04ltshardenedcis

Ubuntu 22.04 LTS Hardened

Life insurance for your entire Ubuntu 22 fleet: a hardened AMI, maintained when nobody else maintains it.

Regions
31 AWS
Latest version
v1.0
Size
8 GB
Boot
~35 s
Lynis
98/100
Open CVEs
0
Pricing
0.008 USD/hr · 60 USD/year
screenshot · SSH session on the AMI
Level of detail

Ubuntu is a registered trademark of Canonical Ltd. Imaxe.cloud has no association or agreement of any kind with Canonical: this AMI is built from Ubuntu 22.04 LTS under its free software licenses, and support is provided by us independently.

Description #

Imaxe Hardened Ubuntu 22.04 LTS is a production-ready, hardened AMI built for organizations that need to keep their Ubuntu 22 fleets running securely well beyond the standard maintenance window. We monitor security advisories, apply critical patches and publish updated AMIs on a regular cadence, so your workloads stay protected without a disruptive OS migration.

The image ships hardened out of the box: default-deny firewall, hardened SSH, AppArmor in enforce mode, auditing with auditd, file integrity with AIDE, rootkit detection with rkhunter, ClamAV antivirus and brute-force protection with fail2ban. All of it verified on every release with a Lynis audit whose full report you can read below.

Quick start: up and running in 5 minutes #

Everything you need to go from zero to a hardened instance in production.

StepActionWhereTime
1Subscribe and launch the AMI — any arm64 (Graviton) instance, e.g. t4g.small to start. Includes a 7-day free trial.AWS Marketplace → EC2~2 min
2Open port 22 in the security group, restricted to your IP or CIDR.EC2 console1 min
3Connect over SSHssh ubuntu@<instance-ip> with the keypair chosen at launch.Your terminal1 min
4Done — hardening is already active. Explore the state with the bundled imaxe tool.The instance
That's it

There’s no setup wizard and no mandatory post-launch steps: the image ships hardened from the factory. The rest of this page is optional. If something goes wrong, jump straight to troubleshooting.

Features #

Everything the image includes, grouped by what’s standard and what’s ours.

General

  • Ubuntu 22.04 LTS base (jammy, arm64), updated on every build, with automatic security patches (unattended-upgrades) enabled.
  • ufw firewall in default-deny: only port 22 open out of the box.
  • Hardened SSH: no root, no passwords, public key only, modern cryptography (ed25519, chacha20-poly1305, post-quantum kex sntrup761x25519).
  • AppArmor with extra profiles installed and all of them in enforce mode.
  • Kernel hardened via sysctl (restricted ptrace, unprivileged BPF disabled, link and FIFO protections, full ASLR).
  • Hardened mounts: /tmp, /var/tmp and /dev/shm with noexec,nosuid,nodev; /proc with hidepid=2.
  • Full auditing with auditd (identity, sudoers, sshd, logins) and accounting with sysstat.
  • PAM with a strong password policy (14-character minimum) and account lockout via faillock after 5 failures.

Extras

  • Extended Lifecycle Support: we keep publishing patched Ubuntu 22.04 AMIs when standard maintenance runs out — support until 2032.
  • File integrity (AIDE): database baked at build time, ready to detect changes from the very first boot.
  • Anti-malware built in: rkhunter with its own baseline and ClamAV with baked-in signatures and automatic updates (24 checks a day).
  • fail2ban integrated with ufw: 5 failed SSH attempts in 10 minutes = 1 hour ban, reading directly from the journal.
  • Package integrity verification with debsums, on cron.
  • Bundled imaxe tool: a CLI to operate the hardening, firewall, auditing and the rest of the modules without editing files by hand.
  • Lynis audit on every release, with the full report published on this page.

imaxe modules

Modules of the imaxe tool baked into this AMI, with their documentation:

ModuleWhat it doesDocumentation
osSystem base: unattended upgrades, locale, timezone, hostname and time.View docs →
sshAuthorized keys, host keys, active sessions and sshd hardening from a single command.View docs →
firewallufw status, blocking/unblocking IPs and opening or closing ports.View docs →
auditauditd events and CIS audit rules without fighting auditctl.View docs →
aideFile integrity monitoring (FIM) with AIDE.View docs →
rkhunterServer scanning for rootkits.View docs →
clamavClamAV antivirus at runtime.View docs →
lynisSystem hardening audit with an actionable report.View docs →
fail2banJail status, banned IPs, manual ban and unban.View docs →
secretsGenerates, reads and rotates the instance’s local secrets.View docs →
infoAMI inventory in /etc/imaxe/info.yaml, no secrets.View docs →
global-alertsCross-cutting alert bus for the instance (SNS).docs in progress

Sizing and costs #

It’s a base operating system image: it runs on any arm64 (Graviton) AWS instance, from t4g.nano to metal — pick the size for your workload, not for the AMI. Builds and tests of this image run on t4g.medium.

ItemPrice
Hourly subscription$0.008/h per instance
Annual subscription$60/year per instance
Free trial7 days

On top of the subscription price you pay the usual AWS cost (EC2 instance, EBS disk and traffic), billed directly by AWS at your rate. The image disk is 8 GB, expandable at launch.

Lynis reports #

Result of the Lynis hardening audit for each published version: hardening index, warnings and suggestions, with the full line-by-line report.

VersionHardening indexTestsWarningsSuggestionsAuditReport
v1.098/100245002026-07-29HTML · PDF ↓

The hardening index is computed by Lynis from the tests passed. We re-run the audit on every release; any open warnings are resolved before the image goes up on the Marketplace.

Available versions #

Versions of this AMI published on AWS Marketplace:

VersionUbuntuArchitectureStatusPublished
v1.022.04 LTS (jammy)arm64 active2026-07

Lifecycle

The reason this product exists, at a glance: when Canonical’s standard support for Ubuntu 22.04 ends, our maintenance carries on.

Ubuntu 22.04standard support
2022 → 2027
Imaxe ELSactive
2026 → 2032
202220242026202820302032

Regions and AMI IDs

Version v1.0 is published in these 31 AWS regions. If you launch from the Marketplace, AWS picks the right ID automatically.

RegionLocationAMI ID (v1.0)
af-south-1Cape Townami-0c0fc690298a3b001
ap-east-1Hong Kongami-0b95004e814cf7882
ap-east-2Taipeiami-056227049121913ba
ap-northeast-1Tokyoami-0521df48aadd24098
ap-northeast-2Seoulami-0ca3a46c793880118
ap-northeast-3Osakaami-0afdc6b6274f262a4
ap-south-1Mumbaiami-0c3c5aaa11ffcdb1e
ap-south-2Hyderabadami-0f1e93453cd9dcda5
ap-southeast-1Singaporeami-04c7b97bb948a3b45
ap-southeast-2Sydneyami-00de9f6eab9802988
ap-southeast-3Jakartaami-0e772bffc352b606e
ap-southeast-4Melbourneami-08c38b2c186977100
ap-southeast-5Kuala Lumpurami-07eccea55afed16fd
ap-southeast-7Bangkokami-03f9aeb4da0e88d4e
ca-central-1Montrealami-09691d988f365f21f
ca-west-1Calgaryami-0596b2452d6c212b8
eu-central-1Frankfurtami-04cfe6082ff824925
eu-central-2Zurichami-0c023a2715e77e64f
eu-north-1Stockholmami-03adc89e226066ce9
eu-south-1Milanami-0c7659ddbb197cb1e
eu-south-2Spainami-0c4bc66463aa38368
eu-west-1Irelandami-0d5d0e8a90a30bf86
eu-west-2Londonami-04b9d315eedd97fb2
eu-west-3Parisami-0bf55d735789c1397
il-central-1Tel Avivami-01c2782a4433e7d4f
mx-central-1Querétaroami-0cca55138d045cfc1
sa-east-1São Pauloami-04bb062fd427f4ab6
us-east-1Virginiaami-0f374e9b3d09bfc7d
us-east-2Ohioami-02b569a7f3d276a0a
us-west-1Californiaami-0c2c699b1f7f8672e
us-west-2Oregonami-0e99e2234c7702526

Pending publication: me-central-1 and me-south-1.

How to launch the AMI #

The AMI follows the standard EC2 launch flow on arm64 (Graviton) instances. The security group only needs one port:

TypeProtocolPortSource
(*) SSHTCP22your CIDRs
Recommended

Restrict SSH to your own CIDRs or a bastion — never 0.0.0.0/0. The image’s internal firewall also denies everything except 22, so any additional port you need has to be opened in both places: the security group and ufw.

arm64 only

v1.0 is published for arm64 architecture: pick a Graviton family (t4g, m7g/m8g, c7g/c8g, r7g/r8g…). It won’t boot on x86_64 instances.

Once it’s running — SSH: user ubuntu with the keypair chosen at launch. There’s no accessible root user and no password authentication.

terminal
ssh -i my-keypair.pem ubuntu@<instance-ip>

The image from the inside # expert

Everything that runs inside the AMI, where each piece lives and the commands you’ll use day to day.

Services and ports

Servicesystemd unitPortWhat it does
OpenSSHssh.service22Hardened remote access (drop-in 99-imaxe-harden.conf)
ufwufw.serviceDefault-deny firewall
auditdauditd.serviceSystem auditing (identity, sudoers, sshd, logins)
fail2banfail2ban.serviceSSH brute-force banning via ufw, reading the journal
AppArmorapparmor.serviceMandatory access control, all profiles in enforce
freshclamclamav-freshclam.serviceClamAV signature updates, 24 times a day
unattended-upgradesapt-daily-upgrade.timerAutomatic security patches
sysstatsysstat.serviceProcess and performance accounting

The resident clamd daemon ships disabled in the base image to avoid consuming 1–2 GB of RAM: scanning is on demand with clamscan, with signatures always up to date.

Key paths

PathWhat it is
/etc/ssh/sshd_config.d/99-imaxe-harden.confsshd hardening (drop-in, doesn’t touch the main file)
/etc/sysctl.d/99-zz-imaxe-harden-kernel.confKernel hardening via sysctl
/var/log/sudo.logLog of every sudo use
/var/log/audit/auditd events
/etc/imaxe/ and /var/lib/imaxe/Configuration and state of the imaxe tool
/usr/local/bin/imaxeimaxe CLI binary

Useful commands

TaskCommand
Firewall statussudo ufw status verbose
IPs banned by fail2bansudo fail2ban-client status sshd
File integrity checksudo aide –check
Rootkit scansudo rkhunter –check
On-demand antivirus scansudo clamscan -r /path
Local Lynis auditsudo lynis audit system
AMI inventory and modulesimaxe

Each of these subsystems has its own module in the imaxe CLI, with a friendlier interface than the underlying command — see imaxe modules.

Backups and updates #

  • Automatic patches: unattended-upgrades applies Ubuntu security updates daily, hands-off.
  • Antivirus signatures: freshclam updates the ClamAV database 24 times a day.
  • New AMIs: we publish updated versions of the image on the Marketplace on a regular cadence; each version passes its own Lynis audit before release.
  • Backups: the image doesn’t impose any system of its own — use EBS snapshots or your usual tool.
AIDE and legitimate changes

The AIDE database is baked at build time. If you install or modify software, regenerate the baseline (sudo aideinit or via imaxe’s aide module) so the integrity check doesn’t flag your own changes.

Troubleshooting #

The issues behind almost every ticket, with their usual cause and the fix.

SymptomLikely causeFix
The instance won’t even launchx86_64 instance typeThe AMI is arm64: use a Graviton family (t4g, m7g, c7g…)
Can’t connect over SSHPort 22 closed in the security group, or IP outside the allowed CIDRCheck the SG — see how to launch the AMI
Permission denied (publickey)Password authentication is disabledConnect as ubuntu with the launch keypair: ssh -i key.pem ubuntu@<ip>
SSH stops responding after several attemptsfail2ban has banned your IP (5 failures in 10 min = 1 h)Wait an hour or, from another IP: sudo fail2ban-client set sshd unbanip <ip>
A new service isn’t reachableThe internal firewall denies everything except 22Open the port in ufw and in the security group
A binary won’t run in /tmp/tmp is mounted with noexec (hardening)Run it from another path or adjust the mount if you accept the risk

Frequently asked questions #

What exactly does the subscription include?

The hardened AMI, new patched versions throughout the extended lifecycle (until 2032), and support from the team that builds it. Billed per instance: $0.008/h or $60/year, with a 7-day free trial.

Does it work on x86_64 instances?

No. v1.0 is published for arm64 (AWS Graviton): the t4g, m6gm8g, c6gc8g, r6gr8g families, etc.

Can I log in as root or with a password?

No: root login and password authentication are disabled by hardening. Log in as ubuntu with your keypair and use sudo (it’s logged to /var/log/sudo.log).

Can the hardening break my application?

In most cases no, but there are two limits to be aware of: /tmp, /var/tmp and /dev/shm are mounted with noexec, and compilers are restricted to root. If your application needs any of that, adjust it deliberately.

How do I upgrade to a new version of the AMI?

Security patches arrive on their own via unattended-upgrades. To jump to a new version of the image, launch instances with the new AMI and retire the old ones — the usual immutable-AMI pattern (works the same with Auto Scaling).

Why stay on Ubuntu 22.04 instead of migrating to 24.04?

An OS version migration is a project with risk. This product exists so you don’t have to do it in a rush: we keep 22.04 patched and audited until 2032, and you migrate when it suits you.

Changelog #

History of the AMI. Dates correspond to when each version was published on AWS Marketplace.

v1.0 2026-07-30Latest

Initial release

First public version on AWS Marketplace, on Ubuntu 22.04 LTS arm64.

New AMI published in 31 AWS regions, arm64 architecture (Graviton).
Security Full out-of-the-box hardening: ufw, hardened SSH, AppArmor, auditd, AIDE, rkhunter, ClamAV and fail2ban. Lynis audit 98/100 with 0 warnings and 0 suggestions.
New Bundled imaxe tool with 12 operational modules baked into the image.
Active support · Mon–Fri 9:00–18:00 CET

Need help with this AMI?

You'll hear back from the same team that builds the image — real engineers, no bots, no first-level tier.

< 4 hfirst response on business days
ES / ENsupport languages
Includedin the AMI price