DCA Hardened Images

Caddy (Hardened) on Amazon Linux 2023

This product has charges associated with it for image hardening, maintenance, and support. Caddy web server on Amazon Linux 2023, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, runs as a non-root user, firewall pre-configured for HTTP/HTTPS, and continuously patched images.

View on AWS Marketplace

Why this image

About

Caddy (Hardened) on Amazon Linux 2023 is a production-ready, security-hardened image of the Caddy web server and reverse proxy, maintained and supported by Derek Coleman & Associates Incorporated.

This is repackaged open-source software. Caddy is developed by the Caddy project community and is distributed under the Apache License 2.0. This listing is not endorsed by or affiliated with the Caddy project. This product builds Caddy from unmodified upstream source with the current patched Go toolchain (so known standard-library vulnerabilities in prebuilt binaries are absent) on a hardened Amazon Linux 2023 base; the charges associated with this listing are for image hardening, continuous patching, vulnerability scanning, and business-day support - not for the underlying open-source software, which remains free.

Hardening baseline: minimal package footprint, SSH key-only access (password authentication disabled), IMDSv2 enforced, Caddy running as a dedicated non-root user with only the bind capability, host firewall exposing only web ports, and no default credentials anywhere. Automatic HTTPS activates once you configure a real domain in the Caddyfile. Images are rebuilt, scanned for HIGH and CRITICAL vulnerabilities, and republished on a regular cadence so that new launches start current. Configure sites in /etc/caddy/Caddyfile and manage the service with systemd: sudo systemctl restart caddy.

Pricing (hourly usage, AWS Marketplace)

Instance typeSizeSoftware price
c7i.xlarge4 vCPU / 8 GiB$0.46/hr
c7i.2xlarge8 vCPU / 16 GiB$0.92/hr
c7i.4xlarge16 vCPU / 32 GiB$1.84/hr

Recommended: c7i.xlarge. AWS infrastructure charges are separate and billed by AWS. Charges stop when instances are terminated. No subscription, no minimum.

Getting started

Launch from AWS Marketplace (1-Click or EC2 console). Connect via SSH: ssh -i <key> ec2-user@<public-ip>. Edit /etc/caddy/Caddyfile to define your sites (replace the placeholder :80 block with your domain to enable automatic HTTPS), then: sudo systemctl restart caddy. Root login is disabled; use sudo. There are no passwords anywhere in this product.

Support

Email support@dcassociatesgroup.com — business-day response. Covers image operation, the hardening baseline, and launch issues. See support.