Envoy Proxy (Hardened) on Amazon Linux 2023
This product has charges associated with it for image hardening, maintenance, and support. Envoy proxy on Amazon Linux 2023, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, admin interface on localhost only, runs as a non-root user, and continuously patched images.
Why this image
- Security-hardened at build time: minimal packages, key-only SSH, IMDSv2-only, non-root service user, admin interface on localhost only.
- Continuously patched: rebuilt, vulnerability-scanned, and republished on a regular cadence.
- Production-ready: systemd-managed Envoy 1.38; config validated at build with envoy --mode validate.
About
Envoy Proxy (Hardened) on Amazon Linux 2023 is a production-ready, security-hardened image of the Envoy edge and service proxy, maintained and supported by Derek Coleman & Associates Incorporated.
This is repackaged open-source software. Envoy is a Cloud Native Computing Foundation (CNCF) graduated project and is distributed under the Apache License 2.0. Envoy is a trademark of The Linux Foundation; this listing is not endorsed by or affiliated with the CNCF or The Linux Foundation. This product bundles the unmodified upstream Envoy release binary on a hardened Amazon Linux 2023 base; the charges associated with this listing are for image hardening, continuous patching, vulnerability scanning, and business-day support - not for the underlying open-source software, which remains free.
Hardening baseline: minimal package footprint, SSH key-only access (password authentication disabled), IMDSv2 enforced, Envoy running as a dedicated non-root user with only the bind capability, the admin interface bound to 127.0.0.1 only, host firewall exposing only web ports, and no default credentials anywhere. Images are rebuilt, scanned for HIGH and CRITICAL vulnerabilities, and republished on a regular cadence so that new launches start current. The shipped config serves a placeholder response on port 80; supply your listeners, clusters, and routes in /etc/envoy/envoy.yaml and manage the service with systemd.
Pricing (hourly usage, AWS Marketplace)
| Instance type | Size | Software price |
|---|---|---|
| c7i.xlarge | 4 vCPU / 8 GiB | $0.46/hr |
| c7i.2xlarge | 8 vCPU / 16 GiB | $0.92/hr |
| c7i.4xlarge | 16 vCPU / 32 GiB | $1.84/hr |
Recommended: c7i.xlarge. AWS infrastructure charges are separate and billed by AWS. Charges stop when instances are terminated. No subscription, no minimum.
Getting started
Launch from AWS Marketplace (1-Click or EC2 console). Connect via SSH: ssh -i <key> ec2-user@<public-ip>. Envoy serves a placeholder on port 80; edit /etc/envoy/envoy.yaml to define your listeners, clusters, and routes, validate with: envoy --mode validate -c /etc/envoy/envoy.yaml, then: sudo systemctl restart envoy. The admin interface is bound to 127.0.0.1:9901. Root login is disabled; use sudo. There are no passwords anywhere in this product.
Support
Email support@dcassociatesgroup.com — business-day response. Covers image operation, the hardening baseline, and launch issues. See support.