DCA Hardened Images

Apache Kafka (Hardened) on Amazon Linux 2023

This product has charges associated with it for image hardening, maintenance, and support. Apache Kafka 4.3 (KRaft, no ZooKeeper) on Amazon Linux 2023 with Amazon Corretto, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, listeners bound to loopback until you configure them, and continuously patched images.

View on AWS Marketplace

Why this image

About

Apache Kafka (Hardened) on Amazon Linux 2023 is a production-ready, security-hardened single-node image of the Apache Kafka event-streaming platform in KRaft mode (no ZooKeeper), maintained and supported by Derek Coleman & Associates Incorporated.

This is repackaged open-source software. Apache Kafka is developed by the Apache Software Foundation and is distributed under the Apache License 2.0. Apache and Apache Kafka are trademarks of the Apache Software Foundation; this listing is not endorsed by or affiliated with the ASF. This product bundles unmodified upstream Apache Kafka (with patched bundled libraries where upstream jars carry known vulnerabilities) on a hardened Amazon Linux 2023 base; the charges associated with this listing are for image hardening, continuous patching, vulnerability scanning, and business-day support - not for the underlying open-source software, which remains free.

Hardening baseline: minimal package footprint, SSH key-only access (password authentication disabled), IMDSv2 enforced, and no exposed default listeners - Kafka ships with no authentication, so the broker binds to 127.0.0.1 and the storage formats itself on first boot; exposing listeners with SASL/TLS to trusted CIDRs is a deliberate customer configuration step. Images are rebuilt, scanned for HIGH and CRITICAL vulnerabilities, and republished on a regular cadence so that new launches start current. The broker is validated at build time with an end-to-end smoke test.

Pricing (hourly usage, AWS Marketplace)

Instance typeSizeSoftware price
c7i.xlarge4 vCPU / 8 GiB$0.46/hr
c7i.2xlarge8 vCPU / 16 GiB$0.92/hr
c7i.4xlarge16 vCPU / 32 GiB$1.84/hr

Recommended: c7i.2xlarge. AWS infrastructure charges are separate and billed by AWS. Charges stop when instances are terminated. No subscription, no minimum.

Getting started

Launch from AWS Marketplace (1-Click or EC2 console). Connect via SSH: ssh -i <key> ec2-user@<public-ip>. Kafka runs in KRaft mode and binds to 127.0.0.1:9092; verify locally with: /opt/kafka/bin/kafka-topics.sh --bootstrap-server 127.0.0.1:9092 --list. To serve clients, configure listeners plus SASL/TLS in /opt/kafka/config/server.properties, restart with: sudo systemctl restart kafka, and open port 9092 to trusted CIDRs only. Root login is disabled; use sudo. There are no passwords anywhere in this product.

Support

Email support@dcassociatesgroup.com — business-day response. Covers image operation, the hardening baseline, and launch issues. See support.