PostgreSQL 16 (Hardened) on Amazon Linux 2023
This product has charges associated with it for image hardening, maintenance, and support. PostgreSQL 16 on Amazon Linux 2023, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, no password auth, data directory initialized on first boot, and continuously patched images.
Why this image
- Security-hardened at build time: minimal packages, key-only SSH, IMDSv2-only, no default database passwords, remote access closed until you configure it.
- Continuously patched: images are rebuilt, vulnerability-scanned, and republished on a regular cadence so new launches start current.
- Production-ready: systemd-managed PostgreSQL 16; the data directory auto-initializes on first boot under /var/lib/pgsql.
About
PostgreSQL 16 (Hardened) on Amazon Linux 2023 is a production-ready, security-hardened image of the PostgreSQL relational database, maintained and supported by Derek Coleman & Associates Incorporated.
This is repackaged open-source software. PostgreSQL is developed by the PostgreSQL Global Development Group and distributed under the PostgreSQL License (a permissive OSI-approved license). This product bundles unmodified upstream PostgreSQL 16 on a hardened Amazon Linux 2023 base; the charges associated with this listing are for image hardening, continuous patching, vulnerability scanning, and business-day support - not for the underlying open-source software, which remains free.
Hardening baseline: minimal package footprint, SSH key-only access (password authentication disabled), IMDSv2 enforced, and no default database passwords (local peer/socket auth; remote access on port 5432 stays closed until you configure pg_hba.conf and open it to trusted CIDRs). Images are rebuilt, scanned for HIGH and CRITICAL vulnerabilities, and republished on a regular cadence. The data directory initializes on first boot under /var/lib/pgsql; manage the service with systemd and administer locally with: sudo -u postgres psql.
Pricing (hourly usage, AWS Marketplace)
| Instance type | Size | Software price |
|---|---|---|
| c7i.xlarge | 4 vCPU / 8 GiB | $0.46/hr |
| c7i.2xlarge | 8 vCPU / 16 GiB | $0.92/hr |
| c7i.4xlarge | 16 vCPU / 32 GiB | $1.84/hr |
Recommended: c7i.2xlarge. AWS infrastructure charges are separate and billed by AWS. Charges stop when instances are terminated. No subscription, no minimum.
Getting started
Launch from AWS Marketplace (1-Click or EC2 console). Connect via SSH with your EC2 key pair: ssh -i <key> ec2-user@<public-ip>. The data directory initializes on first boot; administer locally with: sudo -u postgres psql. Remote access (port 5432) and authentication are a deliberate customer configuration step - edit pg_hba.conf and postgresql.conf, then open 5432 to trusted CIDRs only. Root login is disabled; use sudo. There are no passwords anywhere in this product.
Support
Email support@dcassociatesgroup.com — business-day response. Covers image operation, the hardening baseline, and launch issues. See support.