DCA Hardened Images

Qdrant (Hardened) on Amazon Linux 2023

This product has charges associated with it for image hardening, maintenance, and support. Qdrant vector database on Amazon Linux 2023, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, bound to loopback until you set an API key, and continuously patched images.

View on AWS Marketplace

Why this image

About

Qdrant (Hardened) on Amazon Linux 2023 is a production-ready, security-hardened image of the Qdrant vector database and similarity-search engine - the storage layer for AI embeddings, retrieval-augmented generation (RAG), and recommendation systems - maintained and supported by Derek Coleman & Associates Incorporated.

This is repackaged open-source software. Qdrant is developed by Qdrant and its open-source community and is distributed under the Apache License 2.0. Qdrant is a trademark of its owner; this listing is not endorsed by or affiliated with Qdrant. This product bundles the unmodified upstream Qdrant release binary on a hardened Amazon Linux 2023 base; the charges associated with this listing are for image hardening, continuous patching, vulnerability scanning, and business-day support - not for the underlying open-source software, which remains free.

Hardening baseline: minimal package footprint, SSH key-only access (password authentication disabled), IMDSv2 enforced, Qdrant running as a dedicated non-root user and bound to 127.0.0.1 (Qdrant ships with no authentication, so exposing the HTTP/gRPC ports is a deliberate customer step: set service.api_key in /etc/qdrant/config.yaml, widen service.host, and open ports 6333-6334 to trusted CIDRs). The health endpoint is verified at build time. Images are rebuilt, scanned for HIGH and CRITICAL vulnerabilities, and republished on a regular cadence so that new launches start current.

Pricing (hourly usage, AWS Marketplace)

Instance typeSizeSoftware price
c7i.xlarge4 vCPU / 8 GiB$0.46/hr
c7i.2xlarge8 vCPU / 16 GiB$0.92/hr
c7i.4xlarge16 vCPU / 32 GiB$1.84/hr

Recommended: c7i.2xlarge. AWS infrastructure charges are separate and billed by AWS. Charges stop when instances are terminated. No subscription, no minimum.

Getting started

Launch from AWS Marketplace (1-Click or EC2 console). Connect via SSH: ssh -i <key> ec2-user@<public-ip>. Qdrant binds to 127.0.0.1; verify locally: curl http://127.0.0.1:6333/healthz. To serve clients, set service.api_key and service.host: 0.0.0.0 in /etc/qdrant/config.yaml, then: sudo systemctl restart qdrant, and open TCP 6333 (HTTP) and 6334 (gRPC) to trusted CIDRs only. Root login is disabled; use sudo. There are no passwords anywhere in this product.

Support

Email support@dcassociatesgroup.com — business-day response. Covers image operation, the hardening baseline, and launch issues. See support.