DCA Hardened Images

Squid Proxy (Hardened) on Amazon Linux 2023

This product has charges associated with it for image hardening, maintenance, and support. Squid caching proxy on Amazon Linux 2023, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, and continuously patched images.

View on AWS Marketplace

Why this image

About

Squid Proxy (Hardened) on Amazon Linux 2023 is a production-ready, security-hardened image of the Squid caching and forwarding web proxy, maintained and supported by Derek Coleman & Associates Incorporated.

This is repackaged open-source software. Squid is developed by the Squid Project and is distributed under the GNU General Public License v2 or later. This product bundles unmodified upstream Squid on a hardened Amazon Linux 2023 base; the charges associated with this listing are for image hardening, continuous patching, vulnerability scanning, and business-day support - not for the underlying open-source software, which remains free.

Hardening baseline: minimal package footprint, SSH key-only access (password authentication disabled), IMDSv2 enforced, and a deny-all default proxy policy (Squid ships denying all client access; defining your ACLs in /etc/squid/squid.conf and opening TCP 3128 to trusted CIDRs is a deliberate customer configuration step, so the instance cannot be abused as an open proxy). Images are rebuilt, scanned for HIGH and CRITICAL vulnerabilities, and republished on a regular cadence so that new launches start current. Manage the service with systemd: sudo systemctl restart squid.

Pricing (hourly usage, AWS Marketplace)

Instance typeSizeSoftware price
c7i.xlarge4 vCPU / 8 GiB$0.46/hr
c7i.2xlarge8 vCPU / 16 GiB$0.92/hr
c7i.4xlarge16 vCPU / 32 GiB$1.84/hr

Recommended: c7i.xlarge. AWS infrastructure charges are separate and billed by AWS. Charges stop when instances are terminated. No subscription, no minimum.

Getting started

Launch from AWS Marketplace (1-Click or EC2 console). Connect via SSH: ssh -i <key> ec2-user@<public-ip>. Edit /etc/squid/squid.conf to set your ACLs (Squid denies all by default), then: sudo systemctl restart squid, and open TCP 3128 to trusted CIDRs only. Root login is disabled; use sudo. There are no passwords anywhere in this product.

Support

Email support@dcassociatesgroup.com — business-day response. Covers image operation, the hardening baseline, and launch issues. See support.