DCA Hardened Images

Varnish Cache (Hardened) on Amazon Linux 2023

This product has charges associated with it for image hardening, maintenance, and support. Varnish Cache HTTP accelerator on Amazon Linux 2023, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, per-instance admin secret, and continuously patched images.

View on AWS Marketplace

Why this image

About

Varnish Cache (Hardened) on Amazon Linux 2023 is a production-ready, security-hardened image of the Varnish Cache HTTP accelerator, maintained and supported by Derek Coleman & Associates Incorporated.

This is repackaged open-source software. Varnish Cache is developed by the Varnish Cache project and is distributed under a BSD 2-Clause license. Varnish is a trademark of Varnish Software AB; this listing is not endorsed by or affiliated with Varnish Software. This product bundles unmodified upstream Varnish Cache on a hardened Amazon Linux 2023 base; the charges associated with this listing are for image hardening, continuous patching, vulnerability scanning, and business-day support - not for the underlying open-source software, which remains free.

Hardening baseline: minimal package footprint, SSH key-only access (password authentication disabled), IMDSv2 enforced, the varnishadm management secret generated per instance on first boot (never baked into the image), admin interface bound to localhost, host firewall exposing only the HTTP port, and no default credentials anywhere. Images are rebuilt, scanned for HIGH and CRITICAL vulnerabilities, and republished on a regular cadence so that new launches start current. Varnish listens on port 80 with the backend defined in /etc/varnish/default.vcl (placeholder points at 127.0.0.1:8080 until you configure your origin).

Pricing (hourly usage, AWS Marketplace)

Instance typeSizeSoftware price
c7i.xlarge4 vCPU / 8 GiB$0.46/hr
c7i.2xlarge8 vCPU / 16 GiB$0.92/hr
c7i.4xlarge16 vCPU / 32 GiB$1.84/hr

Recommended: c7i.xlarge. AWS infrastructure charges are separate and billed by AWS. Charges stop when instances are terminated. No subscription, no minimum.

Getting started

Launch from AWS Marketplace (1-Click or EC2 console). Connect via SSH: ssh -i <key> ec2-user@<public-ip>. Varnish listens on port 80; edit /etc/varnish/default.vcl to point the backend at your origin server, then: sudo systemctl restart varnish. The varnishadm secret is generated per instance at /etc/varnish/secret. Root login is disabled; use sudo. There are no passwords anywhere in this product.

Support

Email support@dcassociatesgroup.com — business-day response. Covers image operation, the hardening baseline, and launch issues. See support.