IOanyT Innovations
Deployment & usage guide

Deploy IOanyT Hardened Amazon Linux 2023

From subscribing on AWS Marketplace to a running, secured instance — plus day-2 operations. Guide updated October 8, 2026

Operating system

Amazon Linux 2023

SSH user

ec2-user

Architectures

x86_64 and arm64 (Graviton)

Ports

22

Operating systemSSH userPortsArchitectures
Amazon Linux 2023ec2-user22 (SSH)x86_64, arm64 (Graviton)

This guide takes you from an AWS Marketplace subscription to a running, hardened server. There is no manual setup: each instance finishes its own first-boot setup automatically.

Prerequisites

  • An AWS account with permission to subscribe in AWS Marketplace and launch EC2 instances
  • An EC2 key pair for SSH
  • A network path to port 22 from your own network (same VPC, VPN or bastion host)

Step 1 — Subscribe and launch

Using the AWS console

  1. Open the listing for your architecture in AWS Marketplace, either IOanyT Hardened Amazon Linux 2023 - CIS Level 1 (x86_64) or IOanyT Hardened Amazon Linux 2023 - CIS Level 1 (Arm64/Graviton), and choose Continue to Subscribe.
  2. Accept the terms, then choose Continue to Configuration.
  3. Pick the latest version and your Region, then choose Continue to Launch.
  4. Choose Launch through EC2, then pick an instance type from the table below, your VPC and subnet, and your key pair.
  5. Create or pick a security group as described in Step 2, then launch.
ArchitectureInstance typesRecommended
x86_64t3.medium to t3.2xlarge; m7i, c7i, r7i large to 4xlargem7i.large
arm64 (Graviton)t4g.medium to t4g.2xlarge; m7g, c7g, r7g large to 4xlargem7g.large

Using the AWS CLI

aws ec2 run-instances \
  --image-id <AMI_ID_FROM_MARKETPLACE> \
  --instance-type m7i.large \
  --key-name <YOUR_KEY_PAIR> \
  --security-group-ids <YOUR_SECURITY_GROUP> \
  --subnet-id <YOUR_SUBNET> \
  --metadata-options HttpTokens=required \
  --tag-specifications 'ResourceType=instance,Tags=[{Key=Name,Value=hardened-amazon-linux}]'

Use --instance-type m7g.large with the AMI from the Graviton (arm64) edition.

Step 2 — Open the right port

PortProtocolPurposeAllow from
22TCPSSH administrationYour own network, admin IP or bastion host only

Never open port 22 to 0.0.0.0/0. The image has no host firewall; your security group is the network control.

Step 3 — Connect over SSH

ssh -i "your-key.pem" ec2-user@<INSTANCE_IP>

If you get a permission error on the key file, run chmod 400 your-key.pem. Only the ec2-user user can log in over SSH.

Check that first-boot setup has finished:

systemctl status ioanyt-firstboot --no-pager

When setup has finished, the service shows active (exited). Confirm administration works:

sudo -n true && echo ok

Use sudo for administration. The root account is locked.

Step 4 — File-integrity (AIDE) baseline

About 5 minutes after boot, the instance builds its own AIDE baseline. It is finished when this file exists:

test -f /var/lib/ioanyt/aide-init.done && echo "AIDE baseline ready"

Then run a check:

sudo aide --config /etc/aide.conf --check

Right after the baseline, expect reports only for frequently changing locations such as /var/log, /var/lib, /var/cache and /run. A change anywhere else deserves a look.

Step 5 — Keep it patched

Security updates install automatically (dnf-automatic). Apply all other updates in your own maintenance window, then reboot if the kernel was updated:

sudo dnf upgrade

The hardened configuration files stay in place on upgrade: rpm keeps a modified configuration file and writes the new packaged version next to it as .rpmnew.

Day-2 operations

Hardening you should know about

  • SSH users: only ec2-user may log in over SSH, with a key. Password login is disabled.
  • Disabled filesystem modules: some unused filesystem modules (NFS/EFS, FUSE, overlay) are disabled by CIS hardening. To re-enable them, delete /etc/modprobe.d/ioanyt-cis-unused-fs.conf and reboot.
  • /tmp is mounted with noexec: programs can’t run from it.
  • Root is locked. Use sudo from the ec2-user account.
  • SELinux stays enforcing. Check it with getenforce; it should print Enforcing.
  • Amazon Systems Manager agent: it is kept so Systems Manager and EC2 hibernation keep working. If you do not use Systems Manager, you can remove it with sudo dnf remove amazon-ssm-agent.

Sending logs to your own server

Sending logs to a remote host is not configured because the target is your own log server. rsyslog is installed and enabled: add a line such as *.* @@<host>:514 in /etc/rsyslog.d/.

Troubleshooting

SymptomLikely causeFix
SSH connection times outSecurity group or network pathAllow port 22 from your network (Step 2), and check routing or VPN.
SSH Permission deniedKey file permissions, or wrong userRun chmod 400 your-key.pem and log in as ec2-user.
ioanyt-firstboot is not active (exited) yetSetup still runningWait a few minutes and check again. Then run sudo journalctl -u ioanyt-firstboot.
AIDE check reports no baselineThe baseline is built about 5 minutes after bootWait, then look for /var/lib/ioanyt/aide-init.done (Step 4).
EFS/NFS mount or overlay-based tools failsFilesystem modules disabled by CIS hardeningSee “Hardening you should know about”.
Program won’t run from /tmp/tmp is mounted noexecRun it from another directory, such as your home directory.

Support

Email aws-marketplace-support@ioanyt.com. We reply within 1 business day. Include your instance ID and Region.

← Back to the product page · Changelog