This is a repackaged open source software product wherein additional charges apply for image hardening, maintenance, and support. MySQL 8.4 Community Server (LTS) on Amazon Linux 2023, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, socket-auth root (no passwords), remote access closed until you configure it, and continuously patched images.
MySQL 8.4 Community (Hardened) on Amazon Linux 2023 is a production-ready, security-hardened image of the MySQL Community Server relational database (8.4 LTS series), maintained and supported by Derek Coleman & Associates Inc.
This is repackaged open-source software. MySQL Community Server is developed by Oracle Corporation and the MySQL community and is distributed under the GNU General Public License v2. MySQL is a trademark of Oracle Corporation; this listing is not endorsed by or affiliated with Oracle. This product bundles unmodified upstream MySQL Community Server on a hardened Amazon Linux 2023 base; the charges associated with this listing are for image hardening, continuous patching, vulnerability scanning, and business-day support - not for the underlying open-source software, which remains free.
Hardening baseline: minimal package footprint, SSH key-only access (password authentication disabled), IMDSv2 enforced, and no default database passwords (the data directory initializes on first boot and root access uses auth_socket - sudo mysql; MySQL binds to 127.0.0.1, so remote access on port 3306 is refused until you change bind-address and create users; the 1-Click security group pre-opens TCP 3306 from anywhere for that step - narrow it to trusted CIDRs before you do). MySQL X protocol is disabled by default. Images are rebuilt, scanned for HIGH and CRITICAL vulnerabilities, and republished on a regular cadence so that new launches start current. Manage the service with systemd and administer locally with: sudo mysql.
Highlights
Production-ready: systemd-managed MySQL 8.4 LTS; data directory initializes on first boot; local root via auth_socket.
Security-hardened at build time: minimal packages, key-only SSH, IMDSv2-only, no default database passwords; MySQL listens on 127.0.0.1 only, so port 3306 refuses remote connections until you change bind-address (the 1-Click security group pre-opens TCP 3306 - narrow it to trusted CIDRs first).
Continuously patched: rebuilt, vulnerability-scanned, and republished on a regular cadence.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for a hardened MySQL 8.4 Community image running on Amazon Linux 2023. The three dimensions are all EC2 compute sizes: c7i.xlarge, c7i.2xlarge, and c7i.4xlarge. They differ only in instance size, so you choose the one that matches your workload. Larger instances carry more vCPU and memory and bill at a higher hourly rate. Fees accrue only while an instance runs, metered by AWS. Cloud infrastructure like compute, storage, and network is billed separately by AWS under your own account.
Top-of-mind questions for buyers
What compute resources come with each c7i instance size?
Each dimension maps to an EC2 instance running the hardened MySQL image. The c7i.xlarge, c7i.2xlarge, and c7i.4xlarge sizes step up in vCPU and memory. You pick the size that fits your database workload, and the hourly rate rises with the larger sizes.
Am I charged when my MySQL instance is stopped?
Software fees accrue only while an instance runs, metered by AWS. A stopped instance stops accruing software charges. Stopped instances may still incur AWS storage fees for attached volumes, billed separately under your own account. The licence meters running time only.
What is not included in the hourly software fee?
The fee covers the hardened MySQL software licence only. AWS bills you separately for cloud infrastructure the instance uses, including compute, storage, and network. The software runs entirely in your own AWS account under your IAM, VPC, and billing controls. Taxes are handled by AWS.
www.dcassociatesgroup.com+1
Helpful?
Vendor refund policy
Usage-based hourly billing; charges stop when instances are terminated. Contact support@dcassociatesgroup.com for billing questions.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
[Security] Refreshed image: rebuilt on the latest hardened Amazon Linux 2023 baseline; all OS packages current at build.
Additional details
Usage instructions
Launch from AWS Marketplace (1-Click or EC2 console).
Connect via SSH with your EC2 key pair: ssh -i <key> ec2-user@<public-ip>. Root login is disabled; use sudo.
The data directory initializes on first boot and a one-shot unit (mysql-firstboot.service) switches root to auth_socket; it is finished when /var/lib/mysql-firstboot.done exists (check progress with: sudo journalctl -u mysql-firstboot). Administer locally with: sudo mysql (local root via auth_socket; no root password exists).
Remote access (port 3306) and user creation are a deliberate customer configuration step: set bind-address in /etc/my.cnf AND /etc/my.cnf.d/zz-hardening.cnf (both pin 127.0.0.1), restart mysqld, create a non-root user with a strong password, and narrow the 1-Click security group's TCP 3306 rule (pre-opened from anywhere) to trusted CIDRs before you do. MySQL X protocol (33060) is disabled.
Verify: sudo mysql -e 'SELECT VERSION();'.
Sensitive data: no passwords or secrets ship in the image. During first-boot initialization MySQL writes a temporary root password to /var/log/mysqld.log; it is invalidated in the same boot when root is switched to auth_socket.
Backup: snapshot the EBS volume (it contains all configuration and data).
Resources: a single instance uses 1 EC2 instance and 1 gp3 EBS volume; no other AWS resources are created.
Support by Derek Coleman & Associates Incorporated. Email: support@dcassociatesgroup.com. Business-day response. Covers image operation, hardening baseline, and launch issues.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This is a repackaged software product wherein additional charges apply for a pre-hardened, SI Core STIG Hardened image and seller support. PostgreSQL on Amazon Linux 2023 offers a robust and secure database solution designed for scalability and performance within the AWS ecosystem. Leveraging the latest technology and security standards, PostgreSQL on Amazon Linux 2023 ensures high availability and easy management for your data workloads. Ideal for developers and enterprises, this AMI simplifies the deployment process, allowing you to focus on building applications while reducing operational overhead. With PostgreSQL on Amazon Linux 2023, you can efficiently handle complex queries and large datasets, all while benefiting from the agility and flexibility of the cloud.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.