Skip to content

AWS

Primcoat builds your hardened image, uploads it to Amazon S3, and registers it as an AMI in every region you deploy to.

Uploads to
Amazon S3
Registers as
an Amazon Machine Image (AMI)

Primcoat builds your hardened image, uploads it to Amazon S3, and registers it as an AMI in each region you deploy to. You reference the result from a launch template, an autoscaling group, or your infrastructure-as-code, exactly as you would any other AMI.

Enhanced networking (ENA) is already in the kernel of the hardened base — nothing to install — and Primcoat registers the AMI with EnaSupport so EC2 enables it. Optional AWS guest agents such as the Systems Manager agent are added during the build, before hardening, so they are scanned and signed with the rest of the image.

What you configure

A publish target holds the AWS account credentials, the destination regions, and the S3 bucket used for staging. You define the image name, and add version information and other details as you like.

Machine-readable:/integrations/aws.md

Get started now.

Request access, describe the image you want, and have your first hardened image in about 15 minutes — a typical estimate, before publishing to your clouds. Primcoat builds, hardens, scans, signs, and publishes it, on the operating systems you already run.