Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
This product has charges associated with it for hardening, security configuration, and support.
AnythingLLM is a self-hosted ChatGPT-style workspace for chatting with your documents using any LLM provider, with built-in RAG, AI agents and vector search in a single hardened container. Unlike bare AnythingLLM AMIs that ship without TLS, no admin auth, and the server on 0.0.0.0:3001, this Lynxroute build is ready out of the box: admin user with unique password at first boot, server bound to loopback behind Nginx TLS, embedded LanceDB and native embedder pre-configured, on a CIS Level 1 hardened Ubuntu 24.04 LTS base.
MIT license - fully auditable, no vendor lock-in.
This product has charges associated with it for hardening, security configuration, and support.
Apache Airflow is the leading open-source platform to programmatically author, schedule, and monitor data-pipeline workflows (DAGs), running Airflow 3.2 on Python 3.12 with the LocalExecutor and a local PostgreSQL metadata database. Unlike bare Airflow AMIs that expose the web server with no TLS and ship a default encryption key, this Lynxroute build is hardened out of the box: the api-server is bound to loopback behind an nginx TLS perimeter on 443, PostgreSQL is bound to 127.0.0.1, the Fernet key, API secret key, database password, and admin login are all generated uniquely at first boot, services run as a non-root user, and the base is CIS Level 1 hardened Ubuntu 24.04 LTS.
Apache-2.0 license - fully auditable, no vendor lock-in. Built on Apache Airflow(R), a trademark of The Apache Software Foundation.
This product has charges associated with it for hardening, security configuration, and support.
Apache Cassandra is the open-source, distributed NoSQL wide-column database (Apache Software Foundation), running here as a single-node JVM service on Eclipse Temurin 17. Unlike bare Cassandra AMIs that ship the default cassandra/cassandra superuser, no authentication, no encryption, and an exposed JMX port, this Lynxroute build is security baked in: the default superuser password is rotated to a strong random value at first boot, password authentication and authorization are enabled, native TLS (client encryption) is required on port 9042, CQL and JMX bind to localhost only, UFW firewall pre-configured, and a CIS Level 1 hardened Ubuntu 24.04 LTS base.
Apache-2.0 license - fully auditable, no vendor lock-in.
This product has charges associated with it for hardening, security configuration, and support.
Apache Flink is a distributed engine for stateful stream and batch processing, run here as a single-node standalone session cluster - a JobManager plus one TaskManager on OpenJDK 17 - with its Web Dashboard ready to accept jobs. Unlike bare Flink AMIs that expose the Web UI on 0.0.0.0:8081 with no authentication and no TLS, leave the cluster RPC and blob ports reachable, and write working data onto a noexec /tmp, this Lynxroute build is ready out of the box: a unique Basic Auth password generated at first launch, an Nginx TLS reverse proxy on 443, the Web UI and all internal cluster ports bound to localhost only, working directories placed off the hardened /tmp, UFW firewall pre-configured, and a CIS Level 1 hardened Ubuntu 24.04 LTS base.
Apache-2.0 license - fully auditable, no vendor lock-in.
This product has charges associated with it for hardening, security configuration, and support.
Apache Solr is an open-source enterprise search platform built on Apache Lucene - schema-driven full-text search, faceting, and rich document handling on the JVM. Unlike bare Solr AMIs that ship with no authentication, an admin API open on every interface, and no TLS, this Lynxroute build is ready out of the box: a unique admin password at first boot, dual-layer Basic Auth (TLS reverse proxy plus Solr's native BasicAuthPlugin), the search server bound to loopback only, UFW firewall pre-configured, and a CIS Level 1 hardened Ubuntu 24.04 LTS base.
Apache-2.0 license - fully auditable, no vendor lock-in.
This product has charges associated with it for hardening, security configuration, and support.
Appsmith is a self-hosted low-code platform for building internal tools, admin panels, dashboards and CRUD apps - a drag-and-drop UI builder backed by a Java server with embedded MongoDB, PostgreSQL and Redis, connecting to 25+ databases and REST/GraphQL APIs. Unlike bare Appsmith AMIs that ship with default encryption keys, signup left open to anyone, and plain HTTP, this Lynxroute build is ready out of the box: per-instance secrets generated at first boot, the first signup becomes the administrator and further signups auto-close, HTTPS enabled by default, anonymous telemetry disabled, UFW firewall pre-configured, and a CIS Level 1 hardened Ubuntu 24.04 LTS base.
Apache-2.0 license - fully auditable, no vendor lock-in.
This product has charges associated with it for hardening, security configuration, and support.
InfluxDB is the open-source time series database for metrics, events, and IoT/sensor data, with a built-in web UI, HTTP API, and the Flux and InfluxQL query languages (MIT-licensed 2.x line). Unlike bare InfluxDB AMIs that serve plaintext HTTP with no certificate, leave the instance on an unconfigured setup screen, and keep usage telemetry phoning home, this Lynxroute build is ready out of the box: native TLS with a per-instance self-signed certificate generated at first boot, an admin user, password, and all-access operator token created at first boot, telemetry disabled, UFW firewall pre-configured, and a CIS Level 1 hardened Ubuntu 24.04 LTS base.
MIT license - fully auditable, no vendor lock-in.
This product has charges associated with it for hardening, security configuration, and support.
Joomla is a popular open-source content management system (CMS) - a PHP 8.3 web application served by Nginx and PHP-FPM with a MariaDB database. Unlike bare Joomla AMIs that ship the web installer wide open, run plain HTTP with no certificate, and leave the database and admin account unconfigured, this Lynxroute build is ready out of the box: a Super User and database credentials generated at first launch, the installer removed automatically, HTTPS on by default with a self-signed certificate, Certbot pre-installed for trusted TLS, MariaDB bound to localhost only, UFW firewall pre-configured, and a CIS Level 1 hardened Ubuntu 24.04 LTS base.
GPL-2.0-or-later license - fully auditable, no vendor lock-in.
This product has charges associated with it for hardening, security configuration, and support.
Meilisearch is a lightning-fast, typo-tolerant search engine shipped as a single Rust binary, exposing a developer-friendly REST API for full-text, semantic, and hybrid search. Unlike bare Meilisearch AMIs that run in development mode with no master key, leave the API open on a public port with no TLS, and report anonymous analytics by default, this Lynxroute build is ready out of the box: production mode with a strong master key generated at first boot, the engine bound to localhost behind an nginx TLS reverse proxy on 443, analytics disabled, UFW firewall pre-configured, and a CIS Level 1 hardened Ubuntu 24.04 LTS base.
MIT license - fully auditable, no vendor lock-in.
This product has charges associated with it for hardening, security configuration, and support.
Ollama + Open WebUI is a complete private AI stack - run Llama, Mistral, Gemma, and 100+ LLMs locally with a ChatGPT-like interface. No OpenAI subscription, no data leaving your VPC. Authentication enabled, Nginx TLS proxy, Ollama API localhost-only, and CIS Level 1 hardened Ubuntu 24.04 LTS base. Built and maintained by Lynxroute.
Models are not pre-loaded - pull via Web UI or CLI after launch. For GPU inference use g4dn.xlarge or g5.xlarge.
Ollama is MIT-licensed; Open WebUI uses a source-available license (see Long Description for details).
This product has charges associated with it for hardening, security configuration, and support.
OpenHands is a self-hosted autonomous AI agent that writes code, runs commands and uses a browser inside isolated sandbox containers, controlled from a web IDE. It works with any LLM provider - operators bring their own key. Unlike bare OpenHands AMIs that ship without TLS, the sandbox runtime not pre-pulled, and the agent UI exposed without auth, this Lynxroute build is ready out of the box: HTTPS via Nginx with HTTP basic auth, sandbox runtime image baked in and SHA-pinned, agent container bound to loopback, on a CIS Level 1 hardened Ubuntu 24.04 LTS base.
MIT license - fully auditable, no vendor lock-in.
This product has charges associated with it for hardening, security configuration, and support.
Qdrant is an open-source, high-performance vector database for AI and semantic search - used in RAG pipelines, recommendation systems, LangChain, LlamaIndex, and any workload requiring similarity search over embeddings. This Lynxroute build is security baked in: unique API key at first boot, UFW firewall pre-configured, and CIS Level 1 hardened Ubuntu 24.04 LTS base.
Web UI included. fastembed pre-installed for local embedding without external API calls.
Apache-2.0 license - fully auditable, no vendor lock-in.
This product has charges associated with it for hardening, security configuration, and support.
Trino is a fast distributed SQL query engine (single JVM, Java 25) that runs ANSI SQL over data where it already lives - S3, PostgreSQL, MySQL, Iceberg, Delta Lake, Kafka, Hive and 40+ other sources. Unlike bare Trino AMIs that expose port 8080 with no authentication, no TLS, and a default heap that OOMs on the recommended instance, this Lynxroute build is ready out of the box: an admin password generated at first boot, file-based password authentication for CLI/JDBC/BI clients, TLS terminated at nginx, the JVM heap and query memory auto-sized to the instance, UFW firewall pre-configured, and a CIS Level 1 hardened Ubuntu 24.04 LTS base.
Apache-2.0 license - fully auditable, no vendor lock-in.