Prerequisites
- An account on the target cloud with permission to launch VM instances (no special IAM roles are required by this product unless stated below — IAM required: none).
- An SSH key pair registered in the target cloud (all access is key-only; password SSH is disabled).
- Instance size ≥ 4 vCPU (pricing floor; 8 vCPU recommended).
- No internet access or external dependency is required at deploy time — the image is self-contained.
AWS
- Subscribe and launch with 4 vCPU+ and RAM ≥ 8 GB (heap sizing: ~50% of RAM).
Expected result curl http://127.0.0.1:9200/ on the instance returns the cluster banner. - For network access: configure the security plugin (TLS + users) FIRST, then set network.host and open 9200 to your app subnet only. Never expose 9200 without auth.
Expected result Remote client authenticates over TLS; anonymous requests are refused.
Validate
curl -s http://127.0.0.1:9200/_cluster/health | jq .status → green (single node: yellow for replicated indices is normal)
First boot: Node data directory initializes fresh on first start (build-time state is wiped). vm.max_map_count preset via sysctl.
Secure it
- Restrict SSH (22) to your own IP range in the cloud firewall/security group.
- Open application ports only per the ports table — closed-by-default is deliberate.
- Volume encryption: use your cloud's native volume encryption (enabled by default on most accounts); the image adds no proprietary encryption layer.
Costs & quotas
Software is billed by the marketplace at the listed rate; infrastructure (VM, storage, egress) is billed
by your cloud at its standard rates. The recommended size fits default service quotas in most accounts —
if you scale out, review your cloud's quota console before launch.
Next: configuration · troubleshooting · security notes