❌

Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Aujourd’hui — 4 octobre 2026Ubuntu

Attach an Ubuntu Pro subscription to your AWS Image Builder image

21 septembre 2026 à 16:35

We are pleased to announce that you can now attach an Ubuntu Pro subscription directly to any base image in AWS Image Builder, allowing you to create enterprise-grade custom images from the get go.

Why this is important

Until now, getting Ubuntu Pro into a custom AMI (Amazon Machine Image) meant either starting from an Ubuntu Pro base image or manually applying a token during the build. You can now attach an Ubuntu Pro subscription to any base image directly in your build pipeline even if the base image is a non-Ubuntu Linux image.

This unlocks simpler and more flexible AMI builds: add Ubuntu Pro as just another component to the recipe, with no manual steps required. This makes Ubuntu Pro straightforward to integrate into CI/CD pipelines and automated provisioning workflows.

Note: Attaching Ubuntu Pro to a non-Ubuntu host only licenses the cluster to run Ubuntu Pro containers. It does not give the host access to Ubuntu Pro services like Expanded Security Maintenance, compliance hardening, or Kernel live patching.

Before you begin

Make sure you have the following in place:

  • An AWS account with permissions to use EC2 Image Builder and AWS Marketplace.
  • IAM permissions which allow Image Builder to access Marketplace components (imagebuilder:GetComponent, aws-marketplace:Subscribe).
  • A base image ready to use (EC2 Managed image, Marketplace AMI, or a custom AMI).
  • If your base image is Ubuntu, ubuntu-pro-client should be installed for the Pro client to activate services on first boot.

How to get it

Step 1: Subscribe to the marketplace listing

Subscribe to the component that matches your target architecture:

Step 2: Create or edit an image recipe

You can do this using the AWS Web Console or the AWS CLI. The overall flow is the same:

  1. Create an image pipeline (or open an existing one).
  2. Create a new recipe or edit an existing one:
    1. Select a base image (EC2 Managed image, Marketplace AMI, or a custom image).
    2. Select the image name (the operating system to use as a base).
    3. Add user data if needed.
    4. Add your components – this is where the Upgrade to Ubuntu Pro component comes in. 

If you are using the AWS Web console, open the Source dropdown and select AWS Marketplace. This will display all available Marketplace components. Search for Ubuntu Pro and select the component that matches your base AMI architecture (AMD64 or ARM64).

If you are using AWS CLI, you will need to take note of the Ubuntu Pro component ARN to use it in your API call.

Step 3: Continue with the rest of the details as usual

The next step should be familiar: configure custom workflows, infrastructure details, and distribution settings.

Step 4: Build and distribute

Once you have added the Ubuntu Pro component to your recipe, the rest of the workflow follows the instructions of the standard Image Builder:

  1. Add any additional components for your own configurations and deployments.
  2. Configure a distribution setting (regions, AMI name, etc.).
  3. Configure a test pipeline (optional but recommended).
  4. Run the pipeline and let Image Builder produce the image.

Once the image is built, the Ubuntu Pro subscription will be attached to the resulting AMI as instance metadata. If your base image is Ubuntu and the Pro client is installed, the default Ubuntu Pro services will be activated on the next boot.

If you want to learn more in detail about how to build a recipe with the Ubuntu Pro component, read more in our official documentation page.

Validating your license

To confirm the Ubuntu Pro license was attached correctly, check whether the right Marketplace product code is present on your AMI.

Using the AWS console

Go to EC2 → AMIs, select your AMI, and look at the Product codes field in the details panel below. You should see one of the following:

  • Marketplace:9bztusbna2lfuk6zw7upzdvsv — AMD64 images
  • Marketplace:291iwywwdb7ujmih1x7z4l3my — Graviton (ARM64) images

Using the AWS CLI

aws ec2 describe-images \
  --owners self \
  --query 'Images[*].{ImageId: ImageId, Name: Name, ProductCodes: ProductCodes[*].ProductCodeId}' \
  --output text

Learn more

Beyond the 10-year mark: Extending Ubuntu Pro 16.04 LTS security coverage

17 septembre 2026 à 19:46

A decade ago, Canonical launched Ubuntu 16.04 LTS (codenamed “Xenial Xerus”). As a Long-Term Support (LTS) release, it comes with 5 years of standard security coverage, which is doubled to a total of 10 years through Expanded Security Maintenance (ESM) for users with an Ubuntu Pro subscription.

As of April 30, 2026, the 10-year ESM coverage for Ubuntu 16.04 LTS, under Ubuntu Pro, has officially reached its end of support.

While Ubuntu 16.04 LTS images can still be launched on the public clouds, they are now marked as deprecated and will no longer receive any security patches, bug fixes, or maintenance updates. There are two paths you can follow to keep your Ubuntu estate security maintained.

Path 1: Upgrade to a newer supported Ubuntu LTS

Canonical strongly recommends migrating workloads to a newer, supported LTS version (such as 22.04 LTS, 24.04 LTS or 26.04 LTS) to benefit from modern security frameworks, updated software stacks, and performance improvements. There are two options when upgrading:

  • Fresh installation: Redeploying your workloads on a brand-new instance of a modern Ubuntu LTS ensures a clean slate and optimal configuration.
  • In-place migration: If redeployment isn’t immediately feasible, you can perform an upgrade on your existing instances. Learn how to perform an in-place migration by reading our Ubuntu LTS Upgrade Guide.

Path 2: Get 5 additional years of maintenance with the Legacy add-on

We understand that complex enterprise architectures, legacy applications, and regulatory dependencies can make immediate migration impossible. If you cannot redeploy your workloads right away, Canonical offers a further five years of security maintenance and support with the Legacy add-on on top of an active Ubuntu Pro subscription.

The Ubuntu Pro Legacy add-on brings the total lifecycle of the release to 15 years. This add-on ensures your Ubuntu 16.04 LTS environments continue to receive critical security patches until 2031 – giving you time to safely plan and execute your migration strategy.

  • How to get it: If you need to keep running Ubuntu 16.04 LTS securely, contact the Canonical team directly via the Canonical Support Form to get the Legacy add-on.

Next steps

Leaving your infrastructure on an unsupported operating system can expose you to security threats. Take control of your migration timeline today:

  1. Assess your inventory: Identify any remaining Ubuntu 16.04 LTS machines or images in your environment.
  2. Choose your path: Begin scheduling upgrades to a newer LTS, or bridge the gap securely with Ubuntu Pro and a Legacy add-on.
  3. Read the full announcement: Learn more about how Canonical is expanding total coverage for legacy releases in our official announcement.
❌
❌