  • Build an instance from a standard AMI
  • modify as needed
  • Stop running instance
  • Follow AWS's security instructions
    • more specifically: remove the server's ssh keys in /etc/ssh
  • Create image (from AWS console. This creates an AMI too.)
  • Restore ssh keys after imaging:
~# ssh-keygen -t rsa -f /etc/ssh/ssh_host_rsa_key
~# ssh-keygen -t dsa -f /etc/ssh/ssh_host_dsa_key
  • Set image to public (AWS Console)
    • Be sure to note which availability zone it's in!
