Skip to main content
An Amazon Machine Image is an EC2 launch artifact; Amazon Linux is an operating-system distribution. An AL2023 AMI combines a Linux filesystem and kernel with EC2 launch metadata and snapshots. Updated October 9, 2026. An AMI is a Region-specific image definition used to create instances and initial volumes, not a running server.

AMI versus Amazon Linux

An AMI records Region, architecture, operating system, root-device type, virtualization type, boot mode, and block-device mappings. Launch permissions determine which accounts can use it. Copying an image to another Region creates another AMI ID. Amazon Linux 2023 is the maintained RPM-based distribution inside AWS-published AMIs and container images. Its lifecycle, packages, repositories, and kernels continue independently of one AMI registration. Amazon Linux is not one AMI ID; AWS publishes variants by Region, architecture, kernel line, and package set.

AMI components and root devices

Current AL2023 EC2 images are HVM AMIs. For EBS-backed images, the root mapping references an EBS snapshot. At launch, EC2 creates and attaches a new root volume. The mapping can include size, type, performance, encryption, and delete-on-termination settings. AMIs can describe additional EBS or instance-store devices. Creating an AMI captures included EBS data in snapshots; instance-store data is not preserved. Deregistering an AMI and deleting its snapshots are separate operations. An AMI is a registration object tied to snapshots and launch metadata, not merely a compressed root filesystem.

Boot and first-launch flow

AL2023 uses a UEFI-preferred boot mode on supported instance types while retaining documented compatibility with legacy BIOS. Architecture must match the instance type. AL2023 includes customized cloud-init. It configures locale, hostname, ec2-user, SSH keys, repositories, package directives, mounts, and user-data scripts. User data is not part of the AMI snapshot. EC2 running does not prove cloud-init or application startup completed successfully.

SSM parameters and image selection

AWS publishes public Systems Manager parameters under /aws/service/ami-amazon-linux-latest/. Parameter names encode package set, kernel selector, and architecture. These parameters are useful when deployments should adopt the current AWS image. They are dynamic references, so record the resolved AMI ID when exact replay matters.

Versioned package repositories

AL2023 locks DNF to the repository release used to build the AMI. Installing a package later draws from that coherent release unless an operator deliberately changes releasever. This improves consistency but means an old instance does not receive fixes merely because AWS published a newer repository. Operators must update the selected release and packages or replace the instance. Kernel lifecycle is separate. Changing the default AMI kernel affects new launches, not existing instances, which need explicit package changes and reboots. A newer public AMI does not automatically update already running instances.

Baking and reproducibility

A disciplined pipeline records the base AMI, pins the repository release, applies a version-controlled recipe, installs explicit packages, tests the result, and registers a new AMI. For immutable fleets, replace instances with newly baked images. For longer-lived hosts, schedule release updates, package updates, kernel reboots, and reconciliation. Launch reproducibility pins an AMI ID and launch-template version. Build reproducibility also pins repositories, packages, external artifacts and checksums, architecture, and builder configuration. A parameter named latest optimizes currency; a pinned AMI and repository optimize replay.

Frequently asked questions

No. AL2023 is an operating-system distribution with a lifecycle, kernels, packages, and versioned repositories. AWS publishes multiple AMIs containing AL2023. Each AMI is a Region-specific registration with snapshots, architecture, boot properties, mappings, and permissions.
No. AL2023 locks package management to the repository release used to build that AMI. Cloud-init can run explicit update commands, but the operator must deliberately select a newer release or replace the instance with a newer image.
Use it when new deployments should adopt AWS’s current image automatically. For repeatable rollouts, resolve the parameter during controlled promotion, record the Region-specific AMI ID, test it, and pin it in the approved launch template or recipe.

Sources and further reading

Last modified on October 8, 2026