FreeIPA, an open source identity management suite, building its own directory, Kerberos realm and certificate authority on first boot.
FreeIPA combines an LDAP directory, a Kerberos key distribution centre and a certificate authority into a single managed identity domain. Organisations use it to give Linux fleets central accounts, single sign on, host based access control, centrally managed sudo rules and certificates that are issued and renewed automatically.
cloudimg ships FreeIPA hardened and fully patched, with nothing baked into the image: the realm, the certificate authority, the Kerberos master key and both administrator passwords are generated on your own instance at first boot, so no two deployments share a secret. Passwords never reach a command line or the system log, the host firewall opens only the ports an identity domain needs, and the image is supported 24/7.
Real screenshots taken while testing this image against its deployment guide.