WSO2 Micro Integrator

AWS Application Servers

config driven integration runtime for APIs, proxy services and enterprise integration patterns

Base
Hardened build
minimal ports, security patches applied at build time
Access
Unique credentials
generated on first boot, readable only by root
Verified
Boots working
services pass a health gate before release
Support
24/7, 365 days
by email and live chat, 24 hour response SLA

Overview

WSO2 Micro Integrator is a lightweight, cloud native, configuration driven integration runtime, an enterprise service bus for building and running REST and SOAP APIs, proxy services, message mediation and enterprise integration patterns. It hot deploys integration artifacts onto a Synapse passthrough transport and routes, transforms and enriches messages between backend systems.

Why the cloudimg image

cloudimg ships the runtime hardened and ready to run: the management API administrator password is rotated to a unique value on first boot, a scoped loopback guard keeps the management and internal APIs off the public interface behind an nginx front, the runtime runs as an unprivileged service account, and a paired deployment guide plus 24/7 support come with every image.

Common uses

  • Exposing REST and SOAP APIs that mediate and route to backend systems
  • Enterprise integration patterns: routing, enrichment, aggregation and protocol switching
  • Lightweight configuration driven ESB workloads on virtual machines

Key features

  • Zero-setup integration runtime: the WSO2 Micro Integrator launches as a systemd-managed service with the correct Java runtime, a dedicated service account and a baked sample health-check API on the data plane. Skip hours of manual installation, systemd authoring and hardening that a DIY EC2 deployment requires - the runtime is accepting traffic within minutes of launch.
  • Hardened, loopback-guarded management plane: a one-shot first-boot service generates a unique management-API administrator password per instance and writes it into the configuration before the runtime starts, so no shared or default credentials ever ship. A scoped packet-filter guard keeps the management and internal APIs off the public interface, reachable only through the nginx front on port 80.
  • Config-driven enterprise integration: deploy REST APIs, proxy services, sequences and enterprise integration patterns as hot-deployable artifacts on the Synapse passthrough transport. Backed by 24/7 cloudimg technical support via email and live chat for deployment, artifact packaging, TLS and JVM administration.

Description

This is a repackaged open source software product wherein additional charges apply for cloudimg support services.

## WSO2 Micro Integrator - Production-Ready Integration Runtime AMI

Deploy a fully configured, cloud-native integration runtime on AWS in minutes - not hours. This AMI delivers the WSO2 Micro Integrator preinstalled and running as a managed system service, so you can start deploying integration artifacts (REST APIs, proxy services, message mediation and enterprise integration patterns) immediately after launch.

### Why This AMI Instead of a DIY Install

  • Versus manual EC2 setup: Skip the hours of downloading the distribution, installing the correct Java runtime, writing systemd units, hardening the management API and rotating credentials. This image handles all of that at launch.
  • Versus a bare runtime: Benefit from a hardened first-boot process that generates a unique management-API administrator password per instance (no shared or default credentials), a scoped loopback guard that keeps the management API off the public interface, and an nginx front for controlled management access.
  • Versus other community images: A dedicated unprivileged service account, a baked sample health-check API that proves the data plane on first boot, and 24/7 professional support from cloudimg.

### Application Stack

  • WSO2 Micro Integrator installed under /opt/wso2mi, run by a dedicated unprivileged service account
  • Headless OpenJDK Java runtime
  • systemd service that starts the runtime on boot and restarts on failure
  • A first-boot service that rotates the management-API administrator password before the runtime starts
  • nginx reverse proxy publishing the loopback-bound management API on port 80

### Two Planes

Integration / data plane: the Synapse passthrough transport on HTTP 8290 and HTTPS 8253, bound to all interfaces so your deployed APIs, proxy services and sequences receive traffic. A sample health-check API is baked in so a GET to /health on port 8290 returns 200 immediately after launch, proving the data plane flows.

Management API: HTTPS 9164, used by the MI command-line tool. The runtime binds this to all interfaces with no configuration key to change that, so a scoped packet-filter guard drops external traffic to the management ports and nginx on port 80 provides a controlled front. The management API is therefore never directly reachable off the instance.

### Security

Secure First Boot: A one-shot service generates a fresh management-API administrator password unique to each instance, writes it into the runtime configuration before the runtime starts, and stores it in a root-only file. No shared or default credentials ship in the image, and the default administrator login is rejected.

Management-Plane Isolation: A scoped packet-filter guard restricts the management and internal APIs to loopback, so they are reachable only through the nginx front on port 80. Restrict that front, plus the data-plane ports, to trusted networks with your security groups.

Encryption: Enable AWS EBS encryption on the root volume to protect configuration and artifacts at rest, and terminate TLS at nginx or your load balancer for encrypted management access.

### Use Cases

  • Exposing REST and SOAP APIs that mediate, transform and route to backend systems
  • Enterprise integration patterns: content-based routing, message enrichment, aggregation and protocol switching
  • Lightweight, config-driven ESB workloads in containers or on virtual machines

### 24/7 cloudimg Support

Technical support by email and live chat covers deployment, integration-artifact packaging and hot deployment, management-API and credential administration, TLS termination, and JVM tuning.

All product and company names are trademarks or registered trademarks of their respective holders. Use of them does not imply any affiliation with or endorsement by them.

Related technologies

integration runtimeesbenterprise service busapi gatewaymessage mediationsynapseenterprise integration patternsmicroservices integrationrest apisoap proxyeaiintegration middlewarewso2