Deploy SOPS on Amazon EC2

SyncSign does not currently publish a ready-to-launch SOPS Amazon Machine Image (AMI) in AWS Marketplace. You cannot create a SOPS instance by selecting an official SyncSign AMI in the EC2 console.

Customers with AWS administration experience may deploy SOPS by importing the virtual machine image supplied by SyncSign into their own AWS account. The resulting AMI is a private, customer-managed image rather than an AMI published or maintained in AWS Marketplace by SyncSign.

Important

This deployment method requires experience with Amazon EC2, IAM, Amazon S3, VPC networking, security groups, and AWS VM Import/Export. The customer is responsible for the AWS import process and ongoing AWS infrastructure operation.

Before You Begin

Prepare the following:

  • A valid SOPS license and the SOPS virtual machine image supplied by SyncSign.

  • An AWS account with permission to use Amazon EC2, Amazon S3, IAM, and VM Import/Export.

  • An S3 bucket and the IAM service role required by AWS VM Import/Export.

  • A target AWS Region, VPC, subnet, security group, and suitable EC2 instance configuration.

  • A stable IP address or domain name for SOPS.

  • If the selected calendar integration requires a public HTTPS endpoint, a publicly resolvable domain, a certificate issued by a trusted CA, and the required inbound firewall path.

Note

Confirm the supplied image format and any required conversion with SyncSign before deployment. AWS-supported image formats and import requirements are governed by AWS.

Deployment Overview

  1. Obtain the SOPS virtual machine image and license from SyncSign.

  2. Complete the AWS VM Import/Export prerequisites, including the required S3 storage and IAM permissions.

  3. Upload the image to Amazon S3 and follow the AWS Importing a VM as an image procedure to create a private AMI in your AWS account.

  4. Launch an EC2 instance from the imported private AMI. Select the instance type and storage according to the expected number of devices and data sources.

  5. Assign a stable address and configure the VPC, routing, and security group rules required by your deployment. See Firewall Configuration for On-Premise Server (SOPS).

  6. Open the SOPS Portal through the instance address, complete the initial setup, and activate the server with the SOPS license.

AWS Documentation and Support Scope

AWS console screens and VM import requirements may change. Follow the current AWS documentation for the import procedure instead of relying on screenshots in this manual.

SyncSign Support can provide the SOPS image and product-specific deployment information. Configuration and troubleshooting of the customer’s AWS account, IAM policies, S3 buckets, VPC, routing, security groups, and VM Import/Export workflow remain the customer’s responsibility.

If your team cannot perform and maintain this AWS deployment, use a supported local virtual machine or SOPS hardware deployment instead.