What is EC2 instance
Elastic Compute Cloud is the most popular service offered by the aws. It is infrastructure as a service where aws lets you rent virtual machine for a pay as you go model pricing.
EC2 Instance Configuration
When you launch an instance, there are a few main things to choose.
AMI (Amazon Machine Image): This is the template your instance boots from. It contains the operating system and some preinstalled software. Amazon Linux, Ubuntu and Windows Server are common choices.
Instance type: This decides the hardware configuration. For example, t3.micro or m5.large.
t is burstable, good for small workloads and labs
m is general purpose
c is compute optimized
r is memory optimized
Storage: Most instances use EBS volumes. These are network drives and the data stays when you stop the instance. Some types have instance store, which is fast but the data is lost when the instance stops.
Networking: You select the VPC, the subnet and whether the instance gets a public IP. A normal public IP changes after stop and start. An Elastic IP stays the same.
Key pair: This is used for SSH login on Linux. AWS keeps the public key and you keep the private key. If you lose the private key, you lose that way of logging in.
Purchasing options: On-Demand is pay as you go. Reserved and Savings Plans are cheaper for steady usage. Spot uses spare AWS capacity at a big discount, but AWS can take it back with short notice.
EC2 Bootstrapping
EC2 bootstrapping also known as user data script is any commands that gets executed when instance is started for the first time. It runs as a root user.
Security Groups for EC2
A security group is a firewall for the ec2 instances which filters incoming and outgoing traffic according to the rules that is attached to the security group.
Connecting to EC2 Instance
You can connect to EC2 Instance using SSH. Download RSA key value pair while setting up the EC2 instance and then using ssh command to connect to it.
IAM Roles for EC2 Instance
Applications on an instance often need to call other AWS services, like reading from S3 or writing to DynamoDB. The wrong way is to store access keys on the server. Keys leak through code repos, logs and compromised machines.
The right way is an IAM role. You create a role with the permissions the app needs and attach it to the instance using an instance profile. The instance gets temporary credentials automatically and they rotate on their own.






Top comments (0)