AWS Cloud Practitioner (CLF-C02) Notes, Part 3: Amazon EC2 Domain 3: Cloud Technology & Services (34%). Pricing also feeds Domain 4 (12%). Amazon EC2 (Elastic Compute Cloud) is AWS's core IaaS service. You rent virtual servers, called instances, and pay only while they run. The services that work alongside EC2 (EBS disks, load balancers, Auto Scaling) come in the next parts. 1. What you configure at launch Setting What it decides ------ AMI The OS image: Linux, Windows or macOS Instance type CPU and memory (section 2) Storage Network-attached (EBS, EFS) or hardware-attached (instance store) Network Public IP address and network performance Security group Firewall rules (section 3) Key pair SSH login to Linux, or decrypting the Windows admin password IAM role Permissions for applications running on the instance User data A bootstrap script that runs once, at first boot, as root. Typically installs updates and software or downloads files Instance states: Stop: compute billing stops. EBS volumes keep their data, and they keep costing money. Terminate: the instance is deleted. Its root volume is deleted by default. 2. Instance types The name m5.2xlarge breaks down as: m = family, 5 = generation, 2xlarge = size. Family Optimized for Typical uses --------- General purpose (T, M) A balance of CPU, memory and network Web servers, code repositories Compute optimized (C) Fast processors Batch processing, media transcoding, HPC, ML, gaming servers, high-performance web servers Memory optimized (R, X) Large data sets held in RAM High-performance databases, in-memory caches and databases, real-time big data processing Storage optimized (I, D) High sequential read/write to local storage OLTP, relational and NoSQL databases, data warehousing, distributed file systems Accelerated computing (P, G, Inf, Trn) GPUs and AI chips ML training and inference, graphics EC2 Mac instances run macOS. They're the answer whenever a question asks how to build iOS or macOS apps on AWS. 3. Security groups A security group is a virtual firewall attached to instances. Traffic it blocks never reaches the instance. It has allow rules only. You can't write a deny rule. It is stateful: return traffic for an allowed connection is allowed automatically. Defaults: all inbound traffic blocked, all outbound traffic allowed. Rules can reference IP ranges (IPv4 or IPv6) or other security groups. One security group can cover many instances, and one instance can have several security groups. They're scoped to a Region and VPC. Troubleshooting: a timeout means a security group is blocking the traffic. "Connection refused" means the traffic got through but the application isn't running. Security group Network ACL (covered with VPC) ------ Instance level Subnet level Allow rules only Allow and deny rules Stateful Stateless Ports to know: 22 SSH (Linux login) · 21 FTP · 22 SFTP · 80 HTTP · 443 HTTPS · 3389 RDP (Windows login) Connecting to an instance: An SSH client on macOS, Linux or Windows 10+ PuTTY on older Windows EC2 Instance Connect, a browser-based SSH session where AWS pushes a temporary key. Port 22 must still be open. 4. Purchasing options Option Commitment Discount vs On-Demand Best for Key facts --------------- On-Demand None None. Highest price, nothing upfront Short-term, unpredictable workloads that can't be interrupted. This is the default Linux and Windows are billed per second (60-second minimum); other OSs per hour Reserved Instances (Standard) 1 or 3 years Up to 72% Steady-state workloads such as databases Locked to instance type, Region, tenancy and OS. Scope is Regional or Zonal (Zonal also reserves capacity). Can be sold on the RI Marketplace Convertible RIs 1 or 3 years Up to 66% Long-term workloads that may change Can be exchanged for a different family, OS or tenancy within the same Region. Can't be sold on the Marketplace Savings Plans 1 or 3 years, committing to a $/hour spend Up to 72% Long-term usage that needs flexibility Usage above the commitment is billed at On-Demand rates. EC2 Instance Savings Plans cover one family in one Region. Compute Savings Plans cover any family and Region, plus Fargate and Lambda Spot Instances None Up to 90% Work that tolerates interruption: batch jobs, data analysis, image processing, stateless or distributed jobs, flexible timing AWS can reclaim them with a 2-minute warning. Never use them for databases or critical jobs Dedicated Hosts On-Demand, or a 1- or 3-year reservation None (the most expensive option) BYOL (per-socket, per-core, per-VM licenses) and strict compliance You get an entire physical server, can see its sockets and cores, and control instance placement Dedicated Instances None None Hardware that no other customer shares May share hardware with your own other instances. No placement control Capacity Reservations None (cancel anytime) None. Billed at the On-Demand rate Guaranteed capacity in a specific AZ You pay whether or not you use the capacity. Combine with Regional RIs or…