16.3 Create a MySQL database
Open the RDS console, then Databases, then Create database. Button names below may vary. Choose Standard create (not Easy create) so every option is visible.
| Setting | Value for this lab |
|---|---|
| Engine | MySQL |
| Templates | Free tier if the page offers it and your account is eligible; otherwise Dev/Test |
| DB instance identifier | appdb (the name in the console, not the SQL schema) |
| Master username | admin |
| Master password | A long password you type yourself. Do not reuse a password from another site |
| Instance class | db.t3.micro or db.t4g.micro |
| Storage type | gp3, 20 GiB is enough |
| Storage autoscaling | Off for the lab |
| Connectivity | Same VPC as your EC2. Skip "connect to an EC2 compute resource" if you see it. We will set the rule ourselves |
| DB subnet group | default, or the private subnets from Chapter 15 |
| Public access | No |
| VPC security group | Create rds-lab-sg (you will edit it in a moment) |
| Database authentication | Password |
| Initial database name | appdb |
| Backup retention | 1 day is enough for the lab |
| Deletion protection | Off for the lab, so you can delete it later |
| Encryption | Leave the default. On is fine |
Choose Create database and wait until the status is Available. This takes several minutes.
Don't worry. The status looks stuck on Creating, but that is normal. Continue once it says Available.
घबरू नका. Status Creating वर थांबल्यासारखा दिसतो, पण ते normal आहे. Available झाल्यावर पुढे जा.
घबराओ मत. Status Creating पर अटका हुआ लगता है, पर यह normal है. Available होने पर आगे बढ़ो.
Free-tier caution
db.t3.micro and db.t4g.micro are the small classes usually listed for the free tier, but eligibility and limits change. Read the free-tier note on the create page before you confirm. A class that is not eligible is billed as soon as the instance is available. Leave Multi-AZ off for this lab. A standby is a second instance. When the lab is finished, stop or delete the database (section 16.8).
Master username
On RDS for MySQL, admin is accepted. Do not use rdsadmin. RDS reserves that account for itself. There is no root login the way there is on the EC2 install from Chapter 10. If another engine rejects admin, pick dbadmin.
Security group: port 3306 only from EC2
Public access is No, so the database has a private address only. That is not enough by itself. Edit rds-lab-sg:
- EC2 console, Security groups,
rds-lab-sg, Edit inbound rules. - Type MySQL/Aurora, port 3306, source = the security group of your EC2 instance (type
sg-and pick it). Not your own IP, and never0.0.0.0/0. - Save.
A private database with a world-open security group is still a bad habit. Private, and locked to the EC2 security group, is the combination this lab wants. Chapter 15 used the same chaining idea: the database allows traffic only from the tier in front of it.
Copy the Endpoint and Port from the Connectivity & security tab. The endpoint looks like this:
appdb.abc123xyz.ap-south-1.rds.amazonaws.com
The middle token is assigned by AWS. Yours will differ. The port is 3306. Always store this hostname in the application. Do not paste the IP address it resolves to. After a failover the IP can change, and the hostname follows the new host.
Lab
Chala, create the MySQL instance with the table above. Confirm Public access is No, storage is gp3, autoscaling is off, and deletion protection is off. Then add the inbound rule for port 3306 from the EC2 security group only. Copy the endpoint into a text file on your laptop.