How to Create an Amazon RDS MySQL Database and Connect from EC2
To create an Amazon RDS for MySQL database and connect from EC2, first make a security group for the database that allows MySQL/Aurora (TCP 3306) only from the EC2 instance's security group. Then in RDS → Create database choose MySQL, the Free tier or Dev/Test template, Public access: No, the same VPC and that security group. On the Amazon Linux 2023 instance install the client with sudo dnf install mariadb105 -y and connect with mysql -h <RDS-ENDPOINT> -u admin -p.
Come on, friends! We installed MariaDB on EC2 and ran WordPress – but the database backups, updates and patching were all our work. With RDS, AWS does that work; we only use the database. Today we create a private MySQL database and connect to it from EC2. Pay attention: never open the database to the internet – only our web server gets permission.
चला मित्रांनो! आपण EC2 वर MariaDB इन्स्टॉल करून WordPress चालवलं – पण डेटाबेसचा बॅकअप, अपडेट, पॅचिंग सगळं आपण करतो. RDS मध्ये हे काम AWS करतो; आपण फक्त डेटाबेस वापरतो. आज एक प्रायव्हेट MySQL डेटाबेस बनवूया आणि EC2 वरून कनेक्ट करूया. लक्ष द्या: डेटाबेस इंटरनेट वर कधीच उघडा नाही – फक्त आपल्या वेब सर्व्हरला परवानगी.
चलो दोस्तों! हमने EC2 पर MariaDB इंस्टॉल करके WordPress चलाया – पर डेटाबेस का बैकअप, अपडेट, पैचिंग सब हम करते हैं. RDS में यह काम AWS करता है; हम सिर्फ़ डेटाबेस इस्तेमाल करते हैं. आज एक प्राइवेट MySQL डेटाबेस बनाएँगे और EC2 से कनेक्ट करेंगे. ध्यान दो: डेटाबेस इंटरनेट पर कभी खुला नहीं – सिर्फ़ अपने वेब सर्वर को इजाज़त.
Quick answer
After the database shows Available (console steps below), on the EC2 instance:
sudo dnf install mariadb105 -y
mysql --version
mysql -h appdb.abcdefgh1234.ap-south-1.rds.amazonaws.com -u admin -p
# mysql> SHOW DATABASES;
The RDS security group must allow TCP 3306 from the EC2 security group (not from 0.0.0.0/0).
What do I need before creating an RDS database?
- An Amazon Linux 2023 EC2 instance with a security group, for example
web-sg. See How to Launch an EC2 Instance in AWS and How to SSH into EC2. - The EC2 instance and the database in the same region and VPC (the default VPC is fine for learning).
- A cost check: RDS charges per hour while the instance exists, unless your account's free tier covers it. Delete it after the lab, and set up a billing alarm and budget first.
How does EC2 reach the RDS database?
The app on EC2 connects to the RDS endpoint on port 3306. The database security group allows 3306 only from the web server security group, so a request from the internet is dropped.
EC2 वरचं ॲप RDS endpoint ला पोर्ट 3306 वर कनेक्ट होतं. डेटाबेसचा सिक्युरिटी ग्रुप 3306 फक्त वेब सर्व्हरच्या सिक्युरिटी ग्रुप कडून येऊ देतो, म्हणून इंटरनेट वरून आलेली रिक्वेस्ट ड्रॉप होते.
EC2 पर चलने वाला ऐप RDS endpoint से पोर्ट 3306 पर कनेक्ट होता है. डेटाबेस का सिक्योरिटी ग्रुप 3306 सिर्फ़ वेब सर्वर के सिक्योरिटी ग्रुप से आने देता है, इसलिए इंटरनेट से आई रिक्वेस्ट ड्रॉप हो जाती है.
How do I create an RDS MySQL database and connect from EC2?
Step 1 — Create the database security group
EC2 → Security Groups → Create security group → name db-sg, same VPC → Inbound rules → Add rule:
| Type | Port | Source | Why |
|---|---|---|---|
| MySQL/Aurora | TCP 3306 | Custom → web-sg (the EC2 security group) |
Only your web servers can connect |
Using a security group as the source means "any instance that has web-sg" — it keeps working when the EC2 IP changes, and nothing else in the world can reach 3306.
Ravindra Bagale's Tip
Because the connection fails, many students put 0.0.0.0/0 for 3306 in db-sg – "I'll remove it later" – and forget. Never! Scanners on the internet keep looking for open 3306, and once they find it they start guessing passwords. Choose web-sg as the source. If you want to see the database from your laptop, use an SSH tunnel through EC2. Keep this in mind!
Ravindra Bagale's Tip – मराठी
कनेक्ट होत नाही म्हणून खूप स्टुडंट्स db-sg मध्ये 3306 साठी 0.0.0.0/0 टाकतात – "नंतर काढू" – आणि विसरतात. कधीच नाही! इंटरनेट वर स्कॅनर्स उघडा 3306 शोधत असतात आणि सापडला की पासवर्ड गेस करायला सुरू करतात. सोर्स मध्ये web-sg निवडा. लॅपटॉप वरून डेटाबेस बघायचा असेल तर EC2 मधून SSH टनेल वापरा. ध्यान रखो!
Ravindra Bagale's Tip – हिंदी
कनेक्ट नहीं हो रहा इसलिए बहुत स्टूडेंट्स db-sg में 3306 के लिए 0.0.0.0/0 डाल देते हैं – "बाद में हटा देंगे" – और भूल जाते हैं. कभी नहीं! इंटरनेट पर स्कैनर्स खुला 3306 ढूँढते रहते हैं और मिलते ही पासवर्ड गेस करना शुरू कर देते हैं. सोर्स में web-sg चुनो. लैपटॉप से डेटाबेस देखना हो तो EC2 के ज़रिए SSH टनल इस्तेमाल करो. ध्यान रखो!
Step 2 — Start creating the database
RDS → Databases → Create database → Full configuration (older consoles and the AWS docs call it Standard create; don't pick Easy create or express configuration) → engine MySQL → keep the default current MySQL 8.x version → template Free tier if your account shows it, otherwise Dev/Test with Single-AZ.
Step 3 — Name, credentials and size
| Setting | Value |
|---|---|
| DB instance identifier | appdb |
| Master username | admin |
| Credentials management | Self managed with a strong password (keep it in a password manager), or Managed in AWS Secrets Manager |
| Instance class | A small burstable class such as db.t3.micro or db.t4g.micro |
| Storage | General Purpose SSD, 20 GiB |
Step 4 — Connectivity: keep it private
| Setting | Value |
|---|---|
| Compute resource | Don't connect to an EC2 compute resource (we set the security group ourselves) |
| VPC | The same VPC as your EC2 instance |
| Public access | No |
| VPC security group | Choose existing → remove default → select db-sg |
Open Additional configuration → Initial database name appdb → keep automated backups on → Create database. Wait until Status shows Available (usually several minutes), open the database and copy the Endpoint from Connectivity & security.
The console option Connect to an EC2 compute resource can create a matching pair of security groups for you automatically. It is fine too; this guide does it by hand so you understand the rule.
Step 5 — Install the MySQL client on the EC2 instance
SSH into the instance and install only the client (no database server is needed on EC2):
sudo dnf install mariadb105 -y
mysql --version # mysql Ver 15.1 Distrib 10.5...-MariaDB
Step 6 — Connect to RDS
mysql -h appdb.abcdefgh1234.ap-south-1.rds.amazonaws.com -u admin -p
Type the master password when asked (nothing appears while typing). You are in when you see the MySQL [(none)]> prompt:
SHOW DATABASES;
SELECT VERSION();
For an encrypted connection, download the RDS certificate bundle and use it:
curl -o global-bundle.pem https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem
mysql -h <RDS-ENDPOINT> -u admin -p --ssl-ca=global-bundle.pem --ssl-verify-server-cert
Step 7 — Create an application user (never use admin in the app)
CREATE DATABASE IF NOT EXISTS appdb;
CREATE USER 'app_user'@'%' IDENTIFIED BY 'Use-A-Long-Random-Password!';
GRANT SELECT, INSERT, UPDATE, DELETE ON appdb.* TO 'app_user'@'%';
SHOW GRANTS FOR 'app_user'@'%';
EXIT;
'%' means "from any host" at the MySQL level. That is acceptable here only because db-sg already allows nobody except web-sg. Your app now uses the endpoint, app_user and appdb. 🗄️
Ravindra Bagale's Tip
When "it doesn't connect", many students change the password again and again. First see which side the problem is on: if the command hangs and times out, it is a network problem (security group, VPC). If Access denied comes back at once, the network is fine – only the user or password is wrong. Two different problems, two different fixes. And always use the endpoint, not an IP.
Ravindra Bagale's Tip – मराठी
"कनेक्ट होत नाही" तेव्हा खूप स्टुडंट्स पासवर्ड पुन्हा पुन्हा बदलतात. आधी प्रॉब्लेम कोणत्या बाजूला आहे ते बघा: कमांड हँग होते आणि टाइमआउट येतो – नेटवर्कचा प्रॉब्लेम (सिक्युरिटी ग्रुप, VPC). लगेच Access denied आलं – नेटवर्क बरोबर आहे, फक्त यूजर/पासवर्ड चूक. दोन वेगळे प्रॉब्लेम्स, दोन वेगळे उपाय. आणि IP नाही, नेहमी endpoint वापरा.
Ravindra Bagale's Tip – हिंदी
"कनेक्ट नहीं हो रहा" तब बहुत स्टूडेंट्स पासवर्ड बार-बार बदलते हैं. पहले देखो प्रॉब्लम किस तरफ़ है: कमांड हैंग होती है और टाइमआउट आता है – नेटवर्क का प्रॉब्लम (सिक्योरिटी ग्रुप, VPC). तुरंत Access denied आया – नेटवर्क ठीक है, बस यूज़र/पासवर्ड ग़लत. दो अलग प्रॉब्लम्स, दो अलग उपाय. और IP नहीं, हमेशा endpoint इस्तेमाल करो.
Step 8 — Clean up after the lab
RDS → select appdb → Actions → Delete → decide about the final snapshot (a snapshot is kept, and billed, until you delete it) → type delete me → Delete. If you ticked deletion protection, turn it off first with Modify.
How do I fix common RDS connection errors?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
Hangs, then Can't connect to MySQL server on '...' (110) |
db-sg does not allow 3306 from web-sg; different VPC |
Fix the inbound rule; same VPC for EC2 and RDS |
Access denied for user 'admin'@'...' |
Wrong password or user name | Retype carefully; reset it with RDS Modify → new master password |
Unknown MySQL server host |
Typo in the endpoint, or the DB is still creating | Copy the endpoint again; wait for Available |
Unknown database 'appdb' |
Initial database name was left empty | CREATE DATABASE appdb; |
mysql: command not found |
Client not installed | sudo dnf install mariadb105 -y |
Connections using insecure transport are prohibited |
The server requires TLS | Use the --ssl-ca=global-bundle.pem command from Step 6 |
Authentication plugin 'caching_sha2_password' cannot be loaded |
MySQL 8.4 uses caching_sha2_password by default and this client cannot load it |
Connect with the TLS command from Step 6; if it still fails, install the official MySQL client (mysql-community-client) from MySQL's own Yum repository |
Learn it properly
This guide is the short path. The free Cyber Security course covers RDS in depth, with labs:
Samajla ka? Got it? In db-sg, 3306 only for web-sg, Public access No, the mariadb105 client, and connect with the endpoint – that's all. A separate user for the app, not admin. Delete the database after the lab.
समजलं का? db-sg मध्ये 3306 फक्त web-sg साठी, Public access No, mariadb105 क्लायंट, आणि endpoint ने कनेक्ट – एवढंच. ॲप साठी वेगळा यूजर, admin नाही. लॅब झाली की डेटाबेस डिलीट करा.
समझ आया? db-sg में 3306 सिर्फ़ web-sg के लिए, Public access No, mariadb105 क्लाइंट, और endpoint से कनेक्ट – बस इतना ही. ऐप के लिए अलग यूज़र, admin नहीं. लैब के बाद डेटाबेस डिलीट करो.
Frequently asked questions
How do I connect to RDS MySQL from EC2?
Install the client (sudo dnf install mariadb105 -y on Amazon Linux 2023), copy the RDS endpoint and run mysql -h ENDPOINT -u admin -p. The RDS security group must allow 3306 from the EC2 security group.
Why does the mysql connection to RDS hang or time out?
It is a network problem: the RDS security group does not allow 3306 from the EC2 security group, the database is in another VPC, or you used a wrong endpoint. A password problem gives Access denied instead.
Should I make my RDS database publicly accessible?
No. Keep Public access at No and allow 3306 only from the web server security group. To reach it from your laptop, use an SSH tunnel through the EC2 instance.
Which client do I install on Amazon Linux 2023?
sudo dnf install mariadb105 -y installs the mysql command-line client (MariaDB 10.5), which connects to RDS for MySQL. You do not need the database server package.
Why should I use the endpoint and not an IP address?
The IP behind an RDS instance can change, for example after a failover or maintenance. The endpoint name always points to the current address.
Why do I get "Unknown database"?
The Initial database name was left empty, so RDS created the server without your database. Connect as admin and run CREATE DATABASE appdb;.