Ravindra BagaleCourses & study guides Track your progress

Guides

How to Create an Amazon RDS MySQL Database and Connect from EC2

To create an Amazon RDS for MySQL database and connect from EC2, first make a security group for the database that allows MySQL/Aurora (TCP 3306) only from the EC2 instance's security group. Then in RDS → Create database choose MySQL, the Free tier or Dev/Test template, Public access: No, the same VPC and that security group. On the Amazon Linux 2023 instance install the client with sudo dnf install mariadb105 -y and connect with mysql -h <RDS-ENDPOINT> -u admin -p.

Come on, friends! We installed MariaDB on EC2 and ran WordPress – but the database backups, updates and patching were all our work. With RDS, AWS does that work; we only use the database. Today we create a private MySQL database and connect to it from EC2. Pay attention: never open the database to the internet – only our web server gets permission.

Quick answer

After the database shows Available (console steps below), on the EC2 instance:

sudo dnf install mariadb105 -y
mysql --version
mysql -h appdb.abcdefgh1234.ap-south-1.rds.amazonaws.com -u admin -p
# mysql> SHOW DATABASES;

The RDS security group must allow TCP 3306 from the EC2 security group (not from 0.0.0.0/0).

What do I need before creating an RDS database?

  • An Amazon Linux 2023 EC2 instance with a security group, for example web-sg. See How to Launch an EC2 Instance in AWS and How to SSH into EC2.
  • The EC2 instance and the database in the same region and VPC (the default VPC is fine for learning).
  • A cost check: RDS charges per hour while the instance exists, unless your account's free tier covers it. Delete it after the lab, and set up a billing alarm and budget first.

How does EC2 reach the RDS database?

EC2 connecting to a private RDS MySQL database The mysql client on the EC2 web server sends a query to the RDS endpoint on TCP port 3306. The database security group allows 3306 only from the web server security group, so the rows come back. A connection attempt from the internet is dropped at the security group. EC2 web serversecurity group web-sg $ mysql -h appdb... -u admin -pMySQL [(none)]> TCP 3306 db-sg: 3306 from web-sg only RDS MySQLappdb endpointPublic access: No Internet queryrows3306 from internet

The app on EC2 connects to the RDS endpoint on port 3306. The database security group allows 3306 only from the web server security group, so a request from the internet is dropped.

How do I create an RDS MySQL database and connect from EC2?

Step 1 — Create the database security group

EC2 → Security Groups → Create security group → name db-sg, same VPC → Inbound rules → Add rule:

Type Port Source Why
MySQL/Aurora TCP 3306 Custom → web-sg (the EC2 security group) Only your web servers can connect

Using a security group as the source means "any instance that has web-sg" — it keeps working when the EC2 IP changes, and nothing else in the world can reach 3306.

Ravindra Bagale's Tip

Because the connection fails, many students put 0.0.0.0/0 for 3306 in db-sg – "I'll remove it later" – and forget. Never! Scanners on the internet keep looking for open 3306, and once they find it they start guessing passwords. Choose web-sg as the source. If you want to see the database from your laptop, use an SSH tunnel through EC2. Keep this in mind!

Step 2 — Start creating the database

RDS → Databases → Create database → Full configuration (older consoles and the AWS docs call it Standard create; don't pick Easy create or express configuration) → engine MySQL → keep the default current MySQL 8.x version → template Free tier if your account shows it, otherwise Dev/Test with Single-AZ.

Step 3 — Name, credentials and size

Setting Value
DB instance identifier appdb
Master username admin
Credentials management Self managed with a strong password (keep it in a password manager), or Managed in AWS Secrets Manager
Instance class A small burstable class such as db.t3.micro or db.t4g.micro
Storage General Purpose SSD, 20 GiB

Step 4 — Connectivity: keep it private

Setting Value
Compute resource Don't connect to an EC2 compute resource (we set the security group ourselves)
VPC The same VPC as your EC2 instance
Public access No
VPC security group Choose existing → remove default → select db-sg

Open Additional configuration → Initial database name appdb → keep automated backups on → Create database. Wait until Status shows Available (usually several minutes), open the database and copy the Endpoint from Connectivity & security.

The console option Connect to an EC2 compute resource can create a matching pair of security groups for you automatically. It is fine too; this guide does it by hand so you understand the rule.

Step 5 — Install the MySQL client on the EC2 instance

SSH into the instance and install only the client (no database server is needed on EC2):

sudo dnf install mariadb105 -y
mysql --version                     # mysql  Ver 15.1 Distrib 10.5...-MariaDB

Step 6 — Connect to RDS

mysql -h appdb.abcdefgh1234.ap-south-1.rds.amazonaws.com -u admin -p

Type the master password when asked (nothing appears while typing). You are in when you see the MySQL [(none)]> prompt:

SHOW DATABASES;
SELECT VERSION();

For an encrypted connection, download the RDS certificate bundle and use it:

curl -o global-bundle.pem https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem
mysql -h <RDS-ENDPOINT> -u admin -p --ssl-ca=global-bundle.pem --ssl-verify-server-cert

Step 7 — Create an application user (never use admin in the app)

CREATE DATABASE IF NOT EXISTS appdb;
CREATE USER 'app_user'@'%' IDENTIFIED BY 'Use-A-Long-Random-Password!';
GRANT SELECT, INSERT, UPDATE, DELETE ON appdb.* TO 'app_user'@'%';
SHOW GRANTS FOR 'app_user'@'%';
EXIT;

'%' means "from any host" at the MySQL level. That is acceptable here only because db-sg already allows nobody except web-sg. Your app now uses the endpoint, app_user and appdb. 🗄️

Ravindra Bagale's Tip

When "it doesn't connect", many students change the password again and again. First see which side the problem is on: if the command hangs and times out, it is a network problem (security group, VPC). If Access denied comes back at once, the network is fine – only the user or password is wrong. Two different problems, two different fixes. And always use the endpoint, not an IP.

Step 8 — Clean up after the lab

RDS → select appdb → Actions → Delete → decide about the final snapshot (a snapshot is kept, and billed, until you delete it) → type delete me → Delete. If you ticked deletion protection, turn it off first with Modify.

How do I fix common RDS connection errors?

Ghabru naka 😅 — these are the usual ones:

Symptom Likely cause Fix
Hangs, then Can't connect to MySQL server on '...' (110) db-sg does not allow 3306 from web-sg; different VPC Fix the inbound rule; same VPC for EC2 and RDS
Access denied for user 'admin'@'...' Wrong password or user name Retype carefully; reset it with RDS Modify → new master password
Unknown MySQL server host Typo in the endpoint, or the DB is still creating Copy the endpoint again; wait for Available
Unknown database 'appdb' Initial database name was left empty CREATE DATABASE appdb;
mysql: command not found Client not installed sudo dnf install mariadb105 -​y
Connections using insecure transport are prohibited The server requires TLS Use the --​ssl-​ca=​global-​bundle.​pem command from Step 6
Authentication plugin 'caching_​sha2_​password' cannot be loaded MySQL 8.4 uses caching_​sha2_​password by default and this client cannot load it Connect with the TLS command from Step 6; if it still fails, install the official MySQL client (mysql-​community-​client) from MySQL's own Yum repository

Samajla ka? Got it? In db-sg, 3306 only for web-sg, Public access No, the mariadb105 client, and connect with the endpoint – that's all. A separate user for the app, not admin. Delete the database after the lab.

Frequently asked questions

How do I connect to RDS MySQL from EC2?

Install the client (sudo dnf install mariadb105 -y on Amazon Linux 2023), copy the RDS endpoint and run mysql -h ENDPOINT -u admin -p. The RDS security group must allow 3306 from the EC2 security group.

Why does the mysql connection to RDS hang or time out?

It is a network problem: the RDS security group does not allow 3306 from the EC2 security group, the database is in another VPC, or you used a wrong endpoint. A password problem gives Access denied instead.

Should I make my RDS database publicly accessible?

No. Keep Public access at No and allow 3306 only from the web server security group. To reach it from your laptop, use an SSH tunnel through the EC2 instance.

Which client do I install on Amazon Linux 2023?

sudo dnf install mariadb105 -y installs the mysql command-line client (MariaDB 10.5), which connects to RDS for MySQL. You do not need the database server package.

Why should I use the endpoint and not an IP address?

The IP behind an RDS instance can change, for example after a failover or maintenance. The endpoint name always points to the current address.

Why do I get "Unknown database"?

The Initial database name was left empty, so RDS created the server without your database. Connect as admin and run CREATE DATABASE appdb;.