How to Launch an EC2 Instance in AWS (Step by Step)
To launch an EC2 instance, open the EC2 console, click Launch instance, choose the Amazon Linux 2023 AMI, a free-tier eligible type such as t3.micro, a key pair, and a security group that allows SSH (22) from your IP and HTTP (80) / HTTPS (443) from anywhere, then click Launch instance. When the instance shows Running and 2/2 checks passed, connect to its Public IPv4 address with SSH.
Come on, today let's launch the first EC2 server for your website. Open the console and do every step with me – you cannot learn EC2 just by reading.
चला, आज तुमच्या वेबसाइट साठी पहिला EC2 सर्व्हर launch करूया. Console उघडा आणि प्रत्येक स्टेप माझ्या सोबत करा – फक्त वाचून EC2 येत नाही.
चलो, आज आपकी वेबसाइट के लिए पहला EC2 सर्वर launch करते हैं. Console खोलो और हर स्टेप मेरे साथ करो – सिर्फ़ पढ़कर EC2 नहीं आता.
Quick answer
In the AWS console open EC2 → Launch instance, then:
- Name it (for example
web-server-1) and choose the Amazon Linux 2023 AMI. - Pick a free-tier eligible instance type such as
t3.microort2.micro. - Create a key pair (
.pem) and keep the file safe — it downloads only once. - In Network settings keep Auto-assign public IP enabled and create a security group: SSH 22 from My IP, HTTP 80 and HTTPS 443 from Anywhere-IPv4.
- Click Launch instance, wait for Running and 2/2 checks passed, and copy the Public IPv4 address.
What are the steps to launch an EC2 instance?
Launching EC2 in six steps: AMI, instance type, key pair, security group, launch, and a running instance with a public IP.
EC2 सुरू करण्याच्या सहा पायऱ्या: आधी AMI निवडा, मग instance type, नंतर key pair आणि security group, शेवटी launch करा – आणि public IP सोबत तुमचा सर्व्हर चालू होतो.
EC2 शुरू करने की छह सीढ़ियाँ: पहले AMI चुनो, फिर instance type, उसके बाद key pair और security group, आख़िर में launch करो – और public IP के साथ आपका सर्वर चालू हो जाता है.
What do I need before launching EC2?
- An AWS account and access to the AWS Management Console.
- A billing alarm or budget set in the AWS Billing console. AWS free-tier offers change from time to time, so check the official AWS Free Tier page for the current rules on your account.
- Select the Mumbai (ap-south-1) region from the top-right region menu (or the region you want to use). The console shows resources only for the selected region.
How do I launch an EC2 instance in the AWS console?
Step 1 — Open EC2
Search "EC2" in the top search bar → EC2 Dashboard → Launch instance.
Step 2 — Name and tags
Name: web-server-1. This creates a tag Name=web-server-1. Tags such as Project=my-website and Environment=dev make billing and clean-up easier later.
Step 3 — Choose an AMI (the operating system)
Under Application and OS Images choose one of:
- Amazon Linux 2023 AMI (default, free-tier eligible) — login user
ec2-user - Ubuntu Server 24.04 LTS (or 22.04 LTS) — login user
ubuntu - CentOS Stream 9 — search Browse more AMIs → AWS Marketplace / Community AMIs for the official "CentOS Stream 9" image — login user
ec2-user
Keep the architecture 64-bit (x86) unless you choose a Graviton instance type.
Step 4 — Instance type
Choose a free-tier eligible type such as t3.micro or t2.micro — the list shows the label. Start small; you can change the type later.
Step 5 — Key pair (login)
Click Create new key pair → name mykey → type RSA or ED25519 → format .pem (OpenSSH on Linux, macOS and Windows 10+) or .ppk (PuTTY) → Create. The file downloads only once, and AWS cannot give it back.
Ravindra Bagale's Tip
This .pem file is the key to your server. As soon as it downloads, keep it in a safe folder and run chmod 400 – if it sits in Downloads and gets deleted, AWS cannot give it back. Never put the key of a live server in an e-mail or on GitHub.
Ravindra Bagale's Tip – मराठी
ही .pem फाइल म्हणजे तुमच्या सर्व्हरची चावी आहे. डाउनलोड झाल्यावर लगेच एका सुरक्षित फोल्डर मध्ये ठेवा आणि chmod 400 करा – Downloads मध्ये पडून राहिली आणि डिलीट झाली तर AWS ती परत देऊ शकत नाही. लाइव्ह सर्व्हरची key कधीच ई-मेल किंवा GitHub वर ठेवू नका.
Ravindra Bagale's Tip – हिंदी
यह .pem फ़ाइल मतलब आपके सर्वर की चाबी है. डाउनलोड होते ही इसे एक सुरक्षित फ़ोल्डर में रखो और chmod 400 करो – Downloads में पड़ी रही और डिलीट हो गई तो AWS इसे वापस नहीं दे सकता. लाइव सर्वर की key कभी ई-मेल या GitHub पर मत रखो.
Step 6 — Network settings and security group
Click Edit in Network settings:
- VPC: default VPC; Subnet: No preference (or pick an Availability Zone)
- Auto-assign public IP: Enable
- Firewall (security groups): Create security group, name
web-sg, with these inbound rules:
| Type | Protocol | Port | Source | Why |
|---|---|---|---|---|
| SSH | TCP | 22 | My IP (e.g. 49.36.12.7/32) |
Only you can log in |
| HTTP | TCP | 80 | Anywhere-IPv4 0.0.0.0/0 |
Website |
| HTTPS | TCP | 443 | Anywhere-IPv4 0.0.0.0/0 |
Secure website |
Customers can open the website from anywhere, so 80 and 443 are open to all. SSH (22) is the door into the server itself, so it is open only to My IP — never to 0.0.0.0/0.
Step 7 — Configure storage
The default root volume is 8 GiB gp3. You can set up to 30 GiB within typical free-tier storage limits.
Step 8 — Advanced details: user data (optional)
A User data script runs once, as root, on the first boot. This one installs Nginx and writes a test page on Amazon Linux 2023:
#!/bin/bash
yum install -y nginx
echo "<h1>Hello from $(hostname -f)</h1>" > /usr/share/nginx/html/index.html
service nginx start
systemctl enable nginx
The script has no sudo because user data already runs as root. When you type the same commands yourself after logging in, add sudo: sudo yum install -y nginx, sudo service nginx start.
Step 9 — Launch and wait for "Running"
Review the Summary panel → Launch instance → View all instances. Wait until Instance state = Running and Status checks = 2/2 checks passed. Copy the Public IPv4 address. Server ready! 🎉
Ravindra Bagale's Tip
💡 On the day you propose, you check everything in advance, right – the ring, the place, the time? In the same way, before you click Launch instance, check three things in the Summary panel: is the region Mumbai, is Auto-assign public IP set to Enable, and does web-sg have its three rules? Without a public IP there is no SSH and no website. Two minutes of checking saves half an hour of debugging.
Ravindra Bagale's Tip – मराठी
💡 प्रपोज करायच्या दिवशी आपण सगळं आधीच नीट बघतो ना – अंगठी, जागा, वेळ? तसंच Launch instance दाबण्याआधी Summary पॅनल मध्ये तीन गोष्टी नक्की बघा: region Mumbai आहे का, Auto-assign public IP Enable आहे का, आणि web-sg चे तीन rules आहेत का. Public IP नसेल तर SSH पण नाही आणि वेबसाइट पण नाही. दोन मिनिटं नीट बघितलं तर अर्धा तास debugging वाचतो.
Ravindra Bagale's Tip – हिंदी
💡 प्रपोज़ करने वाले दिन हम सब कुछ पहले से देख लेते हैं ना – अंगूठी, जगह, समय? वैसे ही Launch instance दबाने से पहले Summary पैनल में तीन चीज़ें ज़रूर देखो: region Mumbai है क्या, Auto-assign public IP Enable है क्या, और web-sg के तीन rules हैं क्या. Public IP नहीं होगा तो न SSH चलेगा, न वेबसाइट. दो मिनट ध्यान से देखा तो आधा घंटा debugging बचता है.
Step 10 — Test
If you used the user-data script, open http://<PUBLIC_IP> in a browser (note http, not https) and you should see Hello from .... Next steps:
- Log in: How to SSH into EC2 from Windows, Mac and Linux
- Install a web server by hand: How to Install Nginx on Amazon Linux 2023
Should I stop or terminate the instance after the lab?
| Action | Public IP | EBS root volume | Billing |
|---|---|---|---|
| Stop | Released (a new one on start); an Elastic IP is kept | Kept | Instance charges stop; EBS and Elastic IP still charged |
| Terminate | Released | Deleted if Delete on termination = yes (the default for root) | All instance charges stop |
Terminated instances cannot be recovered. For an important server turn on Termination protection (Actions → Instance settings → Change termination protection). If a server needs a fixed address, use an Elastic IP.
How do I fix common EC2 launch problems?
Ghabru naka 😅 — these are the problems I see in almost every batch:
| Problem | Likely cause | Fix |
|---|---|---|
| Browser shows a timeout | Security group without port 80; typed https://; web server not running; subnet without a route to an Internet Gateway; no public IP |
Check the rules, use http://, check the server, the route table and the public IP |
| The instance has no public IP | Auto-assign public IP was disabled | Launch again with it enabled, or attach an Elastic IP |
| "My instance disappeared" | A different region is selected | Switch back to the region where you launched it |
Lost the .pem file |
It downloads only once | Keep keys in a safe folder from day one |
| SSH works at home, times out later | Your IP changed (new Wi-Fi or hotspot), so My IP no longer matches | Update the SSH rule to your current IP |
| An unexpected bill | Instances, Elastic IPs or volumes left running | Terminate what you do not need; release unused Elastic IPs |
Learn it properly
This guide is the short path. The free AWS course explains every step in depth, with labs:
Got it? AMI + instance type + key pair + security group + storage – these are the five pillars of a launch. Your first server is ready! Now log in with SSH.
समजलं का? AMI + instance type + key pair + security group + storage – हेच launch चे पाच खांब आहेत. तुमचा पहिला सर्व्हर तयार! आता SSH करून login करा.
समझ आया? AMI + instance type + key pair + security group + storage – यही launch के पाँच खंभे हैं. आपका पहला सर्वर तैयार! अब SSH करके login करो.
Frequently asked questions
What do I choose when launching an EC2 instance?
A name, an AMI (the operating system), an instance type, a key pair for login, network settings with a security group, and the storage size.
Which security group rules does a web server need?
SSH (TCP 22) from My IP only, and HTTP (TCP 80) and HTTPS (TCP 443) from Anywhere-IPv4 0.0.0.0/0. Never leave port 22 open to 0.0.0.0/0.
Which EC2 instance type is free-tier eligible?
Pick a type that the list marks as free-tier eligible, such as t3.micro or t2.micro. Free-tier offers change, so check the official AWS Free Tier page.
What happens if I lose the .pem key file?
The key pair file downloads only once and AWS cannot give it back, so keep it in a safe folder as soon as it downloads.
Why does the browser show a timeout after launch?
Almost always one of: the security group does not allow port 80, you typed https:// but no TLS is configured, the web server is not running, the subnet has no route to an Internet Gateway, or no public IP is assigned.
Does a stopped instance still cost money?
Instance charges stop, but the EBS storage and any Elastic IP are still charged. Terminate what you no longer need.