Labs · Cyber Security
Lab: Launch a Free-Tier EC2 Server Safely – New Key Pair, SSH Only from My IP, and a Zero-Spend Budget Alert
Course: Cyber Security · Chapter 4: Amazon EC2: Launch and Connect to Your Linux Server
Chapter 4 launches and connects to a Linux server; this lab does it the safe way from the first click.
Chala mitrano! Most beginners launch their first server with SSH open to the whole world and no billing alert. Then one day a bill or a strange login arrives. Today we do the same launch, but safe from the first click: budget alert first, then the server. Shant raha, step by step.
चला मित्रांनो! बहुतेक beginners पहिला server SSH संपूर्ण जगासाठी open ठेवून आणि billing alert शिवाय launch करतात. मग एक दिवस bill किंवा विचित्र login येतो. आज आपण तेच launch करणार, पण पहिल्या click पासून safe: आधी budget alert, मग server. शांत राहा, step by step.
चलो दोस्तों! ज़्यादातर beginners अपना पहला server SSH पूरी दुनिया के लिए खुला रखकर और billing alert के बिना launch करते हैं। फिर एक दिन bill या कोई अजीब login आ जाता है। आज हम वही launch करेंगे, पर पहले click से safe: पहले budget alert, फिर server। आराम से, step by step।
Suppose we are…
Suppose we are a cloud trainee at Infosys and our team lead says: "Launch one test server for the demo, but I don't want any surprise bill and I don't want SSH open to the internet." That is exactly what good cloud engineers do every time: a budget alert (an email from AWS when spending starts), a new key pair (the private key file that replaces a password for SSH) and a security group (the server's firewall) that allows SSH only from our own IP.
Goal of this lab
By the end you will have:
- A zero-spend budget that emails you as soon as anything costs money.
- An Amazon Linux 2023 server launched with a new key pair and SSH allowed only from My IP.
- Logged in once with SSH, checked who you are, and terminated the server.
What you need (all free)
- Your own AWS account (Free Tier). Sign in as an IAM admin user, not as root, if you have one.
- Terminal (Mac/Linux) or PowerShell (Windows 10/11 has the
sshcommand built in). - 40–45 minutes.
Safety and ethics
Never share your .pem key file, never commit it to GitHub, and never open port 22 to 0.0.0.0/0 (the whole internet). Choose only options marked Free tier eligible. Terminate the server at the end of the lab.
Part 1: budget alert first
- Sign in to the AWS console. In the top search bar type Budgets and open AWS Budgets (under Billing and Cost Management).
- Click Create budget → Use a template (simplified) → Zero spend budget.
-
Enter your email address under Email recipients and click Create budget.
What you should see: a budget named My Zero-Spend Budget in the list. AWS will email you if your spend goes above $0.01.
Part 2: launch the server safely
- Search EC2, open it, and check the Region at the top right (for example Asia Pacific (Mumbai) ap-south-1). Click Launch instance.
- Name:
lab-safe-server. Application and OS Images: Amazon Linux 2023 AMI (it says Free tier eligible). - Instance type: choose the one marked Free tier eligible (t2.micro or t3.micro, depending on Region and account).
- Key pair (login): click Create new key pair. Name
lab-key, type RSA, format .pem, then Create key pair. The filelab-key.pemdownloads. Move it to a folder such asDocuments\aws-keys. -
Network settings: keep Create security group and tick Allow SSH traffic from. In the drop-down change Anywhere to My IP.
What you should see: the source shows your public IP with
/32at the end, for example49.36.12.80/32./32means exactly one address. -
Leave Allow HTTPS and Allow HTTP unticked for now. Keep storage at 8 GiB gp3. Click Launch instance, then View all instances.
- Wait until Instance state is Running and Status check shows 2/2 checks passed. Select the instance and copy its Public IPv4 address.
Part 3: connect and check
-
Protect the key file so only you can read it.
Mac / Linux:
chmod 400 ~/Documents/aws-keys/lab-key.pemWindows PowerShell (inside the key's folder):
icacls .\lab-key.pem /inheritance:r /grant:r "$($env:USERNAME):(R)" -
Connect (replace the IP):
ssh -i lab-key.pem ec2-user@13.233.10.25Type
yeswhen asked about the fingerprint.What you should see: the Amazon Linux banner and a prompt like
[ec2-user@ip-172-31-5-20 ~]$. -
Run
whoami(showsec2-user) andhostname -I(shows the private IP inside AWS, starting with172.31.). Typeexit. - In the EC2 console click the instance → Security tab → the security group link → Inbound rules. Confirm there is exactly one rule: SSH, TCP 22, your-IP/32.
Ravindra Bagale's Tip
If SSH worked yesterday and today it says "Connection timed out", your home IP has probably changed. Don't open port 22 to Anywhere in panic. Edit the inbound rule and pick My IP again. Five seconds, problem solved.
Ravindra Bagale's Tip – मराठी
काल SSH चालत होतं आणि आज "Connection timed out" येतंय, तर तुमचा घरचा IP बदलला असेल. घाबरून port 22 Anywhere साठी open करू नका. Inbound rule edit करा आणि परत My IP निवडा. पाच seconds, problem solved.
Ravindra Bagale's Tip – हिंदी
अगर कल SSH चल रहा था और आज "Connection timed out" आ रहा है, तो शायद आपका घर का IP बदल गया है। घबराकर port 22 Anywhere के लिए मत खोलो। Inbound rule edit करो और फिर से My IP चुनो। पाँच seconds, problem solved।
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
| SSH source left as Anywhere 0.0.0.0/0 | Bots from the whole internet try to log in within minutes | Use My IP (/32) |
| Key file permissions too open | UNPROTECTED PRIVATE KEY FILE! and SSH refuses the key |
chmod 400 (Mac/Linux) or the icacls command (Windows) |
Using root@ or ubuntu@ on Amazon Linux |
Permission denied (publickey) |
The user on Amazon Linux is ec2-user |
| Choosing a bigger instance type "for speed" | Charges start immediately | Pick only Free tier eligible |
| Stopping instead of terminating after the lab | The disk (EBS volume) still exists and can count against free storage | Terminate lab servers you no longer need |
Self-check checklist
0 of 6 done
Try-at-home challenge
Your mobile hotspot has a different public IP from your home Wi-Fi. Connect your laptop to your phone's hotspot and try ssh again. What happens and why? Then fix it the safe way without using Anywhere.
Check your answer
The connection times out, because the security group allows only your home IP. Fix: edit the inbound rule, choose My IP (now the hotspot IP), save, connect, and change it back later. You can also keep two rules with descriptions "home" and "hotspot".
Clean up to avoid charges
- EC2 → Instances → select
lab-safe-server→ Instance state → Terminate (delete) instance → Terminate. - Wait until the state is Terminated. The 8 GiB volume is deleted with it (Delete on termination is on by default).
- EC2 → Security Groups: delete the
launch-wizard-…group the wizard created (it can be deleted after the instance is gone). - Keep the zero-spend budget. It is free and protects you in every future lab.
Samjla ka? Budget first, My IP for SSH, new key, terminate after. Aata pudhe jaauya: Chapter 5 teaches the Linux commands we use on this server.