AWS · मराठी आवृत्ती
5.4 EC2 ला connect करूया
या page मध्ये
पहिल्यांदा अडचण आली तर username, key permissions आणि port 22 हे तीन checks करा.
सामान्य usernames
| AMI | User — publisher docs तपासा |
|---|---|
| Amazon Linux 2023 / 2 | ec2-user |
| Ubuntu | ubuntu |
| CentOS Stream official image | अनेक images मध्ये ec2-user; जुन्या CentOS मध्ये centos |
| RHEL | ec2-user |
| Debian | admin |
| SUSE | ec2-user |
Linux/macOS OpenSSH
cd ~/Downloads
chmod 400 mykey.pem # private key must not be readable by others
ssh -i mykey.pem ec2-user@<PUBLIC_IP> # Amazon Linux / CentOS Stream
ssh -i mykey.pem ubuntu@<PUBLIC_IP> # Ubuntu
पहिल्यांदा host key fingerprint दिसतो. Trusted channel/instance console मधल्या fingerprint शी पडताळून मग yes द्या. तो ~/.ssh/known_hosts मध्ये साठतो. पुढे mismatch आला तर न विचारता जुनी entry delete करू नका.
UNPROTECTED PRIVATE KEY FILE किंवा Permissions 0644 too open असेल तर chmod 400 mykey.pem. Key GitHub/e-mail वर share करू नका.
Windows 10/11: OpenSSH
PowerShell मध्ये key ACL योग्य करा:
cd $env:USERPROFILE\Downloads
icacls.exe mykey.pem /reset
icacls.exe mykey.pem /grant:r "$($env:USERNAME):(R)"
icacls.exe mykey.pem /inheritance:r
ssh -i .\mykey.pem ec2-user@<PUBLIC_IP>
ACL commands नंतर अनावश्यक users ना read access नाही याची खात्री करा; directory/group inheritance तुमच्या machine वर वेगळं असू शकतं.
Windows: PuTTY
- PuTTY/PuTTYgen install करा.
- .pem असल्यास PuTTYgen → Load → All files → mykey.pem → Save private key as mykey.ppk.
- PuTTY Session मध्ये user@PUBLIC_IP आणि port 22.
- Connection → SSH → Auth → Credentials मध्ये .ppk निवडा.
- Saved Sessions मध्ये नाव देऊन Save → Open. Host key पडताळून accept करा.
Windows: MobaXterm
- योग्य edition install करा.
- Session → SSH → Remote host; Specify username मध्ये ec2-user/ubuntu.
- Advanced SSH settings → Use private key → mykey.pem.
- OK. SFTP panel मधून permission असलेल्या paths मध्ये files upload करता येतात.
इतर पर्याय
EC2 Instance Connect: Instance → Connect tab. AMI/package/IAM आणि network prerequisites लागतात; region च्या योग्य source range किंवा endpoint मधून SSH allow करा. फक्त यासाठी 22 सगळ्या internet ला उघडू नका.
Session Manager: Public port 22 लागत नाही. SSM Agent, योग्य instance role — उदा. AmazonSSMManagedInstanceCore — आणि SSM endpoints पर्यंत connectivity लागते.
Login नंतर
cat /etc/os-release # confirm distribution
sudo yum update -y # AL2023 / CentOS Stream
sudo apt update && sudo apt upgrade -y # Ubuntu
curl -s http://169.254.169.254/latest/meta-data/ -H "X-aws-ec2-metadata-token: $(curl -s -X PUT http://169.254.169.254/latest/api/token -H 'X-aws-ec2-metadata-token-ttl-seconds: 60')"
sudo timedatectl set-timezone Asia/Kolkata
OS तपासून त्या OS चाच update command वापरा; दोन्ही package manager commands run करू नका. Lab मध्ये Asia/Kolkata निवडल्यास logs local time मध्ये वाचायला सोपे. Production मध्ये UTC ठेवून display convert करणंही सामान्य; team ची पद्धत पाळा.
IMDSv2 metadata
169.254.169.254 वर instance ID, IPs, AZ आणि role metadata मिळतो. IMDSv2 token वापरतो; example आधी token मागतो. URL ला public-ipv4 किंवा placement/availability-zone जोडा. Role credential output share करू नका. Required/optional metadata mode instance settings मध्ये तपासा.
Lab
तुमच्या platform वर OpenSSH, PuTTY उपलब्ध असल्यास .ppk, आणि prerequisites पूर्ण असल्यास Instance Connect वापरून connect करा. OS तपासा आणि योग्य update करा. AL2023 वर चुकून ubuntu user दिल्यावर येणारा publickey error ओळखा.