Ravindra Bagale · AWSसर्व coursesया course चे lessonsशोधाEnglish

AWS · मराठी आवृत्ती

5.4 EC2 ला connect करूया

रवींद्र बागले यांच्या course वर आधारित · सहज मराठीत explanation

या page मध्ये

पहिल्यांदा अडचण आली तर username, key permissions आणि port 22 हे तीन checks करा.

सामान्य usernames

AMIUser — publisher docs तपासा
Amazon Linux 2023 / 2ec2-user
Ubuntuubuntu
CentOS Stream official imageअनेक images मध्ये ec2-user; जुन्या CentOS मध्ये centos
RHELec2-user
Debianadmin
SUSEec2-user

Linux/macOS OpenSSH

cd ~/Downloads
chmod 400 mykey.pem                                  # private key must not be readable by others
ssh -i mykey.pem ec2-user@<PUBLIC_IP>                # Amazon Linux / CentOS Stream
ssh -i mykey.pem ubuntu@<PUBLIC_IP>                  # Ubuntu

पहिल्यांदा host key fingerprint दिसतो. Trusted channel/instance console मधल्या fingerprint शी पडताळून मग yes द्या. तो ~/.ssh/known_hosts मध्ये साठतो. पुढे mismatch आला तर न विचारता जुनी entry delete करू नका.

UNPROTECTED PRIVATE KEY FILE किंवा Permissions 0644 too open असेल तर chmod 400 mykey.pem. Key GitHub/e-mail वर share करू नका.

Windows 10/11: OpenSSH

PowerShell मध्ये key ACL योग्य करा:

cd $env:USERPROFILE\Downloads
icacls.exe mykey.pem /reset
icacls.exe mykey.pem /grant:r "$($env:USERNAME):(R)"
icacls.exe mykey.pem /inheritance:r
ssh -i .\mykey.pem ec2-user@<PUBLIC_IP>

ACL commands नंतर अनावश्यक users ना read access नाही याची खात्री करा; directory/group inheritance तुमच्या machine वर वेगळं असू शकतं.

Windows: PuTTY

  1. PuTTY/PuTTYgen install करा.
  2. .pem असल्यास PuTTYgen → Load → All files → mykey.pem → Save private key as mykey.ppk.
  3. PuTTY Session मध्ये user@PUBLIC_IP आणि port 22.
  4. Connection → SSH → Auth → Credentials मध्ये .ppk निवडा.
  5. Saved Sessions मध्ये नाव देऊन Save → Open. Host key पडताळून accept करा.

Windows: MobaXterm

  1. योग्य edition install करा.
  2. Session → SSH → Remote host; Specify username मध्ये ec2-user/ubuntu.
  3. Advanced SSH settings → Use private key → mykey.pem.
  4. OK. SFTP panel मधून permission असलेल्या paths मध्ये files upload करता येतात.

इतर पर्याय

EC2 Instance Connect: Instance → Connect tab. AMI/package/IAM आणि network prerequisites लागतात; region च्या योग्य source range किंवा endpoint मधून SSH allow करा. फक्त यासाठी 22 सगळ्या internet ला उघडू नका.

Session Manager: Public port 22 लागत नाही. SSM Agent, योग्य instance role — उदा. AmazonSSMManagedInstanceCore — आणि SSM endpoints पर्यंत connectivity लागते.

Login नंतर

cat /etc/os-release                 # confirm distribution
sudo yum update -y                 # AL2023 / CentOS Stream
sudo apt update && sudo apt upgrade -y   # Ubuntu
curl -s http://169.254.169.254/latest/meta-data/ -H "X-aws-ec2-metadata-token: $(curl -s -X PUT http://169.254.169.254/latest/api/token -H 'X-aws-ec2-metadata-token-ttl-seconds: 60')"
sudo timedatectl set-timezone Asia/Kolkata

OS तपासून त्या OS चाच update command वापरा; दोन्ही package manager commands run करू नका. Lab मध्ये Asia/Kolkata निवडल्यास logs local time मध्ये वाचायला सोपे. Production मध्ये UTC ठेवून display convert करणंही सामान्य; team ची पद्धत पाळा.

IMDSv2 metadata

169.254.169.254 वर instance ID, IPs, AZ आणि role metadata मिळतो. IMDSv2 token वापरतो; example आधी token मागतो. URL ला public-ipv4 किंवा placement/availability-zone जोडा. Role credential output share करू नका. Required/optional metadata mode instance settings मध्ये तपासा.

Lab

तुमच्या platform वर OpenSSH, PuTTY उपलब्ध असल्यास .ppk, आणि prerequisites पूर्ण असल्यास Instance Connect वापरून connect करा. OS तपासा आणि योग्य update करा. AL2023 वर चुकून ubuntu user दिल्यावर येणारा publickey error ओळखा.