# EC2 म्हणजे काय? महत्त्वाचे concepts

Source: https://ravindrabagale.com/mr/cyber/part-02/ch04-amazon-ec2-launch-and-connect-to-your-linux/4-1-what-is-ec2-key-concepts.html
Language: mr (Marathi with English technical terms)

Amazon EC2 म्हणजे cloud मध्ये गरजेनुसार वापरता येणारा server. समजण्यासाठी “AWS कडून भाड्याने घेतलेला computer” असं म्हणा. त्याचं size म्हणजे instance type, OS/software template म्हणजे AMI, login साठी key pair आणि network access चे नियम म्हणजे security group. अनेक आधुनिक EC2 instance types AWS Nitro platform वापरतात.

 AWS Region: Asia Pacific (Mumbai) ap-south-1
 +---------------------------------------------------------------------+
 |  Availability Zone ap-south-1a        Availability Zone ap-south-1b |
 |  +---------------------------+        +---------------------------+ |
 |  | VPC subnet                |        | VPC subnet                | |
 |  |  +---------------------+  |        |  +---------------------+  | |
 |  |  | EC2 instance        |  |        |  | EC2 instance        |  | |
 |  |  | AMI: Ubuntu 24.04   |  |        |  | AMI: AL2023         |  | |
 |  |  | Type: t3.micro      |  |        |  | Type: t3.small      |  | |
 |  |  | SG: web-sg          |  |        |  | SG: web-sg          |  | |
 |  |  +----------+----------+  |        |  +----------+----------+  | |
 |  |             | EBS vol     |        |             | EBS vol     | |
 |  +---------------------------+        +---------------------------+ |
 +---------------------------------------------------------------------+

Diagram मध्ये Mumbai region ap-south-1, वेगवेगळ्या Availability Zones, प्रत्येकात subnet, EC2 instance आणि जोडलेलं EBS storage दाखवलं आहे.

 | Term
 | काय आहे?
 | उदाहरण / नोंद

 | Instance
 | Virtual server
 | i-​0abc123def4567890

 | AMI (Amazon Machine Image)
 | Instance launch करण्यासाठी OS + software असलेली image
 | Amazon Linux 2023, Ubuntu 24.04, CentOS Stream 9, स्वतःची custom AMI

 | Instance type
 | Hardware क्षमता: vCPU, RAM, network
 | t3.micro (2 vCPU, 1 GiB), t3.medium (2 vCPU, 4 GiB)

 | Key pair
 | SSH login साठी public/private key pair
 | Public key AWS कडे; mykey.pem एकदाच download करता

 | Security group (SG)
 | Instance interface साठी stateful virtual firewall
 | My IP वरून TCP 22; public website साठी 0.0.0.0/0 वरून TCP 80/443

 | EBS volume
 | Network-attached block storage; virtual disk
 | Root volume 8 GiB gp3

 | Instance store
 | Host ला जोडलेली temporary disk
 | Stop/terminate नंतर data जातो; निवडक types वर उपलब्ध

 | Elastic IP
 | स्थिर public IPv4 address
 | Stop/start नंतर टिकतो; remap करता येतो

 | Region
 | अनेक data centres असलेला भौगोलिक परिसर
 | ap-south-1 Mumbai, us-east-1 N. Virginia

 | Availability Zone (AZ)
 | Region मधले एक किंवा अधिक वेगळे data centres
 | ap-south-1a, ap-south-1b, ap-south-1c

 | VPC / subnet
 | तुमचं logical network / एका AZ मधला भाग
 | Default VPC 172.31.0.0/16

 | User data
 | पहिल्या boot वर आपोआप चालणारी script
 | Launch वेळी Nginx install करणे

 | IAM role (instance profile)
 | कायमचे access keys न ठेवता instance ला AWS permissions
 | Instance ला S3 read permission

हे शब्द सोप्या भाषेत

Instance: virtual server; उदा. i-0abc123def4567890.

AMI: OS आणि आवश्यक software असलेलं launch template/image; Amazon Linux 2023, Ubuntu 24.04, CentOS Stream 9 किंवा custom AMI.

Instance type: vCPU, RAM, network क्षमता. उदाहरणात t3.micro 2 vCPU/1 GiB आणि t3.medium 2 vCPU/4 GiB.

Key pair: public/private key. Login साठी private key तुमच्याकडे सुरक्षित ठेवता.

Security group: instance च्या network interface ला लागू होणारा stateful virtual firewall. SSH trusted IP वरून, public web साठी 80/443 असे rules.

EBS: network-attached block storage, म्हणजे virtual disk; उदाहरणात 8 GiB gp3 root volume.

Instance store: काही types वर host ला जोडलेली temporary disk. Stop/terminate नंतर data टिकत नाही.

Elastic IP: स्थिर public IPv4; दुसऱ्या eligible resource ला remap करता येतो.

Region: भौगोलिक परिसर; उदा. Mumbai ap-south-1, N. Virginia us-east-1.

Availability Zone: region मधला स्वतंत्र infrastructure zone; उदा. ap-south-1a.

VPC/subnet: तुमचं logical network आणि त्याचा एका AZ मधला भाग. Default VPC उदाहरण 172.31.0.0/16.

User data: पहिल्या boot वेळी आपोआप चालवता येणारी setup script.

IAM role/instance profile: code मध्ये कायमचे access keys न ठेवता instance ला आवश्यक AWS permissions देण्याची पद्धत; उदा. S3 read access.

Security ची जबाबदारी कोणाची?

Shared responsibility model मध्ये AWS physical infrastructure, hardware आणि underlying platform सुरक्षित ठेवतो. Customer म्हणून OS updates, keys, security groups, application configuration आणि data access तुमच्याकडे असतात. Open port, leaked key किंवा unpatched service यांसारख्या चुका या बाजूला होऊ शकतात.

Practice

Instance, AMI, instance type, key pair, security group, EBS, region, AZ आणि IAM role यांचा अर्थ प्रत्येकी एका ओळीत स्वतः लिहा.

रवींद्र बागले यांची tip

Account तयार झाल्यावर root user ला MFA लावा आणि AWS Budgets मध्ये alert configure करा. रोजच्या कामासाठी root वापरू नका; योग्य IAM/federated identity आणि कमीतकमी permissions वापरा. Budget alert खर्च आपोआप बंद करतो असं समजू नका.
