Amazon EC2 Explained | Instance Types, Pricing & Security Groups | AWS CLF-C02 Day 8 — Transcript
Full transcript
- 0:00Hello everyone, welcome back to day
- 0:02eight of our AWS builder challenge. I
- 0:04hope you are enjoying the journey so far
- 0:05because today we are finally going to
- 0:09learn, read, understand one of the most
- 0:12important service in AWS that is Amazon
- 0:15EC2.
- 0:16If AWS had a celebrity service, EC2
- 0:19would probably be it. In fact, when most
- 0:21people think about AWS, they think about
- 0:24EC2. Before we talk about EC2, let me
- 0:27ask you a simple question. When you open
- 0:30Instagram, where are those photos
- 0:32stored?
- 0:33Or whenever you watch YouTube, where
- 0:35does the video come from? Everything
- 0:38comes from servers. At the end of the
- 0:40day, applications need computers to run.
- 0:44Traditionally, companies had to buy
- 0:46physical servers. They had to buy
- 0:48hardware, data centers. Uh they had to
- 0:51manage the electricity, cooling systems
- 0:53as well as networking, security,
- 0:55maintenance and a lot. And if there is
- 0:58sudden rise in traffic then they had to
- 1:01buy even more hardware. This process
- 1:04could takes weeks or even months. And
- 1:07that cloud computing had changed that
- 1:10model. And instead of buying servers,
- 1:14companies can now rent them whenever
- 1:16they need them. If you need one server,
- 1:20you can launch one. You need 10, you can
- 1:23launch 10. If you need 100, you can
- 1:26launch 100 as well. And let's say if you
- 1:29need them only for 2 hours, you can get
- 1:33them for 2 hours only and pay only for 2
- 1:36hours. And that is exactly what EC2
- 1:38provides. EC2 stands for elastic compute
- 1:44cloud. Here C2 means there are two C's
- 1:48that is CL compute cloud. Elastic
- 1:50compute cloud. Now let's simplify that.
- 1:53Whenever I say EC2 instance, I want uh
- 1:56you to simply think about virtual
- 1:58computer. That's it. Whenever I say EC2,
- 2:04think of it like virtual computer inside
- 2:09AWS.
- 2:10That's it. An EC2 instance is a virtual
- 2:13computer running inside an AWS data
- 2:15center. And by the end of this today's
- 2:17session, you are not just going to learn
- 2:19about EC2, read about EC2, but you are
- 2:23going to actually launch your own cloud
- 2:25server and connect to it. That's a
- 2:27pretty exciting milestone. So let's get
- 2:29started. Take a look at our road map for
- 2:31today. Think of today's session as
- 2:34building a complete cloud server. Every
- 2:36server needs four major thing. The right
- 2:39hardware,
- 2:40a pricing model, a security, and a
- 2:43storage. We will start by understanding
- 2:47the instance families because not every
- 2:49workload needs the same type of
- 2:51hardware. See a machine learning
- 2:53workload needs a different hardware than
- 2:56a web application. A database workload
- 2:58is different from a gaming server. AWS
- 3:01provide different families for different
- 3:03types of workload. Then we will discuss
- 3:05pricing models. This is one of the most
- 3:08frequently tested EC2 topics in the
- 3:09cloud practitioner exam. And after that
- 3:11we will learn about the security groups.
- 3:14What they are? Think of them as like a
- 3:16firewall protecting your server. Then we
- 3:19will discuss EBS that is elastic block
- 3:22store. What do this means? Think of it
- 3:25like a storage for EC2 instances but
- 3:30persistent storage. We will understand
- 3:32it more in the further section of the
- 3:35video. Um now and finally we will put
- 3:38everything together and we will launch a
- 3:40real EC2 instance and connect to Linux
- 3:43and then run run commands in it and we
- 3:45will see in AWS infrastructure in action
- 3:48and by the end of this video you will
- 3:50have launched your own first cloud
- 3:52server. Now before we launch anything we
- 3:55need to answer an important question.
- 3:57See what kind of servers should we
- 3:59launch? That's a great question. Yeah.
- 4:02So that's where instance families come
- 4:04in. So let us see what are instance
- 4:07families. You will see TM, C, ID, PG. It
- 4:12might look confusing but don't worry
- 4:14it's a simple thing. Uh take an example.
- 4:16Imagine if you are buying a laptop.
- 4:19I recently purchased a laptop but I
- 4:22didn't need it for heavy thing like
- 4:25gaming uh programming. I didn't want it
- 4:28for that purpose. just normal web
- 4:31browsing,
- 4:33um, writing word documents. Yeah. So,
- 4:37would I buy this laptop that is high-end
- 4:40for just normal task? Probably not.
- 4:44See, would you buy a same laptop for
- 4:46gaming, video editing, programming,
- 4:47machine learning, or web browsing? No.
- 4:50Different workloads require different
- 4:52hardware. AWS follows the exact
- 4:55principle.
- 4:56That's why EC2 instances are grouped
- 4:58into families. Each family is optimized
- 5:00for different type of workload. Means
- 5:03each family is optimized for a specific
- 5:05type of workload. Let's explore them one
- 5:08by one. The first one is TNM series. TNM
- 5:12series is called journal purpose. They
- 5:14are the most common EC2 instances. Think
- 5:16of them as the everyday laptop of the
- 5:18AWS. We have balanced CPU. We have
- 5:21balanced RAM. It has also balanced
- 5:24course as well. It is perfect for web
- 5:27applications, development environments,
- 5:29uh student projects, small databases,
- 5:32testing environments.
- 5:34For most beginners, general purpose
- 5:36instances are the correct choices. In
- 5:39today's lab, we will use T2 micro, T3
- 5:42micro. If you're unsure about what
- 5:46instance to choose, start with the
- 5:48general purpose. Later, you can upgrade
- 5:51anytime. Now let's talk about compute
- 5:55optimized that is C. From the name
- 5:57itself it is clear. Imagine a workload
- 6:01that performs million of calculations
- 6:03every second. Examples can include
- 6:05scientific simulations, gaming servers,
- 6:08financial modeling, also video
- 6:10processing or batch processing. These
- 6:13workloads care much more about the CPU
- 6:15power. That's why AWS created compute
- 6:18optimized instances. uh you can remember
- 6:22this compute optimized by C. C equal to
- 6:25compute. If the exam says high CPU
- 6:28requirement,
- 6:29think compute optimized. Now let's talk
- 6:32about RX. RX series is the memory
- 6:36optimized series. Some workloads care
- 6:39more about memory than the CPU. Examples
- 6:42include radius if you might have heard
- 6:44that we will see that SEP HANA large
- 6:48analytics platform in-memory databases
- 6:50real-time processing systems these
- 6:52actually require more RAM like uh RAM is
- 6:56the most important resource for these
- 6:58type of workloads and AWS provide memory
- 7:01optimized instances for these scenarios.
- 7:04Easy trick is whenever it says R that is
- 7:08RAM. So whenever you see a massive
- 7:11memory requirement, think memory
- 7:13optimized.
- 7:15Now let's talk about ID
- 7:18that is storage optimized series. Some
- 7:21workloads constantly read and write
- 7:24data. Examples can include NoSQL
- 7:28databases, big data platforms, data
- 7:30warehouses. See these workloads needs
- 7:33extremely fast disk performance. That's
- 7:35where storage optimized instances sign.
- 7:38Easy memory trick is I for I for IO ops.
- 7:43IOPS means input output operations per
- 7:46second. The higher is the IO ops, the
- 7:49higher is the storage performance. Okay,
- 7:54higher is the IOPS it means faster
- 7:56storage performance. Now let's talk
- 7:59about PNG that is accelerated computing
- 8:04series. So you might have heard the term
- 8:07that is GPU, machine learning, deep
- 8:10learning, AI training, image processing
- 8:12and graphics workload like editing and
- 8:16stuff. These workloads need GPU
- 8:18acceleration and AWS provide accelerated
- 8:22computing instances like P series, G
- 8:25series and if the exam asks
- 8:29a company wants to train machine
- 8:30learning models, the answer is usually
- 8:32accelerated computing. Remember that the
- 8:35easy trick is G that is graphics. Okay,
- 8:38from this you can remember that.
- 8:42So now let's test ourself. Let's say a
- 8:45company wants to run radius. A company
- 8:47wants to run radius. So which family
- 8:50should they choose? Remember don't look
- 8:52over here. Now you have heard that is RX
- 8:56series. RX series it is memory
- 8:59optimized. So we will use
- 9:03RX series. Excellent. A company needs
- 9:07GPU resources for AI model training.
- 9:09What will they use? Accelerated
- 9:12computing. Let's say I wanted to host a
- 9:15simple website. Which instant family
- 9:17will I choose? I will choose general
- 9:20purpose that is TM. Okay. Make sure to
- 9:23remember that general purpose, compute
- 9:25optimized, memory optimized, storage
- 9:27optimized, and accelerated computing.
- 9:30Got it? Now, here's an interesting part.
- 9:33AWS doesn't provide five instance types.
- 9:36It provides 100. Let's actually see them
- 9:39inside the AWS. Let me switch to
- 9:41console. As you can see, now I am in
- 9:44console.
- 9:45What I will do is simply search for EC2.
- 9:49You will find EC2 service that is
- 9:51virtual servers in the cloud written
- 9:54properly over here. I will open it. And
- 9:57now I will create an instance. So for
- 10:01that I will click on I will click on
- 10:04launch instance. Uh let me close this.
- 10:07Now you can see I need to set up um
- 10:11these some settings. We will see what
- 10:13these settings are. Let me put a name
- 10:15first. Uh this is once server not
- 10:20server. Now let me scroll scroll. You
- 10:23can find multiple OS images over here.
- 10:25You can choose whatever you need. Mac,
- 10:27you need mac OS, Ubuntu, Windows for
- 10:30your machine. And but we will see the
- 10:33instance type what we are studying right
- 10:36now. You can see the instance type.
- 10:40Whenever you click on this, you will
- 10:42find a lot of instances over here.
- 10:44Whenever you are on free tier, free
- 10:47plan, you can't select the larger
- 10:50machines.
- 10:52Remember that. And but if you are see if
- 10:55you are for learning over here you can
- 10:57just select the free tier eligible
- 10:59things and we can use them. It is also
- 11:01the large machine. It has two CPU 8 GB
- 11:05RAM and you can find the pricing over
- 11:08here. How much does this cost hourly?
- 11:12Okay. Whenever I click on compare
- 11:14instance type you can find each and
- 11:17every details like what is the network
- 11:20per performance of it? What is instance
- 11:22type? How many CPUs are there? How many
- 11:24memory? So you can select on the basis
- 11:27of that. See we have 748 plus instance
- 11:31type. So you can choose accordingly.
- 11:34Notice how many instances AWS type
- 11:35provide. You can see D M series C series
- 11:40R Z. At first glance this may look
- 11:43overwhelming but here's a good news. The
- 11:45cloud practitioner exam does not expect
- 11:47you to memorize hundred of instance
- 11:49type. It expect you to understand the
- 11:51family only
- 11:53general purpose compute optimized memory
- 11:56optimized storage optimized accelerated
- 11:59optimized
- 12:00that is accelerated computing that's
- 12:03what matters so let us go back now let's
- 12:06answer another important question how
- 12:08much does an EC2 instance cost well the
- 12:11answer depends on how you plan to use it
- 12:14AWS provides four pricing model on
- 12:18demand reserve instances, spot instances
- 12:20and dedicated host instances. And this
- 12:24is one of the most tested EC2 topics in
- 12:26the certification exam. And instead of
- 12:28memorizing the definition, let's use a
- 12:31real world scenario so you can
- 12:32understand easily. Suppose you need a
- 12:35server today. Suppose you need a server
- 12:37today. Maybe that may be for a project,
- 12:40that may be for testing, development,
- 12:41anything. You don't know how long you
- 12:43will need it and you don't want to
- 12:45commit. Which option would you choose?
- 12:48On demand. Yes, on demand. On demand
- 12:51means pay only for what you use. No
- 12:55contracts, no commitments, no upfront
- 12:58payments. It has maximum flexibility.
- 13:01This has maximum flexibility, but also
- 13:05the highest cost per hour. Think of it
- 13:07like booking a hotel room for one night.
- 13:10It is very flexible, but it is not the
- 13:13cheapest. You can't live in that hotel
- 13:16room for 10 years, 20 years. Now imagine
- 13:21a company is running a production
- 13:22application. They know they will need a
- 13:25server for the next 1 to 3 years. And
- 13:28AWS rewards the commitment.
- 13:31This is where reserved instances come
- 13:33in. By committing for 1 or 3 years,
- 13:35customer can receive significant
- 13:37discounts compared to the ondemand
- 13:39pricing. Remember this rule, commitment
- 13:42equal to savings.
- 13:44The more predictable the workload, the
- 13:46more attractive reserved instances
- 13:48become. Now let's talk about the
- 13:50cheapest option that is spot instances.
- 13:54AWS data centers sometimes have unused
- 13:56capacity. So instead of leaving them
- 13:59idle, AWS offers it at huge discounts,
- 14:02sometimes up to 90% cheaper. Sounds
- 14:06amazing, right? But there is a one
- 14:08catch. AWS can take the instance back at
- 14:10any time with approximately 2 minutes
- 14:13notice. That's why spot instances are
- 14:16great for batch processing, data
- 14:18analysis, rendering jobs, fault
- 14:20tolerance workloads, but they are
- 14:23terrible for critical production
- 14:24application.
- 14:26And talking about dedicated host and
- 14:28instances,
- 14:30this means the physical server belongs
- 14:32entirely to you. No other AWS customer
- 14:35shares that hardware. These are commonly
- 14:37used for compliance requirement or
- 14:39licensing requirement restrictions,
- 14:42regulatory workloads of any country.
- 14:44Dedicated host provide maximum isolation
- 14:47but are usually the most expensive
- 14:49options. So what's the cheapest EC2
- 14:52option for a workload that can tolerate
- 14:54interruption? What would you say? Spot
- 14:57instances. Correct.
- 14:59Let's say a company production will run
- 15:01continuously for 3 years and you are you
- 15:03know that you will be using that for 3
- 15:05years. So, which pricing model saves you
- 15:07the most money? Yes, reserved instances.
- 15:11Let's say you would need a server for
- 15:12testing this afternoon for just a
- 15:14testing purpose. Which model? Spot
- 15:17instances. No, it is on demand. Perfect.
- 15:21Now that we have understood how to
- 15:23choose and pay for the server, let's
- 15:24learn how to secure it. And that's where
- 15:27security groups come in. Now that we
- 15:29have understood how to choose an EC2
- 15:31instance and how AWS charges for it. Now
- 15:35let's talk about the security.
- 15:37Let me ask you a question. Imagine you
- 15:40buy a house. I hope this looks like
- 15:42house. Would you leave every door
- 15:45opened? Would you leave every window
- 15:48unlocked? Would you like allow everyone
- 15:51to walk inside?
- 15:53No, of course not. You decide who can
- 15:56enter your house. You decide which doors
- 16:00need to stay locked or unlocked. That's
- 16:02exactly what security groups do for EC2.
- 16:05A security groups is a EC2's virtual
- 16:08firewall. Its job is to control network
- 16:11traffic entering into the EC2 instance
- 16:14and leaving EC2 instance. See, see from
- 16:17this diagram, let's say this is my EC2
- 16:19instance and think of security groups
- 16:22like this firewall. What these security
- 16:26groups do is they allow or they deny
- 16:30they control the network traffic. Think
- 16:32of your EC2 instance as a house and
- 16:35think of security groups as the security
- 16:38guard standing at the gate and every
- 16:40incoming request every incoming request
- 16:43must pass through the security guard and
- 16:46if the rule allows it the request
- 16:49enters. If the rule blocks it
- 16:53then the request is rejected. Simple as
- 16:56that. What is security group? It is a
- 16:58stateful virtual firewall that operates
- 17:00on the AC2 instance level. Stateful
- 17:03means when you allow inbound traffic on
- 17:05a port the response traffic is
- 17:07automatically allowed outbound. No
- 17:09separate rule needed. So we need to
- 17:11understand what this inbound traffic
- 17:13means and what do these outbound traffic
- 17:16means. Okay. So let's start with
- 17:19inbound. Inbound traffic means the
- 17:23traffic coming into your EC2 instance.
- 17:27For example, a user is opening your
- 17:29website, an administrator connecting
- 17:32through SSH or an application sending
- 17:35request to a servers. These are all
- 17:37inbound connections. Here's an important
- 17:40fact. By default, AWS blocks all those
- 17:45requests. Okay? By default, AWS blocks
- 17:50all the inbound traffic, everything.
- 17:53Nothing can enter only to explicitly
- 17:55allow it. This is the security first
- 17:57design. AWS assumes block everything
- 18:00unless the customer says otherwise. And
- 18:02that's a good thing. Now let's
- 18:04understand about outbound traffic.
- 18:07Traffic leaving your EC2 instance. Let's
- 18:09say this is my EC2 instance and the
- 18:11traffic that leaves my EC2 instance is
- 18:13an outbound traffic. For example, your
- 18:16server is downloading updates
- 18:19that is uh outbound traffic. Let's say
- 18:22your application is calling another API
- 18:24or your server is accessing AWS
- 18:26services. These are all examples of
- 18:30outbound traffic and by default all
- 18:33outbound traffic is allowed. This means
- 18:34your EC2 instance can communicate
- 18:36outward without any additional
- 18:38configuration.
- 18:40Now let's understand the rule
- 18:41components. Every security group rule
- 18:44contain three important component that
- 18:47is protocol, port range, source. Don't
- 18:51worry, we will see this all in the AWS
- 18:53console. You will understand it more
- 18:55better. Let's break them down. What is
- 18:57protocol? What is port range? And what
- 18:59is source? Protocol tells AWS what type
- 19:02of traffic we are talking about. That
- 19:05may be TCP, UDP, ICMP. For the cloud
- 19:08practitioner, you will mostly see TCP.
- 19:11We will see about it.
- 19:13Port means port identify services.
- 19:17Some common examples like let's say I
- 19:20have port 22. Port 22 is for SSH. Port
- 19:25S80. Port 80 is for HTTP. Port 443
- 19:30HTTPS. talking about port 3306 that is
- 19:34for MySQL or port uh I guess 5432
- 19:41as I remember that is for postgSQL
- 19:45remember port services are like doors
- 19:48different services listen on different
- 19:50doors now it's time for source who is
- 19:53allowed it to connect
- 19:56examples my IP a C block another
- 20:00security groups
- 20:02This actually gives us the fine grained
- 20:04control. Let's imagine you are launching
- 20:07a web server. Which ports do you need?
- 20:11HTTP that is port 80. HTTPS I'm writing
- 20:16S that is port 443.
- 20:20Yes. And if you need an administration
- 20:23access then we need an SSH as well. We
- 20:28will see about SSH in the further part
- 20:30of the video. But for SSH, we need port
- 20:3422 that is used for administrator
- 20:37access. Now, here's the best practice.
- 20:40Port 22 should not be open to everyone.
- 20:43Instead, allow SSH only from your own IP
- 20:46address. So, this will dramatically
- 20:49reduce security risks. Now, let's talk
- 20:51about a word AWS loves to test that is
- 20:55stateful. Stateful means suppose a user
- 21:00sends HTTP HTTP request to your server.
- 21:05AWS allows that request because port 80
- 21:07is open.
- 21:09When your server sends the response
- 21:11back, AWS automatically allows it. You
- 21:13don't you do not need a separate
- 21:15outbound rule. The response is
- 21:17automatically permitted. That's what
- 21:19stateful means. And AWS exams this
- 21:21constantly. Remember security groups
- 21:23equal to stateful. a stateful virtual
- 21:27firewall that operates on the EC2
- 21:29instance level. So there's a quick
- 21:31question for you. Are the security
- 21:34groups stateful or stateless? Stateful.
- 21:37What is the default inbound behavior? By
- 21:40default, all the inbound traffic is
- 21:42blocked and all outbound traffic is
- 21:44allowed. Okay. So now let's actually see
- 21:47security groups in action. Theory part
- 21:49is done. Now we will see where are these
- 21:51located? What is this security group?
- 21:53how like we are controlling the inbound
- 21:55traffic, outbound traffic, how we are
- 21:56setting this up, all these things. Let
- 21:59us go to the console. As I'm in the
- 22:01dashboard, let's take a look at real
- 22:04security groups. You will find this um
- 22:07security groups option over here. I will
- 22:11click on security groups and then you
- 22:13will find security groups like I do have
- 22:15two security groups one default and one
- 22:17is WordPress certified bit naming. So
- 22:20let me customize this one. This is my
- 22:22security groups that I am using. You can
- 22:25find three inbound rules over here that
- 22:28is SSH, HTTP, HTTPS. These are the rules
- 22:32I was using for my web application. So
- 22:35here you can see protocol, port range
- 22:38and source.
- 22:40Let me try adding a rule one inbound
- 22:43rule. I will click on add rule. I will
- 22:45click on SSH. This is how you create a
- 22:48rule. You can see port range that is 22
- 22:52is automatically selected. That is
- 22:53default for SSH. And now I will only
- 22:57allow that SSH. You can select the
- 23:00source as anywhere IPv4 or my IP only.
- 23:04What you want to do like you want to
- 23:06allow the connection to be uh done only
- 23:09through your PC only your IP. So what I
- 23:13will do is select on my IP. Okay. So my
- 23:16IP is selected and yes we are done. You
- 23:19can simply click on save rules and you
- 23:21are done. So this is how you customize
- 23:24the security groups. This is an easy way
- 23:28but I do have two security groups. So I
- 23:30don't need to SSH. What I will do is
- 23:33delete one. You can try adding HTTP. The
- 23:37port 80 will be automatically selected
- 23:38and yeah you need the source anywhere.
- 23:42So you might find there is an another
- 23:45rule that is HTTP and HTTP allows
- 23:48traffic from anywhere in the world that
- 23:50is 000000
- 23:52/ zero. That means this allows anyone on
- 23:54the internet to access our website.
- 23:56Notice how security groups are simply
- 23:58collection of allow rules. We don't
- 24:00create deny rules here. Only allow
- 24:03rules. This is an important exam fact.
- 24:04Security groups only allow rules only.
- 24:07You can find the outbound rules over
- 24:09here means which traffic to send out
- 24:13from the server. Now our server is
- 24:16secure but a server also needs storage.
- 24:20So that's where EBS comes in. Let us see
- 24:23what is EBS. Imagine you have a file
- 24:26saved on your laptop. Then you shut down
- 24:29your laptop. When you turn it back on
- 24:31tomorrow, what happens? The file is
- 24:33still there. Why? What is the reason
- 24:35behind that? because it is stored in
- 24:37hard drive. EC2 needs storage too.
- 24:40That's where EBS comes in. Think of EBS
- 24:44like an hard drive attached to your
- 24:47cloud server. Without storage, your
- 24:49server would have nowhere to keep the
- 24:51file. No operating system, no
- 24:53application, no data. Everything would
- 24:56disappear. Everything would disappear.
- 24:59EBS solves that problem. Here's one of
- 25:01the most tested EBS concepts.
- 25:04Data persistence. Data persist when the
- 25:07EC2 instance is stopped.
- 25:10Data is deleted by default when an
- 25:12instance is terminated unless configured
- 25:15otherwise.
- 25:16Okay. The data remains on the EBS volume
- 25:18if it is configured. This surprises many
- 25:21beginners because they think stopping
- 25:23the server deletes everything. It
- 25:25doesn't. Stopping an EC2 instance is
- 25:27like shutting down your laptop and your
- 25:29files remain. We have ABS volume types
- 25:32that is GP3, IO2, ST1, SC1. Let us see
- 25:36that AWS provides different volume types
- 25:39for different purpose. GP3 is the
- 25:42default choice for most and honestly
- 25:45it's the correct answer most of the
- 25:46time. General purpose SSD. It has
- 25:49balanced performance, balanced cost. It
- 25:51is suitable for web application
- 25:53development, testing, boot volumes. If
- 25:55you are unsure what to choose, choose
- 25:58GP3. Now IO2 that is block express.
- 26:03Now imagine a mission critical database
- 26:06Oracle SQL server or there might be
- 26:09enterprise workloads.
- 26:11These applications need extremely high
- 26:14performance. That's where IIO2 comes in.
- 26:17It has much higher IOPS input output per
- 26:20second, much higher reliability and much
- 26:23higher cost. Talking about SD1
- 26:27throughput optimized SDDD hard disk
- 26:30drive they are designed for large
- 26:32sequential workloads and examples
- 26:34include big data log processing map
- 26:37reduce or large file processing. The
- 26:39last one is SC1 cold SD. From the name
- 26:42itself it must be clear it is the
- 26:45cheapest EBS option and it is used for
- 26:48rarely access data. One important
- 26:50limitation is that SC1 cannot be used as
- 26:54boot volume. AWS likes asking that. So
- 26:57remember that. Another exam favorite EBS
- 27:01volumes are tied to single AZs and they
- 27:03cannot be directly attached to the EC2
- 27:05instance in a different availability
- 27:06zone. Let us take an example. Let's say
- 27:09if my volume exist here in Mumbai AZ.
- 27:13So it cannot be directly attached to the
- 27:15EC2 instance running in Mumbai AZ B.
- 27:19Remember that EBS is a aability zone
- 27:22specific. Which EBS volume type should
- 27:25most customer used? What you will
- 27:27choose? GP3. If asked, does EBS survive
- 27:32a stop operation? Yes. Can an EBS volume
- 27:35be directly attached across aability
- 27:37zones? No. Excellent. Now, let's take a
- 27:41look at EBS inside the AWS. So let me
- 27:44show you where do this volumes where do
- 27:47this elastic block store lives. You can
- 27:49find this in in the dashboard of EC2.
- 27:53You will find this volume option and you
- 27:55can create these volumes manually as
- 27:57well. Select the volume type. We have
- 27:59GP2, GP3. These are both for general
- 28:01purpose and IOPS SSD IO1 and IO2. You
- 28:05can select whatever you need. Let's see.
- 28:06I select the GP2 or GP3 whatever you
- 28:09can. You can define the size. How much
- 28:12do you want? What is the IO ops? You can
- 28:14define that through portut and in which
- 28:17avail which availability zone do you
- 28:19need that remember that um in if your
- 28:23server is in Mumbai AZ you need to uh
- 28:28put that uh volume in the in the same
- 28:30availability zone you can set up tags
- 28:33and you can simply click on create
- 28:35volume and your volume is created okay
- 28:39now we have reached the most exciting
- 28:41part of today's session up until now we
- 28:42have been discussing concept We have
- 28:44talked about EC2. We explored instance
- 28:46families. We learned pricing models. We
- 28:48have understood security groups. We have
- 28:50discussed EBS storage. Now it's time to
- 28:53put everything together. We are going to
- 28:55launch our real cloud server, not a
- 28:58simulation or a screenshot and actually
- 29:00C2 instance running inside AWS data
- 29:02center. So by the end of this lab, you
- 29:05will be clear and you will be having
- 29:07your own cloud server running on AWS.
- 29:10Just follow these steps. Once I'm in the
- 29:13AWS console, I will simply search for
- 29:15EC2 or I can find my EC2 over here. I
- 29:18will click on EC2 and here is my EC2
- 29:21dashboard.
- 29:22See in the EC2 dashboard you have uh a
- 29:26lot of options like instances,
- 29:27autoscaling groups, capacity
- 29:29reservations.
- 29:31Don't get overwhelmed by these all
- 29:33things. We will look we will see all
- 29:36these things in upcoming videos as well.
- 29:39Now what I will do you can select the
- 29:42region in which you want as I wanted
- 29:45that to be in Mumbai region. So I will
- 29:47select the Mumbai region and then click
- 29:49on launch instance. Always
- 29:53double check the reason because
- 29:55resources are created inside a specific
- 29:57region. So now name this instance
- 30:01SBG power. Okay, these names are not
- 30:05globally unique. So you can write
- 30:07anything. Now, here's an important
- 30:09point. Names don't affect functionality.
- 30:12AWS doesn't care whatever you call it.
- 30:14You call it production web server, you
- 30:16call it my first EC2, my EC2, his EC2,
- 30:19anything. The service behaves exactly
- 30:22the same. The names are for our
- 30:24recognization, for our understanding.
- 30:26Good naming makes the management easier.
- 30:28So, I suggest you to keep good names.
- 30:31Here I'm keeping SBG power because I
- 30:33know this is for SBG uh training purpose
- 30:36only. Why do we need names? Imagine if
- 30:39you are managing 500 servers
- 30:42then proper naming becomes extremely
- 30:44important. Now, now what you do uh in
- 30:47the application and OS images, select an
- 30:49image what you need. You can select Mac
- 30:51OS, Ubuntu, Windows, whatever you need.
- 30:53Let me select Amazon Linux for now. And
- 30:56you can check whether it is free tier
- 30:59eligible or not in the AMI. So what is
- 31:02this AMI? AMI stands for Amazon machine
- 31:05image. Think of AMI as a template.
- 31:07Whenever you install Windows on a
- 31:09laptop, you start with an installation
- 31:11image. And AMI serves the similar
- 31:13purpose. So I will select this one only.
- 31:17This is the AWS own Linux distribution.
- 31:19It's optimized for AWS workloads. Notice
- 31:22the free tier eligible badge and that's
- 31:24exactly what we are want for learning.
- 31:26Select Amazon Linux 2023 and choose the
- 31:28instance type.
- 31:30You can select any instant type based on
- 31:33your need. But we will select the free
- 31:35tier eligible only. So let us go with
- 31:38the T3 micro that is for general
- 31:41purpose.
- 31:42You can see the pricing over here. How
- 31:44much does it charges? Now we choose our
- 31:46hardware. This is where our earlier
- 31:48lesson on instance families become
- 31:50useful. Let's select T2 micro. I don't
- 31:52have T2 micro. Okay. Let's select T3
- 31:54micro.
- 31:56So which family does it belong to?
- 31:58General purpose. Yes. It has balanced
- 32:01CPU, balanced memory. It is perfect for
- 32:03learning purpose and also small
- 32:05applications. Notice the free tier
- 32:08eligible badge for the beginner. This is
- 32:10usually the right choice. Now we are
- 32:12going to create something extremely
- 32:14important that is key pair. Think of
- 32:17this as a key to a cloud server. Without
- 32:19this key accessing the server becomes
- 32:20much more difficult. So what I will do
- 32:23is click on create a new key pair. And
- 32:26you can name it anything. Let me name
- 32:28it. Let me name it my SBG key. Select
- 32:35the type RSA and format as PEM. Now
- 32:40click on create key. Notice AWS
- 32:43automatically downloads the key for you
- 32:45and AWS will never show it again. Treat
- 32:48this file exactly like the key to your
- 32:50house. Never upload it to GitHub, never
- 32:51email it and never share it publicly and
- 32:54absolutely never show it contents in the
- 32:57screen. Store it safely. We will need it
- 33:00whenever we want secure access to our
- 33:02server.
- 33:03So now let's configure the network
- 33:07security. Uh remember our house analogy.
- 33:10This is where we decide which doors are
- 33:12open. Now what you can do here you can
- 33:15select create security group and you can
- 33:19select what you want to allow allow SSH
- 33:21traffic from anywhere from my IP only or
- 33:24what SSS allows administrator to connect
- 33:27to the Linux server and AWS
- 33:30automatically selects port 22 for this
- 33:32you can select the existing security
- 33:34groups as well if you have those I will
- 33:37click I will create and select my IP
- 33:41will allow HTTPS traffic And I will
- 33:43allow HTTP traffic as well. Why do we
- 33:46need this? Because if we why we need
- 33:49this? If we eventually host a website,
- 33:52we want everyone to access it. This is
- 33:54the common web server configuration. Now
- 33:57our security group is also ready. You
- 33:59can configure how much storage do you
- 34:01want and what type of file system do you
- 34:04want to choose. For now what I will do I
- 34:08will just keep that as it is and click
- 34:12on launch instance. AWS is now
- 34:14provisioning a virtual server for us
- 34:16inside a data center. You can see
- 34:18successfully initiated launch of
- 34:20instance.
- 34:22I when I whenever I click on this you
- 34:24can see my instances is in the running
- 34:26state. Okay. Now what I can do is click
- 34:28on instance ID and now we are taken to
- 34:31the EC2 instance page. Observe the state
- 34:35instance state it is running. Okay. If
- 34:38it is showing pending for you that means
- 34:40EC2 is creating the server for you. You
- 34:43will see after a time after a short time
- 34:46in a minute or two you will find this as
- 34:49in a running state. Your first EC2
- 34:52instance is now running. Now comes the
- 34:54fun part. Let's actually connect to the
- 34:55server. There are various method to
- 34:58connect to the server. Uh the first one
- 35:00the one you can use is click on connect
- 35:03and here I do have EC2 instance connect
- 35:06SSM session manager SSH client EC2
- 35:08serial console. What I will do? Click on
- 35:11EC2 instance connect. I will select it
- 35:14is it has default public connect using
- 35:16public IP and yes connect. You might see
- 35:20an error. Okay. Yes. So we will see what
- 35:23is this error. When you will see this in
- 35:26the security option,
- 35:28we have inbound rule set up as you can
- 35:31see what was this rule. This was SSH
- 35:33access. We have set this as our IP. What
- 35:37do this means? See um the reason your
- 35:40connection is denied is that the browser
- 35:43based EC2 instance connect does not
- 35:45route traffic through your personal IP
- 35:47address. Instead, what it does is AWS
- 35:50uses uses its own regional IP to bridge
- 35:52the connection from your browser to your
- 35:55virtual machine because your current
- 35:58security group setup allows only
- 36:00explicit local IP, your personal IP. So,
- 36:03AWS blocks its own connection
- 36:04infrastructure. So, we need to set up
- 36:06that we need to find uh our
- 36:10regional IP. You can search it on
- 36:13Google. Okay. Once we are once we have
- 36:16got that for AP south one for Asia
- 36:20Pacific region for Mumbai AP south one
- 36:23my IP is this one. So what I will do is
- 36:26edit inbound rules
- 36:28and then
- 36:32let me put it like this C block. You can
- 36:36add one more rule that is SSH that
- 36:39allows traffic from your IP as well.
- 36:42Okay, we can click on save and you're
- 36:44done. Now let us try to connect to EC2
- 36:47instance again. I will go to instances
- 36:50and then select this one and click on
- 36:53connect
- 36:55and connect. Congratulation. Now you
- 36:58have connected to your first EC2
- 37:00instance. Take a moment. A few minutes
- 37:03ago we had nothing. Now we are connected
- 37:05to a real Linux server inside AWS. This
- 37:08is a major milestone in your cloud
- 37:10journey. So let me run an command that
- 37:13is who am I? EC2 user. It tells the
- 37:17current user and now host name. So this
- 37:22displays your server host name. Every
- 37:24Linux machine has a host name. Think of
- 37:26it as a machine's identity. You can also
- 37:29check how much memory do you have.
- 37:32Notice the RAM available to our
- 37:34instance. Remember our discussion about
- 37:36instance families. Different instance
- 37:39type provide different amount of CPU and
- 37:41memory. So you can find this over here.
- 37:45You can also check okay DFH. Okay, it is
- 37:49DFH.
- 37:50And notice the volume attached to the
- 37:52instance. This is our EBS volume. The
- 37:55storage we discussed earlier is now
- 37:56visible inside the Linux. This is where
- 37:58our files live. Now let's update our
- 38:00software packages. This is similar to
- 38:02installing updates on our Windows. What
- 38:05I will do is write sudo dnf
- 38:09update
- 38:11space dash y. So what it will do is it
- 38:15will keep it will install updates on our
- 38:18system. So because keeping system
- 38:21updated is an important security best
- 38:23practice. So this may take a minute.
- 38:25While it runs, remember that managing
- 38:28the operating system is our
- 38:30responsibility
- 38:31because EC2 follows the shared
- 38:34responsibility model. As you can see,
- 38:36Amazon Linux 2023 kernel live patch
- 38:39repository. Nothing to do complete.
- 38:41Okay, I was thinking should I show you
- 38:43how you can set up your own web server
- 38:46today by installing Apache on that
- 38:49because Apache is one of the most
- 38:50popular web servers. We will do that web
- 38:54server part in our next video. Now what
- 38:56I will do is close this one. Before you
- 38:59close this AWS console, what I want you
- 39:02to do is stop the machine. You can even
- 39:06delete or terminate instance so that it
- 39:08doesn't cost you. So what I will do is
- 39:11for now I will just click on stop this
- 39:14machine and click on stop.
- 39:17Uh if I check in elastic block store you
- 39:20will find there is one volume
- 39:22automatically attached to my EC2
- 39:25instance. You can check this is my EC2
- 39:28instance attach resources status. Got
- 39:30it? Before we finish today here is an
- 39:33important thing you need to remember.
- 39:34Whenever I click on stop button it
- 39:37doesn't terminate. And when I click on
- 39:40delete terminate what it will do? It
- 39:43will completely delete. That means stop
- 39:46means just turning off your server. That
- 39:49is your data remains, your EBS volume
- 39:51remains, your operating system remains
- 39:53as it is. But the termination is
- 39:55different. Termination permanently
- 39:58deletes the instance. AWS asks this
- 40:00frequently in certification exam.
- 40:01Remember stop is equal to pause and
- 40:05terminate is equal to delete. Also
- 40:08remember while stopped compute charges
- 40:10stopped. storage charges for EBS may
- 40:13continue. That's why we always stop lab
- 40:16instances when we are done.
- 40:18Congratulation, you have successfully
- 40:20launched and connected and managed your
- 40:22first EC2 instance. Now you're
- 40:23officially working with the cloud. As of
- 40:26the summary, so today was a huge
- 40:28milestone in our AWS journey. Let's take
- 40:30a moment and appreciate what we have
- 40:32accomplished
- 40:34this morning. Many of you may have never
- 40:36launched a cloud server before. Now we
- 40:38have launched a real EC2 instance
- 40:40connected to Linux explored storage
- 40:42configured networking also created a
- 40:44security groups that's a real cloud
- 40:47infrastructure not theory not simulation
- 40:49these are actual AWS server running
- 40:52inside AWS data center let us quickly
- 40:54review what we have learned today um we
- 40:57have completed instance families we have
- 40:59learned about what are the pricing
- 41:00models what are the security groups EBS
- 41:03storage so what I want you to do is
- 41:06practice some questions on EC2 that are
- 41:09provided in the notes itself. So do it
- 41:12and tomorrow we will learn how modern
- 41:15cloud application move beyond
- 41:16traditional servers. We will explore
- 41:18AWS, Lambda, ECS, EKS and Far Grate and
- 41:24containers as well and serverless
- 41:25computing. You will discover why many
- 41:28organization today don't even manage
- 41:30server directly anymore. It is one of
- 41:32the most exciting topics in the AWS
- 41:34ecosystem. So fantastic work today
- 41:36everyone. You launched your first EC2
- 41:38instance, connected everything. Today
- 41:40was the major achievement. Keep
- 41:42practicing, keep building and most
- 41:44importantly stay curious. Thank you for
- 41:47joining day eight of our AWS builder
- 41:49challenge. I will see you tomorrow on
- 41:51day 9. Take care and happy
About this transcript
This page contains the full transcript of Amazon EC2 Explained | Instance Types, Pricing & Security Groups | AWS CLF-C02 Day 8 by Pawan Joshi, generated from the public captions YouTube serves with the video. The transcript has 6,155 words across 942 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.