YouTube2Text

Amazon EC2 Explained | Instance Types, Pricing & Security Groups | AWS CLF-C02 Day 8 — Transcript

by Pawan Joshi · 6,155 words · 942 segments · language en · Watch on YouTube

Full transcript

  1. 0:00Hello everyone, welcome back to day
  2. 0:02eight of our AWS builder challenge. I
  3. 0:04hope you are enjoying the journey so far
  4. 0:05because today we are finally going to
  5. 0:09learn, read, understand one of the most
  6. 0:12important service in AWS that is Amazon
  7. 0:15EC2.
  8. 0:16If AWS had a celebrity service, EC2
  9. 0:19would probably be it. In fact, when most
  10. 0:21people think about AWS, they think about
  11. 0:24EC2. Before we talk about EC2, let me
  12. 0:27ask you a simple question. When you open
  13. 0:30Instagram, where are those photos
  14. 0:32stored?
  15. 0:33Or whenever you watch YouTube, where
  16. 0:35does the video come from? Everything
  17. 0:38comes from servers. At the end of the
  18. 0:40day, applications need computers to run.
  19. 0:44Traditionally, companies had to buy
  20. 0:46physical servers. They had to buy
  21. 0:48hardware, data centers. Uh they had to
  22. 0:51manage the electricity, cooling systems
  23. 0:53as well as networking, security,
  24. 0:55maintenance and a lot. And if there is
  25. 0:58sudden rise in traffic then they had to
  26. 1:01buy even more hardware. This process
  27. 1:04could takes weeks or even months. And
  28. 1:07that cloud computing had changed that
  29. 1:10model. And instead of buying servers,
  30. 1:14companies can now rent them whenever
  31. 1:16they need them. If you need one server,
  32. 1:20you can launch one. You need 10, you can
  33. 1:23launch 10. If you need 100, you can
  34. 1:26launch 100 as well. And let's say if you
  35. 1:29need them only for 2 hours, you can get
  36. 1:33them for 2 hours only and pay only for 2
  37. 1:36hours. And that is exactly what EC2
  38. 1:38provides. EC2 stands for elastic compute
  39. 1:44cloud. Here C2 means there are two C's
  40. 1:48that is CL compute cloud. Elastic
  41. 1:50compute cloud. Now let's simplify that.
  42. 1:53Whenever I say EC2 instance, I want uh
  43. 1:56you to simply think about virtual
  44. 1:58computer. That's it. Whenever I say EC2,
  45. 2:04think of it like virtual computer inside
  46. 2:09AWS.
  47. 2:10That's it. An EC2 instance is a virtual
  48. 2:13computer running inside an AWS data
  49. 2:15center. And by the end of this today's
  50. 2:17session, you are not just going to learn
  51. 2:19about EC2, read about EC2, but you are
  52. 2:23going to actually launch your own cloud
  53. 2:25server and connect to it. That's a
  54. 2:27pretty exciting milestone. So let's get
  55. 2:29started. Take a look at our road map for
  56. 2:31today. Think of today's session as
  57. 2:34building a complete cloud server. Every
  58. 2:36server needs four major thing. The right
  59. 2:39hardware,
  60. 2:40a pricing model, a security, and a
  61. 2:43storage. We will start by understanding
  62. 2:47the instance families because not every
  63. 2:49workload needs the same type of
  64. 2:51hardware. See a machine learning
  65. 2:53workload needs a different hardware than
  66. 2:56a web application. A database workload
  67. 2:58is different from a gaming server. AWS
  68. 3:01provide different families for different
  69. 3:03types of workload. Then we will discuss
  70. 3:05pricing models. This is one of the most
  71. 3:08frequently tested EC2 topics in the
  72. 3:09cloud practitioner exam. And after that
  73. 3:11we will learn about the security groups.
  74. 3:14What they are? Think of them as like a
  75. 3:16firewall protecting your server. Then we
  76. 3:19will discuss EBS that is elastic block
  77. 3:22store. What do this means? Think of it
  78. 3:25like a storage for EC2 instances but
  79. 3:30persistent storage. We will understand
  80. 3:32it more in the further section of the
  81. 3:35video. Um now and finally we will put
  82. 3:38everything together and we will launch a
  83. 3:40real EC2 instance and connect to Linux
  84. 3:43and then run run commands in it and we
  85. 3:45will see in AWS infrastructure in action
  86. 3:48and by the end of this video you will
  87. 3:50have launched your own first cloud
  88. 3:52server. Now before we launch anything we
  89. 3:55need to answer an important question.
  90. 3:57See what kind of servers should we
  91. 3:59launch? That's a great question. Yeah.
  92. 4:02So that's where instance families come
  93. 4:04in. So let us see what are instance
  94. 4:07families. You will see TM, C, ID, PG. It
  95. 4:12might look confusing but don't worry
  96. 4:14it's a simple thing. Uh take an example.
  97. 4:16Imagine if you are buying a laptop.
  98. 4:19I recently purchased a laptop but I
  99. 4:22didn't need it for heavy thing like
  100. 4:25gaming uh programming. I didn't want it
  101. 4:28for that purpose. just normal web
  102. 4:31browsing,
  103. 4:33um, writing word documents. Yeah. So,
  104. 4:37would I buy this laptop that is high-end
  105. 4:40for just normal task? Probably not.
  106. 4:44See, would you buy a same laptop for
  107. 4:46gaming, video editing, programming,
  108. 4:47machine learning, or web browsing? No.
  109. 4:50Different workloads require different
  110. 4:52hardware. AWS follows the exact
  111. 4:55principle.
  112. 4:56That's why EC2 instances are grouped
  113. 4:58into families. Each family is optimized
  114. 5:00for different type of workload. Means
  115. 5:03each family is optimized for a specific
  116. 5:05type of workload. Let's explore them one
  117. 5:08by one. The first one is TNM series. TNM
  118. 5:12series is called journal purpose. They
  119. 5:14are the most common EC2 instances. Think
  120. 5:16of them as the everyday laptop of the
  121. 5:18AWS. We have balanced CPU. We have
  122. 5:21balanced RAM. It has also balanced
  123. 5:24course as well. It is perfect for web
  124. 5:27applications, development environments,
  125. 5:29uh student projects, small databases,
  126. 5:32testing environments.
  127. 5:34For most beginners, general purpose
  128. 5:36instances are the correct choices. In
  129. 5:39today's lab, we will use T2 micro, T3
  130. 5:42micro. If you're unsure about what
  131. 5:46instance to choose, start with the
  132. 5:48general purpose. Later, you can upgrade
  133. 5:51anytime. Now let's talk about compute
  134. 5:55optimized that is C. From the name
  135. 5:57itself it is clear. Imagine a workload
  136. 6:01that performs million of calculations
  137. 6:03every second. Examples can include
  138. 6:05scientific simulations, gaming servers,
  139. 6:08financial modeling, also video
  140. 6:10processing or batch processing. These
  141. 6:13workloads care much more about the CPU
  142. 6:15power. That's why AWS created compute
  143. 6:18optimized instances. uh you can remember
  144. 6:22this compute optimized by C. C equal to
  145. 6:25compute. If the exam says high CPU
  146. 6:28requirement,
  147. 6:29think compute optimized. Now let's talk
  148. 6:32about RX. RX series is the memory
  149. 6:36optimized series. Some workloads care
  150. 6:39more about memory than the CPU. Examples
  151. 6:42include radius if you might have heard
  152. 6:44that we will see that SEP HANA large
  153. 6:48analytics platform in-memory databases
  154. 6:50real-time processing systems these
  155. 6:52actually require more RAM like uh RAM is
  156. 6:56the most important resource for these
  157. 6:58type of workloads and AWS provide memory
  158. 7:01optimized instances for these scenarios.
  159. 7:04Easy trick is whenever it says R that is
  160. 7:08RAM. So whenever you see a massive
  161. 7:11memory requirement, think memory
  162. 7:13optimized.
  163. 7:15Now let's talk about ID
  164. 7:18that is storage optimized series. Some
  165. 7:21workloads constantly read and write
  166. 7:24data. Examples can include NoSQL
  167. 7:28databases, big data platforms, data
  168. 7:30warehouses. See these workloads needs
  169. 7:33extremely fast disk performance. That's
  170. 7:35where storage optimized instances sign.
  171. 7:38Easy memory trick is I for I for IO ops.
  172. 7:43IOPS means input output operations per
  173. 7:46second. The higher is the IO ops, the
  174. 7:49higher is the storage performance. Okay,
  175. 7:54higher is the IOPS it means faster
  176. 7:56storage performance. Now let's talk
  177. 7:59about PNG that is accelerated computing
  178. 8:04series. So you might have heard the term
  179. 8:07that is GPU, machine learning, deep
  180. 8:10learning, AI training, image processing
  181. 8:12and graphics workload like editing and
  182. 8:16stuff. These workloads need GPU
  183. 8:18acceleration and AWS provide accelerated
  184. 8:22computing instances like P series, G
  185. 8:25series and if the exam asks
  186. 8:29a company wants to train machine
  187. 8:30learning models, the answer is usually
  188. 8:32accelerated computing. Remember that the
  189. 8:35easy trick is G that is graphics. Okay,
  190. 8:38from this you can remember that.
  191. 8:42So now let's test ourself. Let's say a
  192. 8:45company wants to run radius. A company
  193. 8:47wants to run radius. So which family
  194. 8:50should they choose? Remember don't look
  195. 8:52over here. Now you have heard that is RX
  196. 8:56series. RX series it is memory
  197. 8:59optimized. So we will use
  198. 9:03RX series. Excellent. A company needs
  199. 9:07GPU resources for AI model training.
  200. 9:09What will they use? Accelerated
  201. 9:12computing. Let's say I wanted to host a
  202. 9:15simple website. Which instant family
  203. 9:17will I choose? I will choose general
  204. 9:20purpose that is TM. Okay. Make sure to
  205. 9:23remember that general purpose, compute
  206. 9:25optimized, memory optimized, storage
  207. 9:27optimized, and accelerated computing.
  208. 9:30Got it? Now, here's an interesting part.
  209. 9:33AWS doesn't provide five instance types.
  210. 9:36It provides 100. Let's actually see them
  211. 9:39inside the AWS. Let me switch to
  212. 9:41console. As you can see, now I am in
  213. 9:44console.
  214. 9:45What I will do is simply search for EC2.
  215. 9:49You will find EC2 service that is
  216. 9:51virtual servers in the cloud written
  217. 9:54properly over here. I will open it. And
  218. 9:57now I will create an instance. So for
  219. 10:01that I will click on I will click on
  220. 10:04launch instance. Uh let me close this.
  221. 10:07Now you can see I need to set up um
  222. 10:11these some settings. We will see what
  223. 10:13these settings are. Let me put a name
  224. 10:15first. Uh this is once server not
  225. 10:20server. Now let me scroll scroll. You
  226. 10:23can find multiple OS images over here.
  227. 10:25You can choose whatever you need. Mac,
  228. 10:27you need mac OS, Ubuntu, Windows for
  229. 10:30your machine. And but we will see the
  230. 10:33instance type what we are studying right
  231. 10:36now. You can see the instance type.
  232. 10:40Whenever you click on this, you will
  233. 10:42find a lot of instances over here.
  234. 10:44Whenever you are on free tier, free
  235. 10:47plan, you can't select the larger
  236. 10:50machines.
  237. 10:52Remember that. And but if you are see if
  238. 10:55you are for learning over here you can
  239. 10:57just select the free tier eligible
  240. 10:59things and we can use them. It is also
  241. 11:01the large machine. It has two CPU 8 GB
  242. 11:05RAM and you can find the pricing over
  243. 11:08here. How much does this cost hourly?
  244. 11:12Okay. Whenever I click on compare
  245. 11:14instance type you can find each and
  246. 11:17every details like what is the network
  247. 11:20per performance of it? What is instance
  248. 11:22type? How many CPUs are there? How many
  249. 11:24memory? So you can select on the basis
  250. 11:27of that. See we have 748 plus instance
  251. 11:31type. So you can choose accordingly.
  252. 11:34Notice how many instances AWS type
  253. 11:35provide. You can see D M series C series
  254. 11:40R Z. At first glance this may look
  255. 11:43overwhelming but here's a good news. The
  256. 11:45cloud practitioner exam does not expect
  257. 11:47you to memorize hundred of instance
  258. 11:49type. It expect you to understand the
  259. 11:51family only
  260. 11:53general purpose compute optimized memory
  261. 11:56optimized storage optimized accelerated
  262. 11:59optimized
  263. 12:00that is accelerated computing that's
  264. 12:03what matters so let us go back now let's
  265. 12:06answer another important question how
  266. 12:08much does an EC2 instance cost well the
  267. 12:11answer depends on how you plan to use it
  268. 12:14AWS provides four pricing model on
  269. 12:18demand reserve instances, spot instances
  270. 12:20and dedicated host instances. And this
  271. 12:24is one of the most tested EC2 topics in
  272. 12:26the certification exam. And instead of
  273. 12:28memorizing the definition, let's use a
  274. 12:31real world scenario so you can
  275. 12:32understand easily. Suppose you need a
  276. 12:35server today. Suppose you need a server
  277. 12:37today. Maybe that may be for a project,
  278. 12:40that may be for testing, development,
  279. 12:41anything. You don't know how long you
  280. 12:43will need it and you don't want to
  281. 12:45commit. Which option would you choose?
  282. 12:48On demand. Yes, on demand. On demand
  283. 12:51means pay only for what you use. No
  284. 12:55contracts, no commitments, no upfront
  285. 12:58payments. It has maximum flexibility.
  286. 13:01This has maximum flexibility, but also
  287. 13:05the highest cost per hour. Think of it
  288. 13:07like booking a hotel room for one night.
  289. 13:10It is very flexible, but it is not the
  290. 13:13cheapest. You can't live in that hotel
  291. 13:16room for 10 years, 20 years. Now imagine
  292. 13:21a company is running a production
  293. 13:22application. They know they will need a
  294. 13:25server for the next 1 to 3 years. And
  295. 13:28AWS rewards the commitment.
  296. 13:31This is where reserved instances come
  297. 13:33in. By committing for 1 or 3 years,
  298. 13:35customer can receive significant
  299. 13:37discounts compared to the ondemand
  300. 13:39pricing. Remember this rule, commitment
  301. 13:42equal to savings.
  302. 13:44The more predictable the workload, the
  303. 13:46more attractive reserved instances
  304. 13:48become. Now let's talk about the
  305. 13:50cheapest option that is spot instances.
  306. 13:54AWS data centers sometimes have unused
  307. 13:56capacity. So instead of leaving them
  308. 13:59idle, AWS offers it at huge discounts,
  309. 14:02sometimes up to 90% cheaper. Sounds
  310. 14:06amazing, right? But there is a one
  311. 14:08catch. AWS can take the instance back at
  312. 14:10any time with approximately 2 minutes
  313. 14:13notice. That's why spot instances are
  314. 14:16great for batch processing, data
  315. 14:18analysis, rendering jobs, fault
  316. 14:20tolerance workloads, but they are
  317. 14:23terrible for critical production
  318. 14:24application.
  319. 14:26And talking about dedicated host and
  320. 14:28instances,
  321. 14:30this means the physical server belongs
  322. 14:32entirely to you. No other AWS customer
  323. 14:35shares that hardware. These are commonly
  324. 14:37used for compliance requirement or
  325. 14:39licensing requirement restrictions,
  326. 14:42regulatory workloads of any country.
  327. 14:44Dedicated host provide maximum isolation
  328. 14:47but are usually the most expensive
  329. 14:49options. So what's the cheapest EC2
  330. 14:52option for a workload that can tolerate
  331. 14:54interruption? What would you say? Spot
  332. 14:57instances. Correct.
  333. 14:59Let's say a company production will run
  334. 15:01continuously for 3 years and you are you
  335. 15:03know that you will be using that for 3
  336. 15:05years. So, which pricing model saves you
  337. 15:07the most money? Yes, reserved instances.
  338. 15:11Let's say you would need a server for
  339. 15:12testing this afternoon for just a
  340. 15:14testing purpose. Which model? Spot
  341. 15:17instances. No, it is on demand. Perfect.
  342. 15:21Now that we have understood how to
  343. 15:23choose and pay for the server, let's
  344. 15:24learn how to secure it. And that's where
  345. 15:27security groups come in. Now that we
  346. 15:29have understood how to choose an EC2
  347. 15:31instance and how AWS charges for it. Now
  348. 15:35let's talk about the security.
  349. 15:37Let me ask you a question. Imagine you
  350. 15:40buy a house. I hope this looks like
  351. 15:42house. Would you leave every door
  352. 15:45opened? Would you leave every window
  353. 15:48unlocked? Would you like allow everyone
  354. 15:51to walk inside?
  355. 15:53No, of course not. You decide who can
  356. 15:56enter your house. You decide which doors
  357. 16:00need to stay locked or unlocked. That's
  358. 16:02exactly what security groups do for EC2.
  359. 16:05A security groups is a EC2's virtual
  360. 16:08firewall. Its job is to control network
  361. 16:11traffic entering into the EC2 instance
  362. 16:14and leaving EC2 instance. See, see from
  363. 16:17this diagram, let's say this is my EC2
  364. 16:19instance and think of security groups
  365. 16:22like this firewall. What these security
  366. 16:26groups do is they allow or they deny
  367. 16:30they control the network traffic. Think
  368. 16:32of your EC2 instance as a house and
  369. 16:35think of security groups as the security
  370. 16:38guard standing at the gate and every
  371. 16:40incoming request every incoming request
  372. 16:43must pass through the security guard and
  373. 16:46if the rule allows it the request
  374. 16:49enters. If the rule blocks it
  375. 16:53then the request is rejected. Simple as
  376. 16:56that. What is security group? It is a
  377. 16:58stateful virtual firewall that operates
  378. 17:00on the AC2 instance level. Stateful
  379. 17:03means when you allow inbound traffic on
  380. 17:05a port the response traffic is
  381. 17:07automatically allowed outbound. No
  382. 17:09separate rule needed. So we need to
  383. 17:11understand what this inbound traffic
  384. 17:13means and what do these outbound traffic
  385. 17:16means. Okay. So let's start with
  386. 17:19inbound. Inbound traffic means the
  387. 17:23traffic coming into your EC2 instance.
  388. 17:27For example, a user is opening your
  389. 17:29website, an administrator connecting
  390. 17:32through SSH or an application sending
  391. 17:35request to a servers. These are all
  392. 17:37inbound connections. Here's an important
  393. 17:40fact. By default, AWS blocks all those
  394. 17:45requests. Okay? By default, AWS blocks
  395. 17:50all the inbound traffic, everything.
  396. 17:53Nothing can enter only to explicitly
  397. 17:55allow it. This is the security first
  398. 17:57design. AWS assumes block everything
  399. 18:00unless the customer says otherwise. And
  400. 18:02that's a good thing. Now let's
  401. 18:04understand about outbound traffic.
  402. 18:07Traffic leaving your EC2 instance. Let's
  403. 18:09say this is my EC2 instance and the
  404. 18:11traffic that leaves my EC2 instance is
  405. 18:13an outbound traffic. For example, your
  406. 18:16server is downloading updates
  407. 18:19that is uh outbound traffic. Let's say
  408. 18:22your application is calling another API
  409. 18:24or your server is accessing AWS
  410. 18:26services. These are all examples of
  411. 18:30outbound traffic and by default all
  412. 18:33outbound traffic is allowed. This means
  413. 18:34your EC2 instance can communicate
  414. 18:36outward without any additional
  415. 18:38configuration.
  416. 18:40Now let's understand the rule
  417. 18:41components. Every security group rule
  418. 18:44contain three important component that
  419. 18:47is protocol, port range, source. Don't
  420. 18:51worry, we will see this all in the AWS
  421. 18:53console. You will understand it more
  422. 18:55better. Let's break them down. What is
  423. 18:57protocol? What is port range? And what
  424. 18:59is source? Protocol tells AWS what type
  425. 19:02of traffic we are talking about. That
  426. 19:05may be TCP, UDP, ICMP. For the cloud
  427. 19:08practitioner, you will mostly see TCP.
  428. 19:11We will see about it.
  429. 19:13Port means port identify services.
  430. 19:17Some common examples like let's say I
  431. 19:20have port 22. Port 22 is for SSH. Port
  432. 19:25S80. Port 80 is for HTTP. Port 443
  433. 19:30HTTPS. talking about port 3306 that is
  434. 19:34for MySQL or port uh I guess 5432
  435. 19:41as I remember that is for postgSQL
  436. 19:45remember port services are like doors
  437. 19:48different services listen on different
  438. 19:50doors now it's time for source who is
  439. 19:53allowed it to connect
  440. 19:56examples my IP a C block another
  441. 20:00security groups
  442. 20:02This actually gives us the fine grained
  443. 20:04control. Let's imagine you are launching
  444. 20:07a web server. Which ports do you need?
  445. 20:11HTTP that is port 80. HTTPS I'm writing
  446. 20:16S that is port 443.
  447. 20:20Yes. And if you need an administration
  448. 20:23access then we need an SSH as well. We
  449. 20:28will see about SSH in the further part
  450. 20:30of the video. But for SSH, we need port
  451. 20:3422 that is used for administrator
  452. 20:37access. Now, here's the best practice.
  453. 20:40Port 22 should not be open to everyone.
  454. 20:43Instead, allow SSH only from your own IP
  455. 20:46address. So, this will dramatically
  456. 20:49reduce security risks. Now, let's talk
  457. 20:51about a word AWS loves to test that is
  458. 20:55stateful. Stateful means suppose a user
  459. 21:00sends HTTP HTTP request to your server.
  460. 21:05AWS allows that request because port 80
  461. 21:07is open.
  462. 21:09When your server sends the response
  463. 21:11back, AWS automatically allows it. You
  464. 21:13don't you do not need a separate
  465. 21:15outbound rule. The response is
  466. 21:17automatically permitted. That's what
  467. 21:19stateful means. And AWS exams this
  468. 21:21constantly. Remember security groups
  469. 21:23equal to stateful. a stateful virtual
  470. 21:27firewall that operates on the EC2
  471. 21:29instance level. So there's a quick
  472. 21:31question for you. Are the security
  473. 21:34groups stateful or stateless? Stateful.
  474. 21:37What is the default inbound behavior? By
  475. 21:40default, all the inbound traffic is
  476. 21:42blocked and all outbound traffic is
  477. 21:44allowed. Okay. So now let's actually see
  478. 21:47security groups in action. Theory part
  479. 21:49is done. Now we will see where are these
  480. 21:51located? What is this security group?
  481. 21:53how like we are controlling the inbound
  482. 21:55traffic, outbound traffic, how we are
  483. 21:56setting this up, all these things. Let
  484. 21:59us go to the console. As I'm in the
  485. 22:01dashboard, let's take a look at real
  486. 22:04security groups. You will find this um
  487. 22:07security groups option over here. I will
  488. 22:11click on security groups and then you
  489. 22:13will find security groups like I do have
  490. 22:15two security groups one default and one
  491. 22:17is WordPress certified bit naming. So
  492. 22:20let me customize this one. This is my
  493. 22:22security groups that I am using. You can
  494. 22:25find three inbound rules over here that
  495. 22:28is SSH, HTTP, HTTPS. These are the rules
  496. 22:32I was using for my web application. So
  497. 22:35here you can see protocol, port range
  498. 22:38and source.
  499. 22:40Let me try adding a rule one inbound
  500. 22:43rule. I will click on add rule. I will
  501. 22:45click on SSH. This is how you create a
  502. 22:48rule. You can see port range that is 22
  503. 22:52is automatically selected. That is
  504. 22:53default for SSH. And now I will only
  505. 22:57allow that SSH. You can select the
  506. 23:00source as anywhere IPv4 or my IP only.
  507. 23:04What you want to do like you want to
  508. 23:06allow the connection to be uh done only
  509. 23:09through your PC only your IP. So what I
  510. 23:13will do is select on my IP. Okay. So my
  511. 23:16IP is selected and yes we are done. You
  512. 23:19can simply click on save rules and you
  513. 23:21are done. So this is how you customize
  514. 23:24the security groups. This is an easy way
  515. 23:28but I do have two security groups. So I
  516. 23:30don't need to SSH. What I will do is
  517. 23:33delete one. You can try adding HTTP. The
  518. 23:37port 80 will be automatically selected
  519. 23:38and yeah you need the source anywhere.
  520. 23:42So you might find there is an another
  521. 23:45rule that is HTTP and HTTP allows
  522. 23:48traffic from anywhere in the world that
  523. 23:50is 000000
  524. 23:52/ zero. That means this allows anyone on
  525. 23:54the internet to access our website.
  526. 23:56Notice how security groups are simply
  527. 23:58collection of allow rules. We don't
  528. 24:00create deny rules here. Only allow
  529. 24:03rules. This is an important exam fact.
  530. 24:04Security groups only allow rules only.
  531. 24:07You can find the outbound rules over
  532. 24:09here means which traffic to send out
  533. 24:13from the server. Now our server is
  534. 24:16secure but a server also needs storage.
  535. 24:20So that's where EBS comes in. Let us see
  536. 24:23what is EBS. Imagine you have a file
  537. 24:26saved on your laptop. Then you shut down
  538. 24:29your laptop. When you turn it back on
  539. 24:31tomorrow, what happens? The file is
  540. 24:33still there. Why? What is the reason
  541. 24:35behind that? because it is stored in
  542. 24:37hard drive. EC2 needs storage too.
  543. 24:40That's where EBS comes in. Think of EBS
  544. 24:44like an hard drive attached to your
  545. 24:47cloud server. Without storage, your
  546. 24:49server would have nowhere to keep the
  547. 24:51file. No operating system, no
  548. 24:53application, no data. Everything would
  549. 24:56disappear. Everything would disappear.
  550. 24:59EBS solves that problem. Here's one of
  551. 25:01the most tested EBS concepts.
  552. 25:04Data persistence. Data persist when the
  553. 25:07EC2 instance is stopped.
  554. 25:10Data is deleted by default when an
  555. 25:12instance is terminated unless configured
  556. 25:15otherwise.
  557. 25:16Okay. The data remains on the EBS volume
  558. 25:18if it is configured. This surprises many
  559. 25:21beginners because they think stopping
  560. 25:23the server deletes everything. It
  561. 25:25doesn't. Stopping an EC2 instance is
  562. 25:27like shutting down your laptop and your
  563. 25:29files remain. We have ABS volume types
  564. 25:32that is GP3, IO2, ST1, SC1. Let us see
  565. 25:36that AWS provides different volume types
  566. 25:39for different purpose. GP3 is the
  567. 25:42default choice for most and honestly
  568. 25:45it's the correct answer most of the
  569. 25:46time. General purpose SSD. It has
  570. 25:49balanced performance, balanced cost. It
  571. 25:51is suitable for web application
  572. 25:53development, testing, boot volumes. If
  573. 25:55you are unsure what to choose, choose
  574. 25:58GP3. Now IO2 that is block express.
  575. 26:03Now imagine a mission critical database
  576. 26:06Oracle SQL server or there might be
  577. 26:09enterprise workloads.
  578. 26:11These applications need extremely high
  579. 26:14performance. That's where IIO2 comes in.
  580. 26:17It has much higher IOPS input output per
  581. 26:20second, much higher reliability and much
  582. 26:23higher cost. Talking about SD1
  583. 26:27throughput optimized SDDD hard disk
  584. 26:30drive they are designed for large
  585. 26:32sequential workloads and examples
  586. 26:34include big data log processing map
  587. 26:37reduce or large file processing. The
  588. 26:39last one is SC1 cold SD. From the name
  589. 26:42itself it must be clear it is the
  590. 26:45cheapest EBS option and it is used for
  591. 26:48rarely access data. One important
  592. 26:50limitation is that SC1 cannot be used as
  593. 26:54boot volume. AWS likes asking that. So
  594. 26:57remember that. Another exam favorite EBS
  595. 27:01volumes are tied to single AZs and they
  596. 27:03cannot be directly attached to the EC2
  597. 27:05instance in a different availability
  598. 27:06zone. Let us take an example. Let's say
  599. 27:09if my volume exist here in Mumbai AZ.
  600. 27:13So it cannot be directly attached to the
  601. 27:15EC2 instance running in Mumbai AZ B.
  602. 27:19Remember that EBS is a aability zone
  603. 27:22specific. Which EBS volume type should
  604. 27:25most customer used? What you will
  605. 27:27choose? GP3. If asked, does EBS survive
  606. 27:32a stop operation? Yes. Can an EBS volume
  607. 27:35be directly attached across aability
  608. 27:37zones? No. Excellent. Now, let's take a
  609. 27:41look at EBS inside the AWS. So let me
  610. 27:44show you where do this volumes where do
  611. 27:47this elastic block store lives. You can
  612. 27:49find this in in the dashboard of EC2.
  613. 27:53You will find this volume option and you
  614. 27:55can create these volumes manually as
  615. 27:57well. Select the volume type. We have
  616. 27:59GP2, GP3. These are both for general
  617. 28:01purpose and IOPS SSD IO1 and IO2. You
  618. 28:05can select whatever you need. Let's see.
  619. 28:06I select the GP2 or GP3 whatever you
  620. 28:09can. You can define the size. How much
  621. 28:12do you want? What is the IO ops? You can
  622. 28:14define that through portut and in which
  623. 28:17avail which availability zone do you
  624. 28:19need that remember that um in if your
  625. 28:23server is in Mumbai AZ you need to uh
  626. 28:28put that uh volume in the in the same
  627. 28:30availability zone you can set up tags
  628. 28:33and you can simply click on create
  629. 28:35volume and your volume is created okay
  630. 28:39now we have reached the most exciting
  631. 28:41part of today's session up until now we
  632. 28:42have been discussing concept We have
  633. 28:44talked about EC2. We explored instance
  634. 28:46families. We learned pricing models. We
  635. 28:48have understood security groups. We have
  636. 28:50discussed EBS storage. Now it's time to
  637. 28:53put everything together. We are going to
  638. 28:55launch our real cloud server, not a
  639. 28:58simulation or a screenshot and actually
  640. 29:00C2 instance running inside AWS data
  641. 29:02center. So by the end of this lab, you
  642. 29:05will be clear and you will be having
  643. 29:07your own cloud server running on AWS.
  644. 29:10Just follow these steps. Once I'm in the
  645. 29:13AWS console, I will simply search for
  646. 29:15EC2 or I can find my EC2 over here. I
  647. 29:18will click on EC2 and here is my EC2
  648. 29:21dashboard.
  649. 29:22See in the EC2 dashboard you have uh a
  650. 29:26lot of options like instances,
  651. 29:27autoscaling groups, capacity
  652. 29:29reservations.
  653. 29:31Don't get overwhelmed by these all
  654. 29:33things. We will look we will see all
  655. 29:36these things in upcoming videos as well.
  656. 29:39Now what I will do you can select the
  657. 29:42region in which you want as I wanted
  658. 29:45that to be in Mumbai region. So I will
  659. 29:47select the Mumbai region and then click
  660. 29:49on launch instance. Always
  661. 29:53double check the reason because
  662. 29:55resources are created inside a specific
  663. 29:57region. So now name this instance
  664. 30:01SBG power. Okay, these names are not
  665. 30:05globally unique. So you can write
  666. 30:07anything. Now, here's an important
  667. 30:09point. Names don't affect functionality.
  668. 30:12AWS doesn't care whatever you call it.
  669. 30:14You call it production web server, you
  670. 30:16call it my first EC2, my EC2, his EC2,
  671. 30:19anything. The service behaves exactly
  672. 30:22the same. The names are for our
  673. 30:24recognization, for our understanding.
  674. 30:26Good naming makes the management easier.
  675. 30:28So, I suggest you to keep good names.
  676. 30:31Here I'm keeping SBG power because I
  677. 30:33know this is for SBG uh training purpose
  678. 30:36only. Why do we need names? Imagine if
  679. 30:39you are managing 500 servers
  680. 30:42then proper naming becomes extremely
  681. 30:44important. Now, now what you do uh in
  682. 30:47the application and OS images, select an
  683. 30:49image what you need. You can select Mac
  684. 30:51OS, Ubuntu, Windows, whatever you need.
  685. 30:53Let me select Amazon Linux for now. And
  686. 30:56you can check whether it is free tier
  687. 30:59eligible or not in the AMI. So what is
  688. 31:02this AMI? AMI stands for Amazon machine
  689. 31:05image. Think of AMI as a template.
  690. 31:07Whenever you install Windows on a
  691. 31:09laptop, you start with an installation
  692. 31:11image. And AMI serves the similar
  693. 31:13purpose. So I will select this one only.
  694. 31:17This is the AWS own Linux distribution.
  695. 31:19It's optimized for AWS workloads. Notice
  696. 31:22the free tier eligible badge and that's
  697. 31:24exactly what we are want for learning.
  698. 31:26Select Amazon Linux 2023 and choose the
  699. 31:28instance type.
  700. 31:30You can select any instant type based on
  701. 31:33your need. But we will select the free
  702. 31:35tier eligible only. So let us go with
  703. 31:38the T3 micro that is for general
  704. 31:41purpose.
  705. 31:42You can see the pricing over here. How
  706. 31:44much does it charges? Now we choose our
  707. 31:46hardware. This is where our earlier
  708. 31:48lesson on instance families become
  709. 31:50useful. Let's select T2 micro. I don't
  710. 31:52have T2 micro. Okay. Let's select T3
  711. 31:54micro.
  712. 31:56So which family does it belong to?
  713. 31:58General purpose. Yes. It has balanced
  714. 32:01CPU, balanced memory. It is perfect for
  715. 32:03learning purpose and also small
  716. 32:05applications. Notice the free tier
  717. 32:08eligible badge for the beginner. This is
  718. 32:10usually the right choice. Now we are
  719. 32:12going to create something extremely
  720. 32:14important that is key pair. Think of
  721. 32:17this as a key to a cloud server. Without
  722. 32:19this key accessing the server becomes
  723. 32:20much more difficult. So what I will do
  724. 32:23is click on create a new key pair. And
  725. 32:26you can name it anything. Let me name
  726. 32:28it. Let me name it my SBG key. Select
  727. 32:35the type RSA and format as PEM. Now
  728. 32:40click on create key. Notice AWS
  729. 32:43automatically downloads the key for you
  730. 32:45and AWS will never show it again. Treat
  731. 32:48this file exactly like the key to your
  732. 32:50house. Never upload it to GitHub, never
  733. 32:51email it and never share it publicly and
  734. 32:54absolutely never show it contents in the
  735. 32:57screen. Store it safely. We will need it
  736. 33:00whenever we want secure access to our
  737. 33:02server.
  738. 33:03So now let's configure the network
  739. 33:07security. Uh remember our house analogy.
  740. 33:10This is where we decide which doors are
  741. 33:12open. Now what you can do here you can
  742. 33:15select create security group and you can
  743. 33:19select what you want to allow allow SSH
  744. 33:21traffic from anywhere from my IP only or
  745. 33:24what SSS allows administrator to connect
  746. 33:27to the Linux server and AWS
  747. 33:30automatically selects port 22 for this
  748. 33:32you can select the existing security
  749. 33:34groups as well if you have those I will
  750. 33:37click I will create and select my IP
  751. 33:41will allow HTTPS traffic And I will
  752. 33:43allow HTTP traffic as well. Why do we
  753. 33:46need this? Because if we why we need
  754. 33:49this? If we eventually host a website,
  755. 33:52we want everyone to access it. This is
  756. 33:54the common web server configuration. Now
  757. 33:57our security group is also ready. You
  758. 33:59can configure how much storage do you
  759. 34:01want and what type of file system do you
  760. 34:04want to choose. For now what I will do I
  761. 34:08will just keep that as it is and click
  762. 34:12on launch instance. AWS is now
  763. 34:14provisioning a virtual server for us
  764. 34:16inside a data center. You can see
  765. 34:18successfully initiated launch of
  766. 34:20instance.
  767. 34:22I when I whenever I click on this you
  768. 34:24can see my instances is in the running
  769. 34:26state. Okay. Now what I can do is click
  770. 34:28on instance ID and now we are taken to
  771. 34:31the EC2 instance page. Observe the state
  772. 34:35instance state it is running. Okay. If
  773. 34:38it is showing pending for you that means
  774. 34:40EC2 is creating the server for you. You
  775. 34:43will see after a time after a short time
  776. 34:46in a minute or two you will find this as
  777. 34:49in a running state. Your first EC2
  778. 34:52instance is now running. Now comes the
  779. 34:54fun part. Let's actually connect to the
  780. 34:55server. There are various method to
  781. 34:58connect to the server. Uh the first one
  782. 35:00the one you can use is click on connect
  783. 35:03and here I do have EC2 instance connect
  784. 35:06SSM session manager SSH client EC2
  785. 35:08serial console. What I will do? Click on
  786. 35:11EC2 instance connect. I will select it
  787. 35:14is it has default public connect using
  788. 35:16public IP and yes connect. You might see
  789. 35:20an error. Okay. Yes. So we will see what
  790. 35:23is this error. When you will see this in
  791. 35:26the security option,
  792. 35:28we have inbound rule set up as you can
  793. 35:31see what was this rule. This was SSH
  794. 35:33access. We have set this as our IP. What
  795. 35:37do this means? See um the reason your
  796. 35:40connection is denied is that the browser
  797. 35:43based EC2 instance connect does not
  798. 35:45route traffic through your personal IP
  799. 35:47address. Instead, what it does is AWS
  800. 35:50uses uses its own regional IP to bridge
  801. 35:52the connection from your browser to your
  802. 35:55virtual machine because your current
  803. 35:58security group setup allows only
  804. 36:00explicit local IP, your personal IP. So,
  805. 36:03AWS blocks its own connection
  806. 36:04infrastructure. So, we need to set up
  807. 36:06that we need to find uh our
  808. 36:10regional IP. You can search it on
  809. 36:13Google. Okay. Once we are once we have
  810. 36:16got that for AP south one for Asia
  811. 36:20Pacific region for Mumbai AP south one
  812. 36:23my IP is this one. So what I will do is
  813. 36:26edit inbound rules
  814. 36:28and then
  815. 36:32let me put it like this C block. You can
  816. 36:36add one more rule that is SSH that
  817. 36:39allows traffic from your IP as well.
  818. 36:42Okay, we can click on save and you're
  819. 36:44done. Now let us try to connect to EC2
  820. 36:47instance again. I will go to instances
  821. 36:50and then select this one and click on
  822. 36:53connect
  823. 36:55and connect. Congratulation. Now you
  824. 36:58have connected to your first EC2
  825. 37:00instance. Take a moment. A few minutes
  826. 37:03ago we had nothing. Now we are connected
  827. 37:05to a real Linux server inside AWS. This
  828. 37:08is a major milestone in your cloud
  829. 37:10journey. So let me run an command that
  830. 37:13is who am I? EC2 user. It tells the
  831. 37:17current user and now host name. So this
  832. 37:22displays your server host name. Every
  833. 37:24Linux machine has a host name. Think of
  834. 37:26it as a machine's identity. You can also
  835. 37:29check how much memory do you have.
  836. 37:32Notice the RAM available to our
  837. 37:34instance. Remember our discussion about
  838. 37:36instance families. Different instance
  839. 37:39type provide different amount of CPU and
  840. 37:41memory. So you can find this over here.
  841. 37:45You can also check okay DFH. Okay, it is
  842. 37:49DFH.
  843. 37:50And notice the volume attached to the
  844. 37:52instance. This is our EBS volume. The
  845. 37:55storage we discussed earlier is now
  846. 37:56visible inside the Linux. This is where
  847. 37:58our files live. Now let's update our
  848. 38:00software packages. This is similar to
  849. 38:02installing updates on our Windows. What
  850. 38:05I will do is write sudo dnf
  851. 38:09update
  852. 38:11space dash y. So what it will do is it
  853. 38:15will keep it will install updates on our
  854. 38:18system. So because keeping system
  855. 38:21updated is an important security best
  856. 38:23practice. So this may take a minute.
  857. 38:25While it runs, remember that managing
  858. 38:28the operating system is our
  859. 38:30responsibility
  860. 38:31because EC2 follows the shared
  861. 38:34responsibility model. As you can see,
  862. 38:36Amazon Linux 2023 kernel live patch
  863. 38:39repository. Nothing to do complete.
  864. 38:41Okay, I was thinking should I show you
  865. 38:43how you can set up your own web server
  866. 38:46today by installing Apache on that
  867. 38:49because Apache is one of the most
  868. 38:50popular web servers. We will do that web
  869. 38:54server part in our next video. Now what
  870. 38:56I will do is close this one. Before you
  871. 38:59close this AWS console, what I want you
  872. 39:02to do is stop the machine. You can even
  873. 39:06delete or terminate instance so that it
  874. 39:08doesn't cost you. So what I will do is
  875. 39:11for now I will just click on stop this
  876. 39:14machine and click on stop.
  877. 39:17Uh if I check in elastic block store you
  878. 39:20will find there is one volume
  879. 39:22automatically attached to my EC2
  880. 39:25instance. You can check this is my EC2
  881. 39:28instance attach resources status. Got
  882. 39:30it? Before we finish today here is an
  883. 39:33important thing you need to remember.
  884. 39:34Whenever I click on stop button it
  885. 39:37doesn't terminate. And when I click on
  886. 39:40delete terminate what it will do? It
  887. 39:43will completely delete. That means stop
  888. 39:46means just turning off your server. That
  889. 39:49is your data remains, your EBS volume
  890. 39:51remains, your operating system remains
  891. 39:53as it is. But the termination is
  892. 39:55different. Termination permanently
  893. 39:58deletes the instance. AWS asks this
  894. 40:00frequently in certification exam.
  895. 40:01Remember stop is equal to pause and
  896. 40:05terminate is equal to delete. Also
  897. 40:08remember while stopped compute charges
  898. 40:10stopped. storage charges for EBS may
  899. 40:13continue. That's why we always stop lab
  900. 40:16instances when we are done.
  901. 40:18Congratulation, you have successfully
  902. 40:20launched and connected and managed your
  903. 40:22first EC2 instance. Now you're
  904. 40:23officially working with the cloud. As of
  905. 40:26the summary, so today was a huge
  906. 40:28milestone in our AWS journey. Let's take
  907. 40:30a moment and appreciate what we have
  908. 40:32accomplished
  909. 40:34this morning. Many of you may have never
  910. 40:36launched a cloud server before. Now we
  911. 40:38have launched a real EC2 instance
  912. 40:40connected to Linux explored storage
  913. 40:42configured networking also created a
  914. 40:44security groups that's a real cloud
  915. 40:47infrastructure not theory not simulation
  916. 40:49these are actual AWS server running
  917. 40:52inside AWS data center let us quickly
  918. 40:54review what we have learned today um we
  919. 40:57have completed instance families we have
  920. 40:59learned about what are the pricing
  921. 41:00models what are the security groups EBS
  922. 41:03storage so what I want you to do is
  923. 41:06practice some questions on EC2 that are
  924. 41:09provided in the notes itself. So do it
  925. 41:12and tomorrow we will learn how modern
  926. 41:15cloud application move beyond
  927. 41:16traditional servers. We will explore
  928. 41:18AWS, Lambda, ECS, EKS and Far Grate and
  929. 41:24containers as well and serverless
  930. 41:25computing. You will discover why many
  931. 41:28organization today don't even manage
  932. 41:30server directly anymore. It is one of
  933. 41:32the most exciting topics in the AWS
  934. 41:34ecosystem. So fantastic work today
  935. 41:36everyone. You launched your first EC2
  936. 41:38instance, connected everything. Today
  937. 41:40was the major achievement. Keep
  938. 41:42practicing, keep building and most
  939. 41:44importantly stay curious. Thank you for
  940. 41:47joining day eight of our AWS builder
  941. 41:49challenge. I will see you tomorrow on
  942. 41:51day 9. Take care and happy

About this transcript

This page contains the full transcript of Amazon EC2 Explained | Instance Types, Pricing & Security Groups | AWS CLF-C02 Day 8 by Pawan Joshi, generated from the public captions YouTube serves with the video. The transcript has 6,155 words across 942 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.