launching-ec2-instance-with-best-practices

oleh aws

Launches an EC2 instance with secure, cost-efficient defaults including AMI selection, burstable instance sizing, least-privilege IAM roles, hardened security…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill launching-ec2-instance-with-best-practices

Launching EC2 Instances with Best Practices

Overview

Domain expertise for launching EC2 instances with sensible defaults optimized for security, cost-efficiency, and operational best practices. Covers AMI selection, instance type recommendation, network configuration, IAM role creation, security group hardening, storage configuration, tagging strategy, and post-launch verification.

Launch an EC2 instance

To launch a fully configured EC2 instance with best-practice defaults, follow the procedure exactly. See EC2 instance launch procedure.

The procedure handles:

  • Intelligent defaults based on workload type and environment
  • Network validation (VPC, subnet, public/private placement)
  • AMI selection with architecture compatibility checks
  • Least-privilege IAM roles for required AWS service access
  • Hardened security groups with minimal port exposure
  • Encrypted gp3 storage with environment-appropriate retention
  • Comprehensive tagging for cost tracking and organization
  • Post-launch verification and connection instructions

Troubleshooting

Insufficient instance capacity

Try a different availability zone or instance type (e.g., t3a instead of t3). See the full troubleshooting guide in the launch procedure.

Instance immediately terminates

Check console output with aws ec2 get-console-output. Verify EBS volume size is sufficient and AMI is compatible with the instance type.

Cannot connect via SSH

Verify the security group allows SSH from your IP, key file permissions are 400, and the instance is running. Consider AWS Systems Manager Session Manager as an alternative.

Lebih banyak skill dari aws

agents-build
aws
Digunakan untuk memperluas proyek agen yang ada dengan memori, integrasi aplikasi, VPC, multi-agen, migrasi, model, browser, interpreter kode, pembayaran, atau sumber daya…
official
agents-connect
aws
Gunakan saat menghubungkan agen Anda ke API, alat, atau layanan eksternal melalui Gateway, atau membatasi akses alat dengan kebijakan Cedar. Menangani penyiapan gateway, target…
official
agents-debug
aws
Use when your agent or environment is broken — wrong answers, errors, timeouts, tool failures, or CLI issues. Reads traces and logs to diagnose root causes.…
official
agents-deploy
aws
Gunakan saat men-deploy agen Anda ke AWS, atau saat deploy gagal. Menangani validasi pra-penerbangan, diagnosis error CDK/IAM/kuota, manajemen versi, rollback,…
official
agents-get-started
aws
Gunakan saat pengembang ingin membuat proyek agen baru atau memulai dengan AgentCore. Menangani pemilihan framework, pembuatan kerangka proyek, deploy pertama, dan…
official
agents-harden
aws
Gunakan saat menyiapkan agen Anda untuk produksi — pembatasan IAM, autentikasi masuk (JWT, SigV4), manajemen rahasia, optimasi cold start, siklus hidup sesi, tingkat…
official
agents-pay
aws
Gunakan saat agent ini perlu membayar konten yang dilindungi x402 saat runtime: menemui paywall di tengah tugas, menyelesaikannya melalui AgentCore Payments, dan menerapkan…
official
amazon-aurora-mysql
aws
Amazon Aurora MySQL — membuat, memodifikasi, dan memberikan saran pada klaster Aurora MySQL secara khusus (mesin yang kompatibel dengan MySQL, Aurora serverless, parallel query).…
official