Launch the API server
An Ubuntu EC2 instance in a private subnet with no public IP, reachable with Session Manager.
About 20 min · Verified 8 October 2026
On this page
- Launch the instance
- Open the launch wizard and name it
- Image and size
- Network settings
- Storage and advanced details
- Wait for it to be ready
- Prove you can reach it with Session Manager
- Check that Systems Manager sees the instance
- Open a session in the console
- Register it with the load balancer
- Add the instance to the target group
Now the server that will run the API. It goes in a private subnet with no public IP address, uses the security group shortlink-api-sg, and carries the role shortlink-ec2-role.
Launch the instance#
Open the launch wizard and name it#
Open EC2InstancesLaunch instances.
| Field | Value |
|---|---|
| Name | shortlink-api |
Image and size#
| Field | Value |
|---|---|
| Application and OS Images | Ubuntu → Ubuntu Server 24.04 LTS (HVM), SSD Volume Type |
| Architecture | 64-bit (x86) |
| Instance type | t3.micro |
| Key pair | Proceed without a key pair |
No key pair is correct: you will connect with Session Manager, not SSH.
Network settings#
Choose Edit next to Network settings.
| Field | Value |
|---|---|
| VPC | shortlink-vpc |
| Subnet | the private subnet 10.0.11.0/24 in ap-south-1a |
| Auto-assign public IP | Disable |
| Firewall (security groups) | Select existing security group → shortlink-api-sg |
Storage and advanced details#
Leave storage at the default 8 GiB gp3.
Expand Advanced details and set:
| Field | Value |
|---|---|
| IAM instance profile | shortlink-ec2-role |
| Metadata version | V2 only (token required) |
| Metadata response hop limit | 2 (so containers and tools can reach metadata later; harmless here) |
Leave everything else at the default and choose Launch instance.
Wait for it to be ready#
Open EC2Instances. Wait until Instance state is Running and Status check is 2/2 checks passed (2 to 4 minutes). Copy the Instance ID (i-…) into My values → API instance ID.
-), and the Private IPv4 is in 10.0.11.x.Prove you can reach it with Session Manager#
Check that Systems Manager sees the instance#
aws ssm describe-instance-information --region ap-south-1 \
--query 'InstanceInformationList[].{id:InstanceId,ping:PingStatus,os:PlatformName}' --output tableping: Online. It can take 3 to 5 minutes after launch.Open a session in the console#
Select the instance → Connect → Session Manager tab → Connect. A browser terminal opens.
whoami
hostname -Iwhoami prints ssm-user. You are not ubuntu, so commands that need privileges use sudo.
The Session Manager tab is greyed out, or the node never appears
Work through these in order:
- Role attached? EC2InstanceSecurity tab shows IAM Role
shortlink-ec2-role. If not: ActionsSecurityModify IAM role. - Outbound path? A private instance reaches Systems Manager through the NAT gateway. Confirm the NAT gateway is Available and both private route tables have
0.0.0.0/0 → nat-…. - Security group outbound?
shortlink-api-sgmust allow outbound HTTPS. The default (all traffic out) does. - Just wait. The agent registers a few minutes after boot. Reboot the instance if 10 minutes pass: Instance stateReboot instance.
Register it with the load balancer#
Add the instance to the target group#
Open EC2Target Groupsshortlink-app-tgTargetsRegister targets.
- Tick your
shortlink-apiinstance. - Ports for the selected instances:
3000. - Choose Include as pending below, then Register pending targets.
Next: install and start the API.
Found a mistake? Edit this page on GitHub.