Skip to content

Launch the API server

An Ubuntu EC2 instance in a private subnet with no public IP, reachable with Session Manager.

About 20 min · Verified 8 October 2026

0 of 8 steps done0%

Now the server that will run the API. It goes in a private subnet with no public IP address, uses the security group shortlink-api-sg, and carries the role shortlink-ec2-role.

Launch the instance#

Open the launch wizard and name it#

Open EC2InstancesLaunch instances.

FieldValue
Nameshortlink-api

Image and size#

FieldValue
Application and OS ImagesUbuntu → Ubuntu Server 24.04 LTS (HVM), SSD Volume Type
Architecture64-bit (x86)
Instance typet3.micro
Key pairProceed without a key pair

No key pair is correct: you will connect with Session Manager, not SSH.

Network settings#

Choose Edit next to Network settings.

FieldValue
VPCshortlink-vpc
Subnetthe private subnet 10.0.11.0/24 in ap-south-1a
Auto-assign public IPDisable
Firewall (security groups)Select existing security group → shortlink-api-sg

Storage and advanced details#

Leave storage at the default 8 GiB gp3.

Expand Advanced details and set:

FieldValue
IAM instance profileshortlink-ec2-role
Metadata versionV2 only (token required)
Metadata response hop limit2 (so containers and tools can reach metadata later; harmless here)

Leave everything else at the default and choose Launch instance.

Wait for it to be ready#

Open EC2Instances. Wait until Instance state is Running and Status check is 2/2 checks passed (2 to 4 minutes). Copy the Instance ID (i-…) into My values → API instance ID.

You should see
Running, 2/2 checks passed, Public IPv4 address is empty (-), and the Private IPv4 is in 10.0.11.x.

Prove you can reach it with Session Manager#

Check that Systems Manager sees the instance#

Your computerIs the instance a managed node?
aws ssm describe-instance-information --region ap-south-1 \
  --query 'InstanceInformationList[].{id:InstanceId,ping:PingStatus,os:PlatformName}' --output table
You should see
A row with your instance ID and ping: Online. It can take 3 to 5 minutes after launch.

Open a session in the console#

Select the instance → Connect → Session Manager tab → Connect. A browser terminal opens.

On the EC2 instanceFirst command in the session
whoami
hostname -I

whoami prints ssm-user. You are not ubuntu, so commands that need privileges use sudo.

The Session Manager tab is greyed out, or the node never appears

Work through these in order:

  1. Role attached? EC2InstanceSecurity tab shows IAM Role shortlink-ec2-role. If not: ActionsSecurityModify IAM role.
  2. Outbound path? A private instance reaches Systems Manager through the NAT gateway. Confirm the NAT gateway is Available and both private route tables have 0.0.0.0/0 → nat-….
  3. Security group outbound? shortlink-api-sg must allow outbound HTTPS. The default (all traffic out) does.
  4. Just wait. The agent registers a few minutes after boot. Reboot the instance if 10 minutes pass: Instance stateReboot instance.

Register it with the load balancer#

Add the instance to the target group#

Open EC2Target Groupsshortlink-app-tgTargetsRegister targets.

  1. Tick your shortlink-api instance.
  2. Ports for the selected instances: 3000.
  3. Choose Include as pending below, then Register pending targets.
You should see
The target shows Unhealthy with a reason like Request timed out or Connection refused. That is expected: nothing listens on port 3000 yet. The next chapter makes it healthy.

Next: install and start the API.

Found a mistake? Edit this page on GitHub.