Skip to content

Start here

What you will build, what it costs, and what to prepare before you touch the console.

About 10 min · Verified 8 October 2026

By the end of this guide you will have ShortLink running in your own AWS account: a React website on S3, a Node.js API on a private EC2 instance behind a load balancer, and a private PostgreSQL database on RDS. You will create every resource by hand in the console so you understand what each one is for.

What you will build#

Browseryour usersS3 static websiteReact app · HTTP1 open the siteVPC 10.0.0.0/16IGW2 API callsPublic subnets · 10.0.1.0/24 and 10.0.2.0/24Application Load BalancerHTTP :80NAT gatewayoutbound internet onlyPrivate subnets · 10.0.11.0/24 and 10.0.12.0/24EC2 · Node.js APIport 3000 · no public IPRDS PostgreSQLport 5432 · not publicS3 gatewayendpoint3 forward :30004apt / npm / SSM (outbound)CI/CD artifacts via S3 endpoint
Browsers load the static site from S3 and call the API through the public load balancer. The API server and database live in private subnets with no public IP.
PieceAWS serviceWhat it does
WebsiteS3 static website hostingServes the built React app over HTTP
APIEC2 (Ubuntu, Node.js) in a private subnetRuns the Express API as a systemd service
Entry pointApplication Load BalancerReceives public HTTP traffic and forwards it to the API on port 3000
DatabaseRDS PostgreSQL in private subnetsStores links, clicks and collections
NetworkVPC, subnets, NAT gateway, S3 endpointKeeps the API and database off the public internet
AccessIAM role + Systems Manager Session ManagerShell access without SSH keys or open port 22

Time and cost#

  • Time: about 2 to 3 hours the first time. The slow parts are waiting: RDS takes 5 to 10 minutes, the NAT gateway and load balancer 2 to 3 minutes each.
  • Cost: while everything runs, expect roughly US$3 per day (estimate; prices vary by Region and change). The NAT gateway, the load balancer and the database make up most of it. Nothing here is free-tier-only.
  • Stop the meter: when you finish, follow the Clean up chapter. Deleting the NAT gateway and the load balancer alone cuts the bill by more than half.

Before you begin#

Tick these off. The boxes remember your answers in this browser.

How do I check that the AWS CLI is signed in?
Your computerCheck your AWS CLI identity
aws sts get-caller-identity

You should get JSON with Account, UserId and Arn. If you get Unable to locate credentials, sign in with aws login, aws configure sso or aws configure, whichever your organisation uses, then try again. Copy the Account value into My values at the top of this page.

How these guides work#

  • Commands are tagged with where to run them: Your computer a terminal on your laptop, On the EC2 instance a Session Manager shell, or Paste in the AWS console a JSON policy for the console editor.
  • Highlighted text such as <AWS_ACCOUNT_ID> is a placeholder. Click My values in the header, fill in what you know, and every command on the site updates. The Copy button copies your real values.
  • Console paths look like VPCYour VPCsCreate VPC. Search the console for the first word if you cannot find it.
  • After each important step there is a You should see box. If you do not see it, stop and fix it before moving on. Problems compound.

Names used everywhere#

Use these names exactly. Later chapters (and the CI/CD guides) refer to them in IAM policies, deployment groups and pipelines.

ResourceName
VPCshortlink-vpc
Security groupsshortlink-alb-sg, shortlink-api-sg, shortlink-db-sg
DB subnet groupshortlink-db-subnets
RDS instance / databaseshortlink-db / shortlink
IAM role for EC2shortlink-ec2-role
Target group / load balancershortlink-app-tg / shortlink-alb
EC2 instance (Name tag)shortlink-api
Website bucket<WEB_BUCKET> (must be globally unique)
systemd service / env fileshortlink-api / /etc/shortlink/shortlink.env

Next: fork the repository.

Found a mistake? Edit this page on GitHub.