Start here
What you will build, what it costs, and what to prepare before you touch the console.
About 10 min · Verified 8 October 2026
By the end of this guide you will have ShortLink running in your own AWS account: a React website on S3, a Node.js API on a private EC2 instance behind a load balancer, and a private PostgreSQL database on RDS. You will create every resource by hand in the console so you understand what each one is for.
What you will build#
| Piece | AWS service | What it does |
|---|---|---|
| Website | S3 static website hosting | Serves the built React app over HTTP |
| API | EC2 (Ubuntu, Node.js) in a private subnet | Runs the Express API as a systemd service |
| Entry point | Application Load Balancer | Receives public HTTP traffic and forwards it to the API on port 3000 |
| Database | RDS PostgreSQL in private subnets | Stores links, clicks and collections |
| Network | VPC, subnets, NAT gateway, S3 endpoint | Keeps the API and database off the public internet |
| Access | IAM role + Systems Manager Session Manager | Shell access without SSH keys or open port 22 |
Time and cost#
- Time: about 2 to 3 hours the first time. The slow parts are waiting: RDS takes 5 to 10 minutes, the NAT gateway and load balancer 2 to 3 minutes each.
- Cost: while everything runs, expect roughly US$3 per day (estimate; prices vary by Region and change). The NAT gateway, the load balancer and the database make up most of it. Nothing here is free-tier-only.
- Stop the meter: when you finish, follow the Clean up chapter. Deleting the NAT gateway and the load balancer alone cuts the bill by more than half.
Before you begin#
Tick these off. The boxes remember your answers in this browser.
How do I check that the AWS CLI is signed in?
aws sts get-caller-identityYou should get JSON with Account, UserId and Arn. If you get Unable to locate credentials, sign in with aws login, aws configure sso or aws configure, whichever your organisation uses, then try again. Copy the Account value into My values at the top of this page.
How these guides work#
- Commands are tagged with where to run them: Your computer a terminal on your laptop, On the EC2 instance a Session Manager shell, or Paste in the AWS console a JSON policy for the console editor.
- Highlighted text such as
<AWS_ACCOUNT_ID>is a placeholder. Click My values in the header, fill in what you know, and every command on the site updates. The Copy button copies your real values. - Console paths look like VPCYour VPCsCreate VPC. Search the console for the first word if you cannot find it.
- After each important step there is a You should see box. If you do not see it, stop and fix it before moving on. Problems compound.
Names used everywhere#
Use these names exactly. Later chapters (and the CI/CD guides) refer to them in IAM policies, deployment groups and pipelines.
| Resource | Name |
|---|---|
| VPC | shortlink-vpc |
| Security groups | shortlink-alb-sg, shortlink-api-sg, shortlink-db-sg |
| DB subnet group | shortlink-db-subnets |
| RDS instance / database | shortlink-db / shortlink |
| IAM role for EC2 | shortlink-ec2-role |
| Target group / load balancer | shortlink-app-tg / shortlink-alb |
EC2 instance (Name tag) | shortlink-api |
| Website bucket | <WEB_BUCKET> (must be globally unique) |
| systemd service / env file | shortlink-api / /etc/shortlink/shortlink.env |
Next: fork the repository.
Found a mistake? Edit this page on GitHub.