· 10 years ago · Apr 11, 2016, 11:03 AM
1# Install awscli
2```sh
3sudo -H pip install awscli --ignore-installed six
4```
5> Collecting awscli [..]
6
7> Installing collected packages: pyasn1, rsa, futures, jmespath, six, python-dateutil, docutils, botocore, s3transfer, colorama, awscli
8> Successfully installed awscli-1.10.19 botocore-1.4.10 colorama-0.3.3 docutils-0.12 futures-3.0.5 jmespath-0.9.0 pyasn1-0.1.9 python-dateutil-1.5 rsa-3.3 s3transfer-0.0.1 six-1.4.1
9
10```sh
11aws configure
12```
13
14```
15AWS Access Key ID [None]: ***
16AWS Secret Access Key [None]: ******
17Default region name [None]: **-****-1
18Default output format [None]: table
19```
20
21
22====
23
24# EC2 creation
25## Create your first keypair
26```sh
27aws ec2 create-key-pair --key-name MyKey --query 'KeyMaterial' --output text > ~/.ssh/mykey.pem
28chmod 400 ~/.ssh/mykey.pem
29```
30
31## Create a new Security group for Web access
32```sh
33aws ec2 create-security-group --group-name fw-kbit-web --description "Default kbit.io Firewall"
34```
35
36### Apply new rules
37```sh
38aws ec2 authorize-security-group-ingress --group-name fw-kbit-web --protocol tcp --port 80 --cidr 0.0.0.0/0
39aws ec2 authorize-security-group-ingress --group-name fw-kbit-web --protocol tcp --port 22 --cidr 0.0.0.0/0
40```
41
42## Create your instance
43* Ubuntu: ami-0fb83963
44* Free-tier Instance: t2.micro
45
46```sh
47aws ec2 run-instances --image-id ami-0fb83963 --count 1 --instance-type t2.micro --key-name MyKey --security-groups fw-kbit-web
48```
49
50### Save important information from the output
51| KEY | VALUE |
52| ------ | ------ |
53| InstanceId | i-0ffac8ea9f6ea0619 |
54| InstanceType | t2.micro |
55
56### NetworkInterface
57* Description
58* MacAddress
59* NetworkInterfaceId
60* OwnerId
61* PrivateDnsName
62* PrivateIpAddress
63* SourceDestCheck
64* Status
65* SubnetId
66* VpcId
67
68## Attach a bigger partition for future usage
69```sh
70aws ec2 create-volume --size 20 --region sa-east-1 --availability-zone sa-east-1a --volume-type gp2
71```
72
73### Use the volumeId to attach it to the right Instance
74```sh
75aws ec2 attach-volume --volume-id vol-5b4f77fa --instance-id i-0ffac8ea9f6ea0619 --device /dev/sdf
76```
77
78## Allocate an ElasticIP
79```sh
80aws ec2 allocate-address --domain standard
81```
82
83## Associate it with your instance
84```sh
85aws ec2 associate-address --instance-id i-0ffac8ea9f6ea0619 --public-ip ##.###.##.##
86````
87
88## Be heroe!
89```sh
90ssh -i .ssh/mykey.pem ubuntu@##.###.##.##
91ubuntu@ip-###-##-##-###:~$
92```
93
94
95====
96
97# S3 Bucket
98## Create a bucket
99```sh
100aws s3api create-bucket --bucket bucketName --region sa-east-1
101```
102### If the bucket name already exists, you will receive an error like
103> A client error (BucketAlreadyExists) occurred when calling the CreateBucket operation: The requested bucket name is not available. The bucket namespace is shared by all users of the system. Please select a different name and try again.
104
105### So try again :)
106```sh
107aws s3api create-bucket --bucket randomNameToAvoidDuplicates --region sa-east-1
108```
109
110
111====
112
113# RDS MySQL Instance
114## Create your Security Group
115```sh
116aws ec2 create-security-group --group-name fw-kbit-db --description "Default kbit.io Firewall DB"
117```
118## Allow your instance to connect to the DB node
119### Change `internalIP` for your Private ElasticIP
120```sh
121aws ec2 authorize-security-group-ingress --group-name fw-kbit-db --protocol tcp --port 3306 --cidr ##internalIP##
122```
123## Create your instance
124### Change the `Identifier` to match your application name
125### Change `master-username` and `master-user-password`
126* Free-tier: db.t2.micro
127* Free-tire: 20GB
128* Define your Security Group
129* Disable MultiAZ
130
131```sh
132aws rds create-db-instance --db-instance-identifier ##Identifier## --allocated-storage 20 --db-instance-class db.t2.micro --engine mysql --master-username ##USER## --master-user-password ##PASSWORD## --availability-zone sa-east-1a --vpc-security-group-ids sg-2b1c154e --storage-type gp2 --no-multi-az
133```
134
135## Create a `.my.cnf` with the proper configuration
136```
137[client]
138host=##identifier##.rds.host
139user=##USER##
140password=##PASSWORD##
141```