Amazon EC2 Compute
Best experience with the AWS MCP server; also works with the AWS CLI alone — no hard dependency on either.
Critical Warnings
Launch configurations are deprecated and do not support current EC2 instance types; new accounts cannot create them. Use launch templates for every new Auto Scaling group. See auto-scaling.md [blocked].
ASGs ignore ELB health checks by default: An Auto Scaling group only uses EC2 status checks unless you set --health-check-type ELB. Without it, instances failing the load balancer's health check stay in service forever. See auto-scaling.md [blocked].
IMDSv2 hop limit breaks containers: the default HttpPutResponseHopLimit of 1 makes the IMDSv2 token PUT response fail to reach a containerized process (the extra hop exceeds the response TTL), so the token request times out. Set HttpPutResponseHopLimit=2 for bridge/awsvpc container workloads. (If IMDSv2 is required, a subsequent tokenless GET returns 401; if optional, it silently falls back to IMDSv1.) See provisioning.md [blocked].
T3/T3a/T4g default to unlimited mode: Unlike T2 (standard), these burst without throttling but bill surplus CPU credits when 24h-average CPU exceeds baseline — a silent cost leak. See instance-selection.md [blocked].
Instance store is ephemeral: Data on instance store volumes is lost on stop, hibernate, terminate, instance-type change, and host failure — it survives only a reboot. Put anything durable on EBS/EFS/S3. See instance-selection.md [blocked].
Which do you need?
Quick Navigation
Common Workflows
"Stand up an autoscaling web fleet" → Create a launch template (AMI, type, IMDSv2), then an ASG referencing it with --health-check-type ELB and a target-tracking policy, see auto-scaling.md [blocked]. For the public entry point, secure the load balancer (TLS/ACM, WAF, security response headers) per the Security Considerations below and the load-balancer notes in auto-scaling.md [blocked] — the load-balancer build itself belongs to aws-networking.
"Roll out a new AMI to my fleet" → New launch template version → instance refresh; pin a numeric launch-template version so rollback works, see auto-scaling.md [blocked].
"Connect to a private instance without a bastion" → Give the instance SSM permissions (an instance profile with AmazonSSMManagedInstanceCore, or account-level DHMC) plus a network path, then use Session Manager, see systems-manager.md [blocked].
"Cut EC2 cost" → Right-size (burstable vs fixed-performance), Graviton where the app supports Arm64, Spot with price-capacity-optimized for fault-tolerant fleets, release idle Elastic IPs, see instance-selection.md [blocked].
Troubleshooting
Full tables and more errors in troubleshooting.md [blocked].
Security Considerations
- Enforce IMDSv2 (
HttpTokens=required) on launch templates to block SSRF-based credential theft; set the account-level default per Region (applies to new launches only). - Prefer Session Manager over inbound SSH — no open port 22, no key management, and a CloudTrail record of session API calls; enable Session Manager session logging to CloudWatch Logs/S3 (off by default) to capture the in-session commands themselves — see systems-manager.md [blocked].
- Use instance profiles, never embedded credentials; scope the role to least privilege.
- Encrypt EBS/AMIs; to share an encrypted AMI cross-account, re-encrypt under a customer-managed KMS key (the default
aws/ebskey can't be shared). - Enable CloudTrail in all Regions to audit EC2/ASG/SSM API activity, and alarm on sensitive actions (security-group changes,
RunInstances/TerminateInstancesfrom unexpected principals) so unauthorized changes surface. - For public-facing web fleets, encrypt traffic in transit with an ACM certificate on the load balancer's HTTPS listener and add AWS WAF for defense in depth against common web exploits — the load-balancer/WAF setup itself lives in
aws-networking. - For hardening beyond this guidance, see AWS EC2 security best practices and CIS Benchmarks for the guest OS.
Not Covered By This Skill
- Launching a single hardened instance with best-practice defaults → use the
launching-ec2-instance-with-best-practicesskill - Creating IAM roles / instance profiles for EC2 → use the
setting-up-ec2-instance-profilesskill - Building AMIs with an Image Builder pipeline → use the
amazon-ec2-image-builderskill - Lambda / serverless →
aws-serverless; ECS/Fargate →aws-containers; EKS/Kubernetes →kubernetes - VPC, subnets, ALB/NLB, endpoints →
aws-networkingor built-in knowledge - IAM policy logic and CloudWatch dashboards/agent setup →
aws-iam,aws-observability


