Choose, buy and run your EC2 instances: types, purchasing options, states, Auto Scaling and load balancers!
AWS
Published on
Karl Certa Systems & network administrator5 years in IT, from support to sysadmin, now Ops. Learning cloud, and writing everything down here. Focused on IaC & cloud AWS SAA, Kubernetes next LinkedIn karlcerta.fr GitHub Karl Certa
Amazon EC2 (Elastic Compute Cloud) is the AWS virtual machine service: you pick an instance type, an image and a purchasing option, and AWS provides the capacity in the requested Availability Zone (AZ).
🏷️ Reading an instance type name
An instance type name reads in four parts: series, generation, options, then size after the dot.
📌 Part
📊 Example m7g.large
💡 Meaning
🔤 Series
m
Workload family (here general purpose)
🔢 Generation
7
The higher the number, the newer the hardware
⚙️ Options
g
AWS Graviton processor (Arm)
📏 Size
large
Number of virtual processors (vCPU) and memory (metal for bare metal)
Main series
📌 Series
🎯 Focus
💼 Typical use cases
T
Burstable: baseline CPU performance, with bursts
Small web servers, dev/test, lightly loaded workloads
M
Balanced general purpose
Application servers, backends
C
Compute optimized
Intensive compute, batch, encoding
R / X
Memory optimized / memory intensive
In-memory databases, caches, analytics
I / D
Storage optimized / dense storage
NoSQL databases, heavy local disk I/O
P / G
GPU accelerated
Machine learning training, graphics rendering
Common options in the name
📌 Letter
💡 Meaning
a
AMD processor
g
AWS Graviton processor (Arm): beware, it needs an arm64 AMI
i
Intel processor
d
Instance Store volumes (local disks) included
💰 Purchasing options
Discounts are stated “up to” compared with On-Demand pricing; the actual rate depends on type, Region, term and payment.
📌 Purchasing option
🔒 Commitment
💰 Max discount
🎯 Use case
On-Demand
None, billed per second (60 s minimum)
None
Unpredictable load, tests, short needs
Savings Plans
1 or 3 years, amount in $/hour
Up to 72%
Stable baseline load, recommended by AWS over RIs
Reserved Instances (RI)
1 or 3 years, fixed instance attributes
Up to 72%
Stable 24/7 load on a known type
Spot
None, instance reclaimed by AWS with a 2 min notice
Up to 90%
Batch, continuous integration, rendering, any job that tolerates interruption
Dedicated Instance
None
Depends on the option chosen
Physical hardware dedicated to a single account
Dedicated Host
Hourly or 1 / 3 year reservation
Reservation up to 70%
BYOL (Bring Your Own License) per socket or core
Capacity Reservation
None for immediate use
None
Guarantee capacity in an AZ (event, disaster recovery plan)
Savings Plans: which one
📌 Type
🌍 Scope
💰 Max discount
Compute Savings Plans
EC2 across families and Regions, Fargate, Lambda
Up to 66%
EC2 Instance Savings Plans
One instance family in one Region
Up to 72%
Reserved Instances: variants
📌 Criterion
📊 Options
💡 Consequence
🔒 Class
Standard / Convertible
Standard: best discount, can only be modified. Convertible: exchangeable for other attributes, lower discount
💳 Payment
All / Partial / No Upfront
The more you pay upfront, the bigger the discount
📍 Scope
Regional / Zonal
Only a zonal RI reserves capacity in an AZ
⏳ Term
Non-cancellable, no automatic renewal
Due until the end even if the instance is terminated; then On-Demand rate
Spot, Dedicated and Capacity Reservation: rules to remember
📌 Item
📊 Rule
💡 Why it matters
⚡ Spot interruption
Mostly when EC2 needs the capacity back, or if the Spot price exceeds your max price
Setting a max price makes interruptions more frequent
⏱️ Spot notice
2 minutes before stop or termination (via EventBridge and metadata)
No 2 min warning if the chosen behavior is hibernation
🖥️ Dedicated Host
Billed per host, socket / core visibility, host affinity
Required for licenses bound to physical hardware
📦 Capacity Reservation
Billed at the On-Demand rate, whether an instance runs in it or not
No discount of its own: combine with Savings Plans or regional RIs
🔄 Instance states and billing
📌 State
💰 Instance billed
💡 Meaning
pending
No
Starting up
running
Yes
Instance in service, even when idle
stopping
No (yes when hibernating)
Stopping
stopped
No
Stopped, can be started; EBS (Elastic Block Store) volumes are still billed
shutting-down
No
Termination in progress
terminated
No
Permanently deleted
Stop, hibernate, terminate: what is kept
📌 Item
⏸️ Stop
💤 Hibernate
🗑️ Terminate
🖥️ Physical host
Usually changes
Usually changes
None
🧮 RAM
Erased
Saved to the EBS root volume
Erased
💽 EBS root volume
Kept
Kept
Deleted by default
💾 Other EBS volumes
Kept
Kept
Kept by default (DeleteOnTermination)
⚡ Instance Store
Data erased
Data erased
Data erased
🔒 Private IPv4
Kept
Kept
None
🌐 Public IPv4
New one at start
New one at start
None
📍 Elastic IP
Stays associated
Stays associated
Disassociated, still allocated to the account
Hibernation prerequisites
📌 Prerequisite
📊 Value
⚙️ Enabling
At launch only, not possible on an existing instance
🧮 RAM
Less than 150 GiB (Linux), 16 GiB max (Windows)
💽 Root volume
Encrypted EBS, large enough to hold the RAM
⏳ Duration
60 days maximum in hibernated state
🚫 Not supported
Instances in an Auto Scaling Group, bare metal
🖼️ AMI, User Data and metadata
📌 Item
📊 Rule
💡 Consequence
🖼️ AMI (Amazon Machine Image)
Boot image specific to a Region, an OS and an architecture
To launch elsewhere, copy the AMI to the target Region
📜 User Data
Script or cloud-init directives, run as root at first boot
Does not run again on reboot without dedicated configuration
📏 User Data size
16 KB before base64 encoding
Hard limit, keep the script short
📄 User Data logs
/var/log/cloud-init-output.log
First place to look when bootstrap fails
🔑 IMDSv2 (Instance Metadata Service v2)
Metadata on 169.254.169.254, token obtained with a PUT request
Requiring IMDSv2 blocks calls without a token (IMDSv1)
HPC (High Performance Computing), low latency between nodes
Spread
Several AZs, each instance on a distinct rack
7 running instances per AZ
A few critical instances to keep apart
Partition
Several AZs, each partition on its own racks
7 partitions per AZ
HDFS, HBase, Cassandra
Spread isolates each instance, hence the low limit. Partition isolates groups: two instances in the same partition can fail together, but a rack failure only hits one partition. An AZ outage takes down an entire Cluster placement group.
🌐 Elastic IP
📌 Item
📊 Value
💡 Consequence
📍 Scope
One Region, cannot be moved
An Elastic IP (EIP) from eu-west-3 cannot be used in eu-central-1
🔢 Default quota
5 Elastic IPs per Region
AWS advises keeping them for failover, DNS for everything else
📈 Auto Scaling Group (ASG)
📌 Item
📊 Role
📄 Launch Template
Instance template: AMI, type, Security Groups, User Data, role
🔢 Min / Desired / Max
The group never goes below min, never above max, and aims for desired
🗺️ Multi-AZ
Instances balanced evenly across the chosen AZs
❤️ Health checks
EC2 status checks by default, ELB (Elastic Load Balancing) health checks optional; unhealthy instance replaced
🔗 Load balancer
Instances registered and deregistered automatically
🪝 Lifecycle hooks
Pause at launch or termination (1 h by default) to install software or collect logs
Scaling policies
📌 Policy
⚙️ Principle
🎯 When to use it
Target tracking
Keeps a metric at a target (average CPU at 50%)
Choice recommended by AWS in most cases
Step scaling
Stepped adjustments based on the size of the alarm breach
Graduated response to CloudWatch thresholds
Simple scaling
One adjustment per alarm, then cooldown (300 s by default)
Discouraged by AWS, prefer target tracking or step
Scheduled
Changes min / desired / max at a set time (cron expression, time zone)
Predictable load: office opening hours, end of week
Predictive
Forecasts load from history and launches capacity ahead of time
Cyclical traffic, applications slow to start
⚖️ Choosing a load balancer
📌 Load balancer
🧱 Layer
📊 Protocols
🔀 Cross-zone by default
🎯 Use case
ALB (Application Load Balancer)
7
HTTP, HTTPS, gRPC
Always on
Web applications, routing by path, host or header
NLB (Network Load Balancer)
4
TCP, UDP, TLS
Off
Extreme performance, static IP or Elastic IP per AZ
GWLB (Gateway Load Balancer)
3 and 4
IP (GENEVE, port 6081)
Off
Inserting third-party appliances: firewalls, intrusion detection and prevention
Security Groups (stateful firewall at instance level) are covered in the VPC cheatsheet.