EC2 24 images have no passwords. At first boot cloud-init puts the key pair's public half into the default user's authorized_keys: ubuntu on Ubuntu 225 , admin on Debian 319 , ec2-user on Amazon Linux 24 . AWS 24 hands you the private half once, at creation:
aws ec2 create-key-pair --key-name lamp-book-key --key-type ed25519 \
--tag-specifications 'ResourceType=key-pair,Tags=[{Key=Project,Value=lamp-book-ch01}]' \
--query KeyMaterial --output text > ~/.ssh/lamp-book-key.pem
chmod 600 ~/.ssh/lamp-book-key.pem
ssh -i ~/.ssh/lamp-book-key.pem -o StrictHostKeyChecking=accept-new ubuntu@54.236.40.252 \
'whoami; hostname; uname -srm; lsb_release -ds'Output
Warning: Permanently added '54.236.40.252' (ED25519) to the list of known hosts. ubuntu ip-172-31-8-174 Linux 7.0.0-1012-aws aarch64 Ubuntu 26.04.1 LTS
accept-new trusts the host key on first contact; to verify it, compare the fingerprints that aws ec2 get-console-output shows. Safer still, generate the key locally (Key Pairs) and upload only the public half with aws ec2 import-key-pair. EC2 Instance Connect and Session Manager avoid opening port 22 at all.