A launch needs the AMI and type, a key pair and security group (Key Pairs and SSH Access and Security Groups, created first), a subnet, a root volume and the user data of User Data for First-Boot Setup. The console's Launch instance wizard asks for the same fields; the CLI form can be reviewed and rerun:
q='Instances[0].[InstanceId,State.Name,InstanceType,'
q+='Placement.AvailabilityZone,PrivateIpAddress]'
aws ec2 run-instances --image-id ami-0abbb5421e6a3a16d --instance-type t4g.micro \
--key-name lamp-book-key --security-group-ids sg-069ce137f5c2f07ba \
--subnet-id subnet-051b6199ef9f283cb --metadata-options HttpTokens=required \
--block-device-mappings \
'DeviceName=/dev/sda1,Ebs={VolumeSize=8,VolumeType=gp3,DeleteOnTermination=true}' \
--user-data file://lamp-user-data.yaml --query "$q" --output text \
--tag-specifications \
'ResourceType=instance,Tags=[{Key=Name,Value=lamp-web},{Key=Project,Value=lamp-book-ch01}]' \
'ResourceType=volume,Tags=[{Key=Project,Value=lamp-book-ch01}]' \
'ResourceType=network-interface,Tags=[{Key=Project,Value=lamp-book-ch01}]'Output
i-0d87b52d19abc8fc5 pending t4g.micro us-east-1a 172.31.8.174
HttpTokens=required enforces IMDSv2, whose session tokens block the request-forgery attacks that leaked credentials through IMDSv1. The Project tag lets one filter find everything at teardown. After aws ec2 wait instance-running, describe-instances reported the auto-assigned public address 54.236.40.252.