Launching Your First Instance

A launch needs the AMI and type, a key pair and security group (Key Pairs and SSH Access and Security Groups, created first), a subnet, a root volume and the user data of User Data for First-Boot Setup. The console's Launch instance wizard asks for the same fields; the CLI form can be reviewed and rerun:

Launching a tagged t4g.micro with a gp3 root volume and first-boot scriptShell
q='Instances[0].[InstanceId,State.Name,InstanceType,'
q+='Placement.AvailabilityZone,PrivateIpAddress]'
aws ec2 run-instances --image-id ami-0abbb5421e6a3a16d --instance-type t4g.micro \
  --key-name lamp-book-key --security-group-ids sg-069ce137f5c2f07ba \
  --subnet-id subnet-051b6199ef9f283cb --metadata-options HttpTokens=required \
  --block-device-mappings \
    'DeviceName=/dev/sda1,Ebs={VolumeSize=8,VolumeType=gp3,DeleteOnTermination=true}' \
  --user-data file://lamp-user-data.yaml --query "$q" --output text \
  --tag-specifications \
    'ResourceType=instance,Tags=[{Key=Name,Value=lamp-web},{Key=Project,Value=lamp-book-ch01}]' \
    'ResourceType=volume,Tags=[{Key=Project,Value=lamp-book-ch01}]' \
    'ResourceType=network-interface,Tags=[{Key=Project,Value=lamp-book-ch01}]'
Output
i-0d87b52d19abc8fc5   pending   t4g.micro   us-east-1a   172.31.8.174

HttpTokens=required enforces IMDSv2, whose session tokens block the request-forgery attacks that leaked credentials through IMDSv1. The Project tag lets one filter find everything at teardown. After aws ec2 wait instance-running, describe-instances reported the auto-assigned public address 54.236.40.252.