# On AWS

At the end, you have a box on Amazon Web Services (AWS), an EC2 instance in AWS's words, with Docker on it, and a Terminal on it from your laptop.

## At a glance

**Time:** 15 minutes, then [Any Linux computer with Docker](any-box.md).

**What you need:**

- An AWS account you can sign in to
- About 30 to 35 dollars a month while the box runs

**Steps:**

1. Rent the box
2. Connect to it
3. Install Docker

## Steps

1. **Sign in to the AWS console, type EC2 in the search bar at the top and open it.**
2. **Check the region in the top right corner.** Pick the one nearest your team.
3. **Press Launch instance** and fill it in:
   - **Name:** `loopgate-runner`.
   - **Application and OS Images:** **Ubuntu**, then **Ubuntu Server 24.04 LTS**. Under **Architecture**, keep **64-bit (x86)**.
   - **Instance type:** **t3.medium** (2 processors and 4 GB of memory).
   - **Key pair:** press **Create new key pair**, name it `loopgate`, keep **RSA** and **.pem**, and press **Create key pair**. Your browser downloads `loopgate.pem`, the key to the box; keep it safe.
   - **Network settings:** keep **Allow SSH traffic from** checked and change its menu from **Anywhere** to **My IP**. Leave **Allow HTTPS traffic** and **Allow HTTP traffic** unchecked, so nothing else comes in.
   - **Configure storage:** **30** GiB.
4. **Press Launch instance, then View all instances.**

   You should see: your instance with **Instance state** "Running" after a minute.

5. **Select it and copy its Public IPv4 address**, four numbers with dots such as `3.120.45.67`.

6. **On your laptop, in Terminal, lock the key file** so only you can read it. SSH refuses a key that others can read.

   ```sh
   chmod 400 ~/Downloads/loopgate.pem
   ```

7. **Connect**, with the address from step 5 in place of `<address>`.

   ```sh
   ssh -i ~/Downloads/loopgate.pem ubuntu@<address>
   ```

   You should see: a question about the box's fingerprint. Type `yes` and press Enter. Then a welcome message and a prompt that starts `ubuntu@`.

8. **Install Docker with Docker's own script.**

   ```sh
   curl -fsSL https://get.docker.com | sudo sh
   ```

   You should see: a few minutes of output ending with a note about running Docker as a non-root user.

9. **Let your user run Docker without `sudo`.**

   ```sh
   sudo usermod -aG docker $USER
   ```

10. **Leave with `exit`, then run the `ssh` command from step 7 again**, so the change takes hold.

## Check

Docker answers without `sudo` with `Docker Compose version v2.` followed by more numbers:

```sh
docker compose version
```

## Next

Your box is ready. Paste the command from the portal: [Any Linux computer with Docker](any-box.md).

## If something is off

- **SSH stops connecting one day.** Your address at home or at the office changed. Edit the instance's security group and set the SSH rule to **My IP** again.
- **SSH says the key's permissions are too open.** Run step 6 again.
- **Docker says permission denied.** Leave and connect again (step 10).

## Doing it by hand

Once Docker answers, [By hand](by-hand.md) sets the runner up from files instead of the portal's line.
