EC2 · EBS · ENI
Updated 2026-09-06
AWS BASIC · 02

EC2 · EBS · ENI

What one server is made of, and how it connects
Icon-Resource/Compute/Res_Amazon-EC2_AMI_48 Icon-Resource/Storage/Res_Amazon-Elastic-Block-Store_Volume_48 Icon-Resource/Networking-and-Content-Delivery/Res_Amazon-VPC_Elastic-Network-Interface_48
What is one serverRent via EC2, clone from an AMI.
What stays, what disappearsStop/terminate, EBS, snapshots.
How it connectsOne ENI holds IPs and SGs.
01

EC2 — AWS servers for rent

Elastic Compute Cloud

  • Renting a server from AWS
  • A virtual server you start when needed and stop when not.
  • Easy to scale up and down, hence Elastic. Two C’s make EC2
02

AMI — a server template

Amazon Machine Image

  • The template that sets the OS and settings to launch with.
  • A configured server can be baked back into an AMI.
  • Then launch as many identical servers as you like.

Seven choices at launchIn the console wizard’s order

OS
Linux · Windows · macOS — set by the AMI
CPU
How many vCPUs — set by the type’s family and size
Memory
RAM. Same size, different amount per family
Storage
Network-attached EBS · EFS, or instance store on the physical host
Network
NIC bandwidth, and whether to assign a public IP
Firewall
Security group — who may connect, on which ports
First-boot script
User data — a script that runs once, at first boot
© 2026 tiaz tiaz.dev 1/14
EC2 · EBS · ENIReading an instance type
03

Reading type names

One short name is a spec sheet

t3.micro
tFamily — T·M general, C compute, R memory
3Generation — higher is newer, usually cheaper and faster
microSize — each step doubles memory
Family first, then generation and size.

Instance familiesExam point

FamilyUseWhen to pickExample
TGeneral · burstableMostly idle web / dev serverst3.micro
MGeneral purposeBalanced CPU and memory; the defaultm7g.large
CCompute optimizedCompute-heavy batch · game serversc7i.xlarge
R / XMemory optimizedCaches · in-memory DBsr7g.large
I / DStorage optimizedHigh IOPS · large local disksi4i.large
G / PAccelerated computingGPU training · inference · renderingg5.xlarge

Instance sizes

nano → micro → small
Smallest three: dev, test
medium → large
Where production starts
xlarge → 2xlarge → 4xlarge…
2× memory, and more vCPUs
a · g · i · n suffixes
AMD · Graviton · Intel · enhanced networking
.metal — bare metal
Whole physical server, no hypervisor. (For licenses tied to hardware)
© 2026 tiaz tiaz.dev 2/14
EC2 · EBS · ENIStates and placement — where billing splits
04

Three states — where billing splits

You pay for the instance only while it runs.

runningOn. Being billed.
stoppedOff. Instance charges stop.
terminatedDeleted for good. No undo.

State transitionsExam point

pendingstarting uprunningbilledstoppingshutting downstoppedno instance feeterminatedno way back

A reboot doesn’t change state. It’s a restart, so the public IP and instance store stay. Hibernate saves memory to the root volume, stops, then resumes where it left off.

Placement groups — how instances sit physically

Cluster
Packed into one rack. Lowest latency; if the rack fails, they all fail
Spread
Scattered across distinct hardware. Limited instances per AZ
Partition
Split by groups of racks. For distributed stores like HDFS·Cassandra
© 2026 tiaz tiaz.dev 3/14
EC2 · EBS · ENIPricing — what you commit to, what you pay for

Pricing models

On-DemandPay per second for what you use. The default, and the priciest.
Savings PlansCommit to a fixed $/h for 1–3 years, get a discount.
ReservedReserve a specific type for 1–3 years. You commit to instances, not dollars.
SpotSpare capacity, up to 90% off. Reclaimed after a 2-minute notice.
Dedicated HostA whole physical server. For licenses tied to cores.
Capacity ReservationHolds capacity in advance. It secures a spot; it saves nothing.

Which one to choose

Servers running 24/7
Savings Plans — commit to an hourly spend for a discount
Interruptible jobs
Spot — up to 90% off, reclaimed after a 2-minute notice
Short trial runs
On-Demand — no commitment. Priciest, and most flexible
Per-core licenses
Dedicated Host — rent the whole physical server

What you pay forStopping halts only the first row

—When chargedTo stop it
Instance hoursOnly while runningStop the instance
EBS volumeAs long as it exists (GB-month)Delete the volume. Stopping won’t do it
SnapshotAs long as it’s kept (GB-month)Delete it
Public IPv4From allocation on (hourly)Release unused EIPs. Billed even while stopped
Data transferOutbound (per GB)Inbound is free; private-IP traffic within one AZ is free
© 2026 tiaz tiaz.dev 4/14
EC2 · EBS · ENIWhat disappears, what stays
05

Instance Store

What’s lost when you stop

  • Data on an EC2 instance store is lost when you stop.
  • A temporary disk on the physical host, so it’s fast
  • It survives a reboot, but not a stop or terminate.
06

EBS — over the network

Elastic Block Store

  • It outlives the instance.
  • Detach it and attach it to another instance.
  • Own lifetime, own bill (billed even with the instance off)

Stop (stopped) vs terminate (terminated)Exam point

—StopTerminate
Instance chargeStopsStops
EBS volumeStill billedRoot volume deleted
Data on itKeptLost
Public IPChanges (EIP excepted)Released
UndoStart it againNot possible

Three disks, easily confused

  • EBSA network-attached disk. Survives instance deletion; detach it and attach it to another instance.
  • Instance storeA temporary disk on the physical host. Fast, but lost on stop or terminate. Survives a reboot.
  • SnapshotIncremental EBS backup in S3. The start for moving AZ/Region or baking an AMI.
© 2026 tiaz tiaz.dev 5/14
EC2 · EBS · ENIAvailability Zones · snapshots · encryption
07

A volume lives in one AZ

It can’t attach to an instance in another AZ.

  • Volume and instance must be in the same AZ.
  • So changing AZ is a copy, not a move.
  • For Region-wide storage, use another service such as EFS.
08

Snapshots — how to cross AZs and Regions

Take a snapshot and create a new volume in another AZ or Region.

  • Stored in S3 incrementally. Only the first one is full
  • A volume made from a snapshot can be larger than the original.
  • Baking an AMI starts from this snapshot, too.

Icon-Resource/Storage/Res_Amazon-Elastic-Block-Store_Snapshot_48 What snapshots doExam point

  • Incremental backupStored in S3; only the first one is full.
  • Moving AZ · RegionCopy it, then create the volume in the other AZ or Region. (The only way a volume crosses AZs)
  • Where AMIs startBaking an instance into an AMI comes down to snapshotting its root volume.
  • Automation and retentionDLM takes and deletes them on a schedule. Old ones move to the archive tier.

Icon-Architecture/16/Arch_AWS-Key-Management-Service_16 Encryption — decide at creation

  • With a KMS keyTurn it on when you create the volume. Data, snapshots and volumes made from them are all encrypted.
  • Can’t enable it laterAn existing volume must go snapshot → encrypted copy → new volume.
  • No performance costNo noticeable penalty, so better to leave it on by default.
© 2026 tiaz tiaz.dev 6/14
EC2 · EBS · ENIVolumes — choosing and changing

Volume rules — where they attach, when they goExam point

AZ
A volume belongs to one AZ. It attaches only to instances there
Attachment
One volume, one instance (except io1·io2 Multi-Attach)
Lifetime
Independent of the instance — detach it and attach it elsewhere
Root volume
Delete on termination is on by default. Off for data volumes
While stopped
Volumes remain and are still billed

Icon-Resource/Storage/Res_Amazon-Elastic-Block-Store_Volume-gp3_48 EBS volume types — which to pickRoot volumes: SSD only

TypeWhatWhen to pick
gp3General Purpose SSD (default)Baseline 3,000 IOPS · 125 MB/s. Size and speed set separately
gp2General Purpose SSD (older)3 IOPS per GiB — size sets performance
io2Provisioned IOPS SSDYou buy the IOPS. Latency-sensitive DBs
st1Throughput Optimized HDDLarge sequential files. Logs · big data
sc1Cold HDDCheapest. Rarely read data

What you can change laterOnly upward

  • Size — grow onlyIt grows while in use, but can’t shrink. To shrink, create a new volume and copy the data over.
  • Type — changeableChange it live, e.g. gp2 → gp3. Performance takes a while to settle afterwards.
  • LimitsVolumes 1 GiB – 16 TiB; gp3 up to 16,000 IOPS · 1,000 MB/s. Beyond that, the instance’s own EBS bandwidth is the cap.
© 2026 tiaz tiaz.dev 7/14
EC2 · EBS · ENIENI — the card and its addresses
09

ENI — EC2’s virtual NIC

Elastic Network Interface

  • An ENI also lives in one Availability Zone — same rule as volumes.
  • Each instance has one primary ENI; its instance type may allow more.
  • Detach it and move it to another instance — the addresses go with it.
  • IPs, MAC and security groups belong to this card, not the instance.
10

Where a public IP attaches

Not to the instance, but to the ENI’s private IP.

  • Assigned at random from AWS’s pool at launch — you can’t choose it.
  • The private IP is fixed for the instance’s life
  • Since 2024-02, public IPv4 is billed hourly, always.
  • Stop and start the instance, and the public IP changes.
11

EIP — a fixed address

Elastic IP

  • A static public IP allocated to your account and attached to an ENI.
  • Billed hourly, attached or not. Release it when unused.
  • Belongs to a Region. 5 per account by default
  • The other way to pin an address is a domain (Route 53).

Icon-Resource/Networking-and-Content-Delivery/Res_Amazon-VPC_Elastic-Network-Interface_48 ENI rulesExam point

AZ
An ENI also belongs to one AZ
Primary ENI
One per instance (eth0). Can’t be deleted; goes with the instance
Extra ENIs
As many as the instance type allows.
Private IP
1 per ENI by default; more secondary IPs by type
Security group
Stateful allow rules on the ENI, not the instance
MAC address
Moves with the card (MAC-bound license? Move the ENI)
© 2026 tiaz tiaz.dev 8/14
EC2 · EBS · ENIENI — a network card inside a subnet
eth0 gets its private IP from Subnet A, eth1 from Subnet B; each card has its own security groups.AWS docs: “Multiple network interfaces”

Four things the diagram showsExam point

  • An ENI belongs to a subnetIts private IP comes from that subnet’s range.
  • Security groups per cardThey attach to the ENI, not the instance — in the diagram eth0 opens 80·443, eth1 only 22.
  • An EIP sits on a private IPOne public IP per private IP on the card. Move the card and the addresses follow.
  • One instance, two subnetsIn one AZ, cards can span subnets: a public one, plus a private one for admin
© 2026 tiaz tiaz.dev 9/14
EC2 · EBS · ENIAddresses · access · checklist

Three kinds of addressExam point

—How you get itAfter stop/startCost
Private IPAutomatic, from the subnetUnchangedFree
Public IPRandom from the pool at launchChanges$0.005 per hour
Elastic IPAllocate to the account, then attachUnchanged$0.005 per hour (even unattached)

Access and permissions — where accidents happen

  • Key pairYou get the private key (.pem) once, at creation. Lose it and there’s no reissue.
  • Security groupAllow rules only — who may connect, on which ports. Never open 22·3389 to 0.0.0.0/0.
  • IAM roleAttach it via an instance profile. Never keep access keys on the server.

Checklist — before you launch an instance

  • Saved the key pair? It can’t be downloaded again
  • Does the security group keep 22/3389 closed to 0.0.0.0/0?
  • Checked the root volume’s Delete on termination setting?
  • Know that User data runs once, at first boot?
  • Turned on termination protection?
  • Attached an IAM role? Don’t embed access keys
  • Tagged it (Name, Env, Owner)? Untagged, it’s lost in the bill
  • Enabled volume encryption? Only possible at creation
© 2026 tiaz tiaz.dev 10/14
EC2 · EBS · ENIScope · stop or not · recovery

Icon-Architecture-Group/32/Region_32 Scope — what belongs to a Region, what to an AZExam point

ResourceScopeGood to know
AMIRegionVisible only in its own Region — copy it to use it elsewhere
SnapshotRegionCopyable across Regions — the only way a volume leaves its Region
EBS volumeAZAttaches only to instances in the same AZ
InstanceAZLives in the AZ picked at launch — to move, relaunch from an AMI
EIPRegionMoves across AZs within its Region. 5 per Region per account by default

Stop first? What works live, what needs a stopSnapshots need no stop

TaskInstanceGood to know
Take a snapshotRunningCaptures only what’s on disk — if unsure, pause first
Resize·retype a volumeRunningThen grow the file system in the OS to use it
Attach/detach data volumeRunningUnmount before detaching
Detach the root volumeStoppedCan’t be detached while running
Change instance typeStoppedChange it while stopped — the public IP changes too
Edit User dataStoppedOnly while stopped. Still runs only at first boot by default
Bake an AMIRunningReboots first by default — skip it and consistency is on you

Recovery — which fix for which lossThe size of the loss sets the method

One file
Leave the volume be; make a new volume from a snapshot, attach it, copy the file out
Whole volume
Restore it from a snapshot. Same AZ: directly; another AZ: copy first
Won’t boot
Detach the root volume, attach it to another instance as a data disk, fix it
Whole server
If you made an AMI, launch a new one from it
Terminated
The root volume is gone. Without a snapshot or AMI, there’s no way back
© 2026 tiaz tiaz.dev 11/14
EC2 · EBS · ENICheck yourself

Try these!Practice

  1. 1You stop a dev server every evening and start it each morning, yet the hours it’s off don’t cost $0. Which charges continue while it’s stopped? Choose all that apply.2 answers

    1. AInstance-hour charges
    2. BThe attached root EBS volume
    3. CData left on the instance store
    4. DThe EIP attached to the instance
    5. EThe instance’s data transfer
  2. 2A fleet that scales between 10 and 50 instances with load, across several Availability Zones, must read and write the same 50 GB folder. What do you attach?

    1. ACreate one volume and attach it to every instance
    2. BGive each instance a volume and keep them in sync
    3. CCreate an EFS file system and mount it everywhere
    4. DKeep it on instance store and copy it as needed
  3. 3A database with heavy random reads and writes. Performance must be consistent, and the data must outlive the instance. Which disk?

    1. AInstance store — on the physical host, so the fastest
    2. Bgp2 — a bigger volume brings more IOPS
    3. Cst1 — Throughput Optimized HDD
    4. Dio2 — Provisioned IOPS SSD
Answers and explanations
  1. 1B · DStopping halts only the instance-hour charge. A volume has its own lifetime, so it stays and is billed as long as it exists. Since 2024-02, public IPv4 and EIPs keep costing money even with the instance off.
  2. 2CA volume lives in one AZ and attaches to one instance. io1·io2 Multi-Attach is the exception, but only for up to 16 Nitro instances in the same AZ — not 50 across AZs. Once many machines write the same data at once, you need a file system, not a block device; EFS is Regional and many instances mount it together. Instance store is a disk on the physical host and can’t be shared at all.
  3. 3DTwo conditions, each ruling out one option. Must outlive the instance rules out instance store — fast, but lost on stop or terminate. Must be consistent rules out gp2: at 3 IOPS per GiB its performance is tied to size, and small volumes rely on bursts. st1 is for large sequential files, not random IO. io2 keeps delivering the IOPS set at creation, so it is the answer when "consistent performance" is required.
© 2026 tiaz tiaz.dev 12/14
EC2 · EBS · ENITraps and terms

Common trapsExam favorite

  • Thinking a stopped instance costs $0Only instance charges stop. Attached EBS and held public IPv4 are still billed.
  • Hitting Terminate, meaning StopEven the root volume is gone. Termination protection is the only safeguard.
  • Picking the size firstChoose the family (the letter) first. At the same size, C and R are different servers.
  • Trusting the public IP to stayIt changes on stop/start. For a fixed address, use an Elastic IP or a domain.
  • Thinking User data runs every bootIt runs only once, at the very first boot.
  • Thinking volumes can shrinkThey only grow. To shrink, create a new volume and copy the data over.
  • Attaching a volume from another AZEBS lives in one AZ. The only way across is to snapshot and copy.
  • Blocking with a security groupSecurity groups have no deny rules, only allows — blocking is the network ACL’s job.

Terms in one line

AMI A template for stamping out servers. Holds the OS and initial setup.
Instance type A spec sheet in one name: family, generation, size.
Instance store A temporary disk on the physical host. Lost on stop or terminate.
EBS A network-attached disk. Outlives the instance and can be moved.
Snapshot An incremental backup of EBS in S3.
User data A script run as root, once, at first boot.
Termination protection Blocks the terminate API. Doesn’t block stop.
Dedicated Host Rent the physical server itself. For per-socket or per-core licenses.
Graviton AWS’s own ARM CPU. Marked by a g in the type name.
IMDS Internal-only address where an instance looks up its own metadata (169.254.169.254).
Availability Zone (AZ) An isolated group of data centers in a Region. EBS and ENIs belong to one.
ENI The virtual network card EC2 talks through. Carries IPs, MAC and security groups.
EIP A static public IP allocated to your account. Billed attached or not.
Multi-Attach Attaches one io1·io2 volume to several instances in the same AZ.
DLM Lifecycle manager that takes and deletes snapshots on a schedule.
In one line

One server is EC2 (compute) · EBS (disk) · ENI (network card). All three are bound to one Availability Zone; to reach beyond it, take a snapshot or pin the address.

EC2AMIInstance typeStatesEBSSnapshotENIEIP
© 2026 tiaz tiaz.dev 13/14
EC2 · EBS · ENIReferences

Official docsAWS guides · video · articles

  • EC2 User Guidep. 1 The source on instances · AMIs · lifecycle docs.aws.amazon.com/ec2
  • Instance lifecyclepp. 3 · 5 What stays and what goes in each state docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-lifecycle.html
  • AMIp. 1 What an image does and doesn’t contain docs.aws.amazon.com/AWSEC2/latest/UserGuide/AMIs.html
  • Instance typesp. 2 How to read family names; tables by generation aws.amazon.com/ec2/instance-types
  • EBS User Guidepp. 5 · 7 All that follows from volumes living outside the instance docs.aws.amazon.com/ebs/latest/userguide/what-is-ebs.html
  • EBS volume typesp. 7 IOPS and throughput of gp3 · io2 · st1 docs.aws.amazon.com/ebs/latest/userguide/ebs-volume-types.html
  • EBS snapshotspp. 6 · 11 The only way to move a volume out of its AZ docs.aws.amazon.com/ebs/latest/userguide/ebs-snapshots.html
  • ENIpp. 8 · 9 Moving a card to another instance docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html
  • Elastic IP addressespp. 8 · 10 What a fixed address means, and what it costs docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html
  • EC2 pricingp. 4 Today’s On-Demand · Reserved · Spot prices aws.amazon.com/ec2/pricing
  • Pricing Calculatorp. 4 Rerun this sheet’s numbers for your own setup calculator.aws
  • Launching your first workload on Amazon EC2p. 1 A Korean-language session that launches one instance from scratch. Official AWS Korea channel www.youtube.com/watch?v=Mg6lLromiQM
  • One to Many: Evolving VPC Designp. 11 What breaks first when one server becomes many aws.amazon.com/blogs/architecture/one-to-many-evolving-vpc-design
  • Security groupspp. 9 · 10 · 13 An allow-only firewall. Denying is the network ACL’s job — coming next docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-security-groups.html
  • EC2 Auto Scalingp. 4 From one server to many, following demand — coming next docs.aws.amazon.com/autoscaling/ec2/userguide/what-is-amazon-ec2-auto-scaling.html
© 2026 tiaz tiaz.dev 14/14