Small public VPC with one EC2 instance in us-east-1. Terraform creates only the network and compute pieces listed in requirements.md.
- VPC
10.10.0.0/16 - Public subnet
10.10.1.0/24 - Internet Gateway
- Public route table with
0.0.0.0/0to the IGW - Security group allowing SSH from
ssh_cidr - One
t3.microAmazon Linux 2023 instance with a public IP (not an Elastic IP)
It does not create a NAT Gateway, RDS, EKS, load balancer, or Elastic IP.
- Terraform
>= 1.6.0 - AWS credentials configured locally (environment variables, AWS CLI profile, or similar)
- Permission to create VPC, subnet, IGW, route table, security group, and EC2 in
us-east-1
Do not put access keys in Terraform files. Credentials stay in your environment or AWS profile.
Edit terraform.tfvars:
ssh_cidr— prefer your public IP asx.x.x.x/32instead of0.0.0.0/0key_name— optional. Only set this if the key pair already exists inus-east-1. Leave it unset to launch without a key pair and use EC2 Instance Connect from the console or AWS CLI (no extra AWS resources required)
The AMI is resolved at plan/apply time from the AWS SSM public parameter:
/aws/service/ami-amazon-linux-latest/al2023-ami-kernel-default-x86_64
terraform init
terraform plan
terraform applyThis repository does not run apply for you. Destroy the stack when you are done:
terraform destroyIf you set key_name:
ssh -i <your-private-key.pem> ec2-user@<instance_public_ip>instance_public_ip is a Terraform output after apply.