Separate intent from packet and block I/O
The control plane includes operations such asRunInstances, StopInstances, and AttachVolume. These APIs validate intent, change resource state, and report asynchronous progress.
The data plane is CPU execution, memory access, packets through ENIs, and block I/O. A control-plane impairment can prevent a new attachment while an existing instance keeps serving.
running state means EC2 started the instance. It does not prove the application is ready.
Nitro establishes the host boundary
AWS describes Nitro as hardware and software components providing compute, storage, networking, memory, and security capabilities. Nitro Cards offload VPC networking, EBS, and instance storage. The Nitro Security Chip helps establish a hardware root of trust. AWS documents interfaces and guarantees, not every placement algorithm or internal call behindRunInstances.
Nitro moves major virtualization and I/O functions into dedicated hardware and firmware components.
What a launch assembles
A launch request supplies or derives:- AMI and architecture. The AMI defines the root image, boot permissions, and block-device mapping.
- Instance type and placement. The type defines resources and capabilities; Region, Availability Zone, tenancy, and placement settings constrain fulfillment.
- Networking. EC2 creates or attaches a primary ENI in a subnet. Security groups apply to ENIs.
- Storage. EC2 creates EBS volumes from snapshots and exposes supported devices as NVMe on Nitro instances.
- Identity and metadata. An instance profile supplies temporary role credentials through IMDS when configured.
- Boot configuration. User data is made available to software such as cloud-init.
Resources have different lifetimes
An ENI carries private addresses, a MAC address, security groups, and other attributes. Secondary ENIs can move between compatible instances in one Availability Zone.
EBS is network-attached block storage.
DeleteOnTermination controls volume cleanup. Attachment alone is not a backup.
Instance store is host-attached temporary storage. Its data is lost on stop, hibernation, termination, or host failure.
EBS and ENIs can outlive compute placement; instance-store data cannot.
User data is input, not readiness
EC2 makes user data available at launch; the AMI decides how to interpret it. On common cloud-init images, scripts run as root on first boot by default. Keep scripts idempotent, pin artifacts, fail visibly, and avoid long-lived secrets. Bake stable dependencies into an AMI and leave environment-specific configuration for launch.Stop, start, reboot, and hibernate differ
A reboot ordinarily keeps the instance on its host. Stopping an EBS-backed instance retains the instance ID, ENIs, and EBS volumes; starting usually places it on a new host. Instance-store data disappears, and an automatic public IPv4 address can change. Hibernation saves RAM to the encrypted EBS root volume before enteringstopped. Eligibility, root-volume capacity, and duration limits apply.
Termination ends the instance. Volume and ENI deletion follow configured lifecycle behavior.
Stop/start preserves durable EC2 resources but normally replaces the underlying host and clears RAM.
Design around failure boundaries
Separate application, guest, instance, host, volume, Availability Zone, and Region failures. Replace unhealthy instances, replicate durable state across suitable boundaries, and distribute stateless capacity across Availability Zones. System status checks reflect AWS infrastructure reachability. Instance status checks reflect guest networking and operating-system responsiveness. Neither replaces application health checks.Frequently asked questions
Does running mean my application is ready?
Does running mean my application is ready?
No. Running indicates that EC2 started the instance. The guest may still be discovering devices, processing user data, installing software, or starting services. Use an application-level readiness check and retain initialization logs.
What survives stop and start?
What survives stop and start?
The instance ID, attached EBS volumes, ENIs, private addresses, and configuration generally persist. The instance usually moves hosts, instance-store data and RAM are lost, and an automatically assigned public IPv4 address can change.
Is hibernation the same as pausing?
Is hibernation the same as pausing?
Not exactly. EC2 asks the operating system to save RAM to the encrypted EBS root volume, shuts down, and later restores memory. Eligibility and time limits apply, instance-store data is lost, and resume depends on capacity.