Skip to content

Compute cheat sheet

Terminal window
export AWS_ACCESS_KEY_ID=… # console → Access keys, or POST /v1/access-keys
export AWS_SECRET_ACCESS_KEY=…
alias sc='aws --endpoint-url https://ec2.shelfcs.com --region hel1'
# ~/.aws/config — so you stop typing the flags
[profile shelf]
region = hel1
endpoint_url = https://ec2.shelfcs.com

Region is hel1. Zone is hel1-a.

Terminal window
sc ec2 describe-instance-types # shapes
sc ec2 describe-images # operating systems
sc ec2 describe-availability-zones # hel1-a
sc ec2 describe-instances # what you have
sc ec2 describe-volumes
sc ec2 describe-security-groups
Terminal window
curl -s https://storefront.job-rss-processor.workers.dev/v1/catalog | jq # prices + live stock
Terminal window
sc ec2 import-key-pair --key-name mykey \
--public-key-material fileb://~/.ssh/id_ed25519.pub
sc ec2 describe-key-pairs
sc ec2 delete-key-pair --key-name mykey

Import your own. create-key-pair returns the private key once and never again.

Terminal window
sc ec2 run-instances \
--image-id ami-… \
--instance-type cd-standard-2-4 \
--key-name mykey \
--count 1 \
--client-token "$(uuidgen)" \
--tag-specifications 'ResourceType=instance,Tags=[{Key=Name,Value=web}]'
Terminal window
sc ec2 run-instances … --user-data file://cloud-init.yaml # ≤16384 bytes decoded

Always send --client-token: it makes a retry safe.

Terminal window
sc ec2 describe-instances --instance-ids i-… \
--query 'Reservations[].Instances[].[InstanceId,PrivateIpAddress,PublicIpAddress,State.Name]' \
--output table
ssh debian@<address> # NOT root@ — the user is set by the image
ImageUser
debian-12, debian-13debian
ubuntu-22.04, ubuntu-24.04ubuntu
rocky-9rocky
alma-9almalinux
fedora-42fedora
opensuse-leap-15.6opensuse
archarch
talos-v1.13.9none — no SSH

Cannot get in? The VNC console works before the network does.

Terminal window
sc ec2 stop-instances --instance-ids i-… # keeps the disk and the address
sc ec2 start-instances --instance-ids i-…
sc ec2 reboot-instances --instance-ids i-…
sc ec2 terminate-instances --instance-ids i-… # final; root disk goes with it
Terminal window
sc ec2 create-volume --availability-zone hel1-a --size 20 --volume-type standard
sc ec2 attach-volume --volume-id vol-… --instance-id i-… --device /dev/sdf
sc ec2 modify-volume --volume-id vol-… --size 40 # grows only, never shrinks
sc ec2 detach-volume --volume-id vol-… # unmount inside FIRST
sc ec2 delete-volume --volume-id vol-… # destroys the data
sc ec2 create-snapshot --volume-id vol-… --description "before upgrade"

--volume-type standard is required — the AWS default is gp2, which is rejected. There is one type, on 7200 rpm SATA.

Inside the guest:

Terminal window
lsblk
mkfs.ext4 /dev/vdb
blkid /dev/vdb
echo 'UUID=<uuid> /data ext4 defaults,nofail 0 2' >> /etc/fstab # nofail matters
mount -a
growpart /dev/vdb 1 && resize2fs /dev/vdb1 # after modify-volume
Terminal window
sc ec2 create-security-group --group-name web --description "http"
sc ec2 authorize-security-group-ingress --group-id sg-… \
--protocol tcp --port 443 --cidr 0.0.0.0/0
sc ec2 revoke-security-group-ingress --group-id sg-… \
--protocol tcp --port 443 --cidr 0.0.0.0/0

They are the only boundary inside your account — everything you run is on one flat 10.200.0.0/24.

provider "aws" {
region = "hel1"
skip_credentials_validation = true
skip_requesting_account_id = true
skip_metadata_api_check = true
endpoints { ec2 = "https://ec2.shelfcs.com" }
}
resource "aws_instance" "web" {
ami = data.aws_ami.debian.id
instance_type = "cd-standard-2-4" # write OUR name, not m5.large
key_name = aws_key_pair.mine.key_name
user_data = file("cloud-init.yaml")
}
resource "aws_ebs_volume" "data" {
availability_zone = "hel1-a"
size = 20
type = "standard" # the gp2 default is rejected
}
Terminal window
sc ec2 terminate-instances --instance-ids i-… --dry-run

DryRunOperation = permitted. UnauthorizedOperation = not.

ErrorFix
SignatureDoesNotMatchRegion. It is hel1
InsufficientInstanceCapacityBox is full. Smaller shape, or wait — quota will not help
InstanceLimitExceededYour quota. Starts at 4 vCPU / 8 GB
InvalidParameterValue on type=gp3One volume type, standard

Debugging a machine that booted but does not work

Section titled “Debugging a machine that booted but does not work”
Terminal window
cloud-init status --long
sudo journalctl -u cloud-final -b
sudo cat /var/log/cloud-init-output.log
# configuration is delivered on a drive, not over the network
mount /dev/disk/by-label/config-2 /mnt && cat /mnt/openstack/latest/user_data

runcmd swallows failures — a running instance is not a configured one.