Getting started
Eight steps. About ten minutes, most of it waiting for a boot.
1. Sign up and verify your email
Section titled “1. Sign up and verify your email”Create an account on the site, then click the verification link. Onboarding refuses an unverified address, and that refusal is the single most common way to get stuck at step 2.
2. Become a customer of the cloud
Section titled “2. Become a customer of the cloud”Press Onboard in the console, or:
curl -X POST $BASE/v1/onboard \ -H "Authorization: Bearer $JWT" \ -H "Content-Type: application/json" \ -d '{"password":"<a password you use nowhere else>"}'This creates your project, your cloud user, your network, and your billing customer. It is idempotent — if it times out, run it again.
[!warning]
Choose that password carefully. It is used only on this first call, there is no reset endpoint yet, and it is stored in recoverable form so the console can be opened for you. Use a unique one and keep it in a password manager. See Credentials and trust.
3. Mint an access key
Section titled “3. Mint an access key”Console → Access keys → mint. Or:
curl -X POST $BASE/v1/access-keys -H "Authorization: Bearer $JWT"# { "access": "…", "secret": "…" }4. Point your tooling at the endpoint
Section titled “4. Point your tooling at the endpoint”export AWS_ACCESS_KEY_ID=…export AWS_SECRET_ACCESS_KEY=…alias sc='aws --endpoint-url https://ec2.shelfcs.com --region hel1'
sc ec2 describe-instance-types[!primary]
The region is
hel1. Get it wrong and every call returnsSignatureDoesNotMatchwith nothing in the message explaining why. This is the second place people get stuck.
5. Upload your SSH key
Section titled “5. Upload your SSH key”sc ec2 import-key-pair --key-name mykey \ --public-key-material fileb://~/.ssh/id_ed25519.pubImport your own rather than using create-key-pair, which returns a private key
once and never again.
6. Pick an image and a shape
Section titled “6. Pick an image and a shape”sc ec2 describe-images --filters Name=name,Values=debian-13sc ec2 describe-instance-typesA new account starts at 4 vCPU and 8 GB, so cd-standard-2-4 is a
comfortable first machine. AWS names work too — m5.large is exactly
cd-standard-2-8.
7. Launch
Section titled “7. Launch”sc ec2 run-instances \ --image-id ami-… \ --instance-type cd-standard-2-4 \ --key-name mykey \ --count 1 \ --client-token "$(uuidgen)" \ --tag-specifications 'ResourceType=instance,Tags=[{Key=Name,Value=first}]'Then wait for running:
sc ec2 describe-instances --instance-ids i-… \ --query 'Reservations[].Instances[].[InstanceId,State.Name,PrivateIpAddress,PublicIpAddress]' \ --output table8. Connect
Section titled “8. Connect”ssh debian@<address>[!warning]
Not
root@. The login user is set by the image, not by us:debian,ubuntu,rocky,almalinux,fedora,opensuse,arch. Using the wrong one gives a permission denied that looks exactly like a broken key. This is the third place people get stuck.
Add a disk
Section titled “Add a disk”sc ec2 create-volume --availability-zone hel1-a --size 20 --volume-type standardsc ec2 attach-volume --volume-id vol-… --instance-id i-… --device /dev/sdfThen inside the machine:
lsblksudo mkfs.ext4 /dev/vdbsudo mkdir -p /dataecho "UUID=$(sudo blkid -s UUID -o value /dev/vdb) /data ext4 defaults,nofail 0 2" | sudo tee -a /etc/fstabsudo mount -a--volume-type standard is required — the AWS default is gp2 and it is
rejected. nofail keeps a missing disk from making the machine unbootable.
Clean up
Section titled “Clean up”sc ec2 terminate-instances --instance-ids i-…sc ec2 delete-volume --volume-id vol-…Terminating destroys the root disk. The volume survives until you delete it, and deleting it destroys the data.
What to read next
Section titled “What to read next”| You want | Read |
|---|---|
| To understand what you just built | Compute user guide |
| To do it from code | Compute developer guide |
| Every command on one page | Cheat sheet |
| To know what the disk really is | Storage user guide |
| To know what it costs | Billing user guide |
| What one account can be divided into | Account user guide |
If it goes wrong
Section titled “If it goes wrong”| Symptom | Cause |
|---|---|
SignatureDoesNotMatch | The region. It is hel1 |
| Onboarding refuses | Email not verified |
Permission denied (publickey) | Wrong login user for that image |
InsufficientInstanceCapacity | The box is full. Smaller shape, or wait |
InstanceLimitExceeded | Your quota — 4 vCPU, 8 GB to start |
| Booted, but nothing works | cloud-init failed silently. Metadata and user data |
| Cannot SSH at all | Use the VNC console — it works before the network does |