Servers
EC2 instances
How AWS servers appear, and what each one needs before you can open it.
If your project is an AWS project, you don't type your EC2 servers in: we list the instances that already exist in your AWS account. They get the same health cards and table as any other server, and you can still add non-AWS servers by hand on the same page.
Listing instances
- The list shows one region at a time, starting with your project's region. Servers you added by hand show in every region.
- Pin keeps the current region as a button next to the dropdown, so a project spread over several regions switches with one click. Unpin removes it. Pins are yours alone; each teammate pins their own.
- Picking a region for the first time loads it from AWS by itself. After that it is cached and opens instantly; Refresh reads it from AWS again, and the page title shows when that last happened.
- Each EC2 card shows its State (Running, Stopped, Stopping…) with how long ago it was read, e.g. Running · 4 min ago. It isn't live: it is read from AWS on the same schedule as the other numbers (every 15 minutes, when you open the page, and with Check now). Running next to Can't connect usually means the security group or firewall is blocking SSH.
- The Dashboard and the background checks still cover every region.
- If a region cannot be listed, the reason is shown — usually a missing permission on the access key. See AWS permissions.
The list needs ec2:DescribeInstances. Listing does not require anything
to do with SSH.
Connecting to an instance
Listing an instance is not the same as being able to log into it. AWS does not
hold your private key — it gave you the .pem file once, when the instance was
created — so each instance needs its own login details before it can be opened.
Click Add SSH login on the instance's card (Owner and Admin only):
| Field | What to enter |
|---|---|
| Username | ubuntu for Ubuntu images, ec2-user for Amazon Linux, admin or debian for some Debian images, centos for CentOS |
| Private key (PEM) | The .pem file you downloaded when you created the instance |
Saved keys are encrypted at rest and never returned to a browser. See How we protect your credentials.
Once saved, the instance opens into the same workspace as any other server, and its first health check starts straight away. To use a different key later, click the key icon on its card; the bin icon removes the saved login (the instance itself stays listed).
If you lost the PEM file
AWS lets you download a key once. If it is gone it cannot be recovered, and you have two options:
- Attach a new key pair through the EC2 console (there is a documented procedure involving detaching the volume, or using EC2 Instance Connect / SSM), or
- Use your own existing key by adding its public half to
~/.ssh/authorized_keyson the instance through the AWS console, then give DevOps Agent the matching private key.
Before it will connect
Two things on the AWS side:
- The security group must allow inbound TCP 22 from the internet (or at least from our servers). This is the most common cause of "We couldn't reach the server".
- The instance needs a reachable address — a public IP or an Elastic IP. Instances on a private subnet with no public address cannot be reached directly.
Differences from hand-added servers
- Health checks need a saved login and a running instance. An instance without a login shows No SSH login; a stopped one shows Not running. Neither is checked, and neither is counted as a problem.
- The instance list comes from AWS, so renaming an instance is done in AWS, not here. The i icon on its card shows the AWS details (type, VPC, key pair).
- EC2 cards have no notes field yet.
