Prev Next

Cloud / Amazon LightSail Interview questions

Last updated

1. What is Amazon Lightsail? 2. What are the key features of Amazon Lightsail? 3. Who should use Amazon Lightsail? 4. What is a Lightsail instance? 5. What are Lightsail blueprints? 6. What is a Lightsail bundle? 7. What are the types of Lightsail instance bundles? 8. What is a Lightsail static IP? 9. What are Lightsail snapshots? 10. What is a Lightsail managed database? 11. What are Lightsail containers? 12. What is a Lightsail load balancer? 13. What is a Lightsail CDN distribution? 14. What is Lightsail object storage? 15. What is a Lightsail block storage disk? 16. What is a Lightsail DNS zone? 17. How do you connect to a Lightsail instance? 18. How do you create a Lightsail instance? 19. What operating systems and applications does Lightsail support? 20. How do Lightsail firewall rules work? 21. What is the difference between Lightsail and EC2? 22. What is the difference between Lightsail and Elastic Beanstalk? 23. How does Lightsail pricing work? 24. How does the Lightsail data transfer allowance work? 25. What are the differences between dual-stack and IPv6-only networking in Lightsail? 26. Why should you attach a static IP to your Lightsail instance? 27. How do automatic snapshots work in Lightsail? 28. How do you restore a Lightsail instance from a snapshot? 29. How do you resize a Lightsail instance? 30. What is the difference between an instance snapshot and a disk snapshot? 31. How do you add more storage to a Lightsail instance? 32. How do you set up HTTPS on a Lightsail load balancer? 33. How does a Lightsail load balancer route traffic and check health? 34. How does a Lightsail CDN distribution reduce latency? 35. How do you deploy a container to Lightsail? 36. What are power and scale in a Lightsail container service? 37. How do you choose between the standard and high-availability database plan? 38. How do you connect a Lightsail instance to a managed database? 39. What is VPC peering in Lightsail and when should you use it? 40. How do backups and point-in-time restore work for Lightsail databases? 41. How do alarms and notifications work in Lightsail? 42. What is burst capacity in Lightsail and why does it matter? 43. How do you secure a Lightsail instance? 44. Why is IMDSv2 enforced on newer Lightsail blueprints? 45. How do you host a WordPress site on Lightsail? 46. How do you point a domain name at a Lightsail instance? 47. How do you troubleshoot an unreachable Lightsail instance? 48. How can you optimize Lightsail costs? 49. How can you automate Lightsail with the AWS CLI? 50. When should you migrate from Lightsail to EC2, and how?

1. What is Amazon Lightsail?

Amazon Lightsail is an AWS service that gives you a virtual private server (VPS) with the supporting pieces already bundled: SSD storage, a monthly data transfer allowance, a static IP option, DNS, and a simple console. You pick an operating system or app, pick a size, and the server is running in a couple of minutes.

It targets people who want AWS reliability without learning VPC design, security groups, EBS volume types, and instance families first. Pricing is a flat monthly figure per bundle, so the bill is easy to predict.

Beyond servers, Lightsail also offers containers, managed MySQL/PostgreSQL databases, load balancers, CDN distributions, and object storage buckets.

Take quiz
Amazon Lightsail is best described as:
a managed Kubernetes control plane only
a serverless function runtime billed per request
a simplified VPS service with bundled storage and data transfer
How is a typical Lightsail instance priced?
Per-request pricing like Lambda
Free forever with no limits
Only by the GB of RAM used each second
A flat monthly bundle price covering compute, SSD, and transfer

2. What are the key features of Amazon Lightsail?

Lightsail packs the common building blocks of a small web workload into one console:

  • Instances with preconfigured OS and application blueprints
  • Containers through a managed container service
  • Managed databases for MySQL and PostgreSQL
  • Load balancers with free TLS certificates
  • CDN distributions for caching static and dynamic content
  • Object storage buckets and attachable block storage disks
  • Static IPs, DNS zones, snapshots, alarms, and firewall rules

Everything is also reachable through the AWS CLI, SDKs, and CloudFormation, so you are not limited to clicking in the console.

Take quiz
Which of these is a Lightsail feature?
A managed Oracle RAC cluster
A serverless GPU training service
A built-in data warehouse
Managed MySQL and PostgreSQL databases
Which Lightsail resource caches content closer to end users?
A CDN distribution
A DNS zone
A static IP
A block storage disk

3. Who should use Amazon Lightsail?

Lightsail suits developers, small businesses, students, and agencies who need a simple, low-cost server and do not want to manage a large AWS architecture. Typical workloads are blogs, WordPress and Magento sites, small web apps, dev and test environments, and hobby projects.

It is also a sensible first step into AWS. You can start small, and later connect to other AWS services or move to EC2 when needs grow.

It is a weaker fit for workloads that need auto scaling groups, custom VPC layouts, specialized instance families, or fine-grained IAM integration. Those belong on EC2 or container services built for scale.

Take quiz
Which workload is the best match for Lightsail?
A small WordPress site with predictable traffic
A multi-account landing zone
A fleet needing auto scaling across hundreds of nodes
A GPU cluster for large model training
Why might a team outgrow Lightsail?
Lightsail only works in one country
They need auto scaling and custom VPC design
Lightsail cannot run Linux
Lightsail has no firewall

4. What is a Lightsail instance?

A Lightsail instance is a virtual private server running in an AWS Region and Availability Zone you choose. It is created from a blueprint (the OS or app image) and a bundle (the size and price plan).

Each instance has a private IP, a public IP, a SSD system disk, and its own firewall rules. You manage it with SSH for Linux or RDP for Windows, either from your own client or from the browser-based client in the console.

Instances can be stopped, started, rebooted, snapshotted, and resized by building a new instance from a snapshot.

Take quiz
What two choices define a new Lightsail instance?
An AMI ID and an IAM role
A blueprint and a bundle
A cluster and a task definition
A VPC and a subnet
Which client can you use directly in the console to reach a Linux instance?
Only a Telnet client
Only the AWS Systems Manager console
A browser-based SSH client
A browser-based RDP client only

5. What are Lightsail blueprints?

A blueprint is the software image Lightsail installs on a new instance. There are two kinds:

  1. OS only - for example Amazon Linux, Ubuntu, Debian, AlmaLinux, CentOS, and Windows Server
  2. Apps + OS - WordPress, LAMP, Node.js, MEAN, Ruby on Rails, Drupal, Magento, cPanel & WHM, Plesk, and others

App blueprints save setup time because the stack is installed and configured at first boot. In January 2026 AWS refreshed the Node.js, LAMP, and Ruby on Rails blueprints and enforced IMDSv2 on them by default.

Take quiz
Which is an Apps + OS blueprint?
A DNS zone
A VPC peering connection
WordPress
A static IP
What changed in the refreshed Node.js, LAMP, and Ruby on Rails blueprints?
They drop IPv6 support
They now run only on Windows
They require a load balancer
IMDSv2 is enforced by default

6. What is a Lightsail bundle?

A bundle is a prepackaged plan that sets the instance size and price. Each bundle fixes the number of vCPUs, the memory, the SSD size, and the monthly data transfer allowance.

Bundles are billed hourly but capped at the monthly price, so running an instance all month costs the listed monthly amount. Bundles come in different networking types too: dual-stack (IPv4 + IPv6) and IPv6-only, with IPv6-only generally cheaper.

You cannot tweak a single value, such as adding only RAM. To change size you move to a different bundle.

Take quiz
What does a Lightsail bundle fix?
Only the Availability Zone
Only the AWS account ID
Only the operating system
vCPU, memory, SSD, and a data transfer allowance
Can you add only extra RAM to an existing bundle?
No, you move to a different bundle
Yes, with a slider in the console
Yes, by attaching a RAM disk
Yes, through a free CLI flag

7. What are the types of Lightsail instance bundles?

Lightsail groups instance bundles by workload profile:

Type Best for
General purpose Web servers, blogs, small apps, dev and test
Compute-optimized CPU-heavy jobs such as batch processing, video encoding, game servers
Memory-optimized In-memory caches, analytics, and memory-hungry applications

Compute-optimized bundles were added in April 2026 and scale up to 72 vCPUs in seven sizes, with IPv6-only and dual-stack options. They support all Lightsail blueprints, Windows included.

Pick general purpose first. Move to compute-optimized or memory-optimized only when metrics show sustained CPU or memory pressure, since larger specialized bundles cost more.

Take quiz
Which bundle type fits video encoding best?
Compute-optimized
A static IP bundle
A DNS bundle
General purpose with the smallest size
How many vCPUs can the largest compute-optimized bundle reach?
8
72
512
16

8. What is a Lightsail static IP?

A static IP is a fixed public IPv4 address you reserve and attach to an instance. Without it, an instance's public IP can change when you stop and start it.

Attach a static IP before you create DNS records, so your domain keeps pointing at the right server. It stays with the instance across stop/start cycles, and you can detach it and attach it to a replacement instance.

A static IP is free while attached to a running resource. If you leave it unattached, AWS charges for it, so release it when you no longer need it.

Take quiz
Why attach a static IP before creating DNS records?
It makes the instance faster
The default public IP can change after stop/start
It removes the firewall
It enables automatic snapshots
What happens if a static IP stays unattached?
It attaches to a random instance
It is deleted at midnight
You are charged for it
It is free forever

9. What are Lightsail snapshots?

A snapshot is a point-in-time backup of a Lightsail resource. You can snapshot instances, block storage disks, and managed databases.

Instance snapshots capture the system disk and attached disks. You can use one to launch a copy of the instance, even in a different Availability Zone or Region, or to upgrade to a larger bundle.

Snapshots are stored in AWS and billed per GB-month. You can create them manually before risky changes or let Lightsail create them automatically each day.

Take quiz
Which can a new instance be launched from?
A firewall rule
A DNS zone
An instance snapshot
A CDN origin
How are snapshots billed?
Per vCPU hour
They are never billed
Only when you restore
Per GB-month of stored data

10. What is a Lightsail managed database?

A Lightsail managed database is a MySQL or PostgreSQL database that Lightsail provisions, patches, and backs up for you. You choose a bundle with set vCPU, memory, storage, and transfer, then connect with the endpoint, port, and master credentials.

It comes in two plans: standard (one Availability Zone) and high availability (a standby in another zone with automatic failover). In January 2026 AWS added two larger bundles, up to 8 vCPUs, 32 GB of memory, and 960 GB of SSD.

Automatic backups and point-in-time restore are built in.

Take quiz
Which engines does a Lightsail managed database support?
Oracle and SQL Server
Redis and DynamoDB
MongoDB and Cassandra
MySQL and PostgreSQL
What does the high-availability plan add?
A standby in another Availability Zone with failover
Unlimited storage
A free CDN
Support for Windows hosts

11. What are Lightsail containers?

The Lightsail container service lets you run Docker containers without managing servers. You create a service, choose a power (CPU and memory per node) and a scale (number of nodes), then deploy one or more containers.

The service provides a public HTTPS endpoint with a default domain, and you can attach your own domain and certificate. Images can come from public registries, from private Amazon ECR repositories, or be pushed from your machine with the Lightsail Control (lightsailctl) plugin.

Each deployment is versioned, and failed deployments can be rolled back to the last working one.

Take quiz
Which two settings size a Lightsail container service?
Power and scale
Region and VPC
vCPU credits and burst bucket
Cluster and task definition
Which tool pushes a local image to a Lightsail container service?
The EC2 Image Builder
The Lightsail Control (lightsailctl) plugin
AWS DataSync
Amazon Inspector

12. What is a Lightsail load balancer?

A Lightsail load balancer spreads incoming HTTP and HTTPS traffic across several instances in the same Region. It performs health checks and sends requests only to healthy targets.

It terminates TLS using free certificates you create in Lightsail, can redirect HTTP to HTTPS, and supports optional session persistence through cookies.

It improves availability and lets you scale horizontally by adding instances. Note that it works at the application layer, so it is not a general TCP load balancer.

Instances must sit in the same Region as the balancer, and you can attach several of them at once. Removing one for maintenance does not interrupt visitors.

Take quiz
What traffic can a Lightsail load balancer handle?
Only SMTP
HTTP and HTTPS
Only raw UDP
Only SSH
What does the load balancer do with an unhealthy instance?
Restarts the whole Region
Deletes it automatically
Stops sending traffic to it
Resizes it to a larger bundle

13. What is a Lightsail CDN distribution?

A Lightsail CDN distribution is a content delivery network, powered by Amazon CloudFront, that caches your content at edge locations around the world. Visitors are served from a location near them, which lowers latency and reduces load on the origin.

Supported origins are Lightsail instances, container services, buckets, and load balancers. In May 2026, IPv6-only instances were added as supported origins too.

Each distribution includes a monthly transfer allowance, and you can attach a custom domain with a certificate.

You choose what gets cached: everything, static files only, or nothing. That lets images and scripts load fast while dynamic pages still reach the origin on every request.

Take quiz
What technology powers Lightsail distributions?
AWS Global Accelerator only
AWS Direct Connect
Amazon CloudFront
Amazon Route 53 Resolver
Which can be a distribution origin?
A DynamoDB table
A local laptop
An Amazon Glacier vault
A Lightsail bucket

14. What is Lightsail object storage?

Lightsail object storage gives you buckets that store files such as images, backups, and static site assets. A bucket plan bundles a set amount of storage and data transfer for a flat monthly price.

Buckets are private by default. You can make objects public read-only, grant access to specific Lightsail instances, or create access keys for programmatic use. Versioning protects against accidental overwrites.

The API is S3-compatible, so common tools and SDKs work. A bucket can also be a CDN origin for faster global delivery.

Take quiz
What is the default access level of a new bucket?
Open to all AWS accounts
Public read and write
Only visible from one IP
Private
Which API style do Lightsail buckets follow?
S3-compatible
SOAP only
Kafka protocol
GraphQL only

15. What is a Lightsail block storage disk?

A block storage disk is extra SSD storage you attach to an instance, like adding a second drive. Disks are useful when the system disk is too small or when data should live apart from the OS.

Key points:

  • A disk must be in the same Availability Zone as the instance.
  • Up to 16 TB per disk, and up to 15 disks per instance.
  • On Linux you must format and mount it yourself before use.
  • Disks can be snapshotted and detached, then reattached elsewhere.
Take quiz
What must be true for a disk to attach to an instance?
Both are in the same Availability Zone
Both have static IPs
Both belong to a load balancer
Both use the same blueprint
What must you do on Linux after attaching a new disk?
Nothing, it mounts automatically
Format and mount it
Reboot the AWS Region
Recreate the instance

16. What is a Lightsail DNS zone?

A DNS zone holds the DNS records for a domain you own, such as A, AAAA, CNAME, MX, and TXT records. Lightsail hosts the zone on its own name servers, at no extra charge.

After creating the zone, you update your registrar's name servers to the four Lightsail values. Then you add records, for example an A record pointing the domain at a static IP, or MX records for email.

You can also register a domain directly from Lightsail, and the service can create the zone for you.

Take quiz
What do you change at your registrar to use a Lightsail DNS zone?
The SSH key
The domain's name servers
The bundle size
The instance blueprint
Which record points a domain at a static IPv4 address?
An SOA record
A TXT record
An A record
An MX record

17. How do you connect to a Lightsail instance?

The quickest route is the browser-based SSH or RDP client in the console. For a terminal, download the default key pair for the Region and run SSH with the right username:

chmod 400 LightsailDefaultKey-us-east-1.pem
ssh -i LightsailDefaultKey-us-east-1.pem ubuntu@203.0.113.10

The username depends on the image: ubuntu on Ubuntu, ec2-user on Amazon Linux, admin on Debian, and bitnami on Bitnami-based app blueprints.

Windows instances use RDP: you retrieve the administrator password from the console, then connect on port 3389. Make sure the firewall allows SSH (22) or RDP (3389) from your IP.

Take quiz
Which username applies to an Ubuntu blueprint?
lightsail-admin
root only
ubuntu
ec2-user
Which port must be open for RDP to a Windows instance?
5432
443
22
3389

18. How do you create a Lightsail instance?

In the console, choose Create instance and follow these steps:

  1. Select the AWS Region and Availability Zone.
  2. Pick the platform (Linux/Unix or Windows) and a blueprint.
  3. Optionally add a launch script that runs at first boot.
  4. Choose or upload an SSH key pair.
  5. Choose the networking type (dual-stack or IPv6-only).
  6. Select a bundle, name the instance, and click create.

The same task from the CLI:

aws lightsail create-instances \
  --instance-names web-1 \
  --availability-zone us-east-1a \
  --blueprint-id ubuntu_24_04 \
  --bundle-id nano_3_0

Run aws lightsail get-blueprints and get-bundles to list valid IDs.

Take quiz
What does a launch script do?
Changes the bundle size
Creates a DNS zone
Backs up the instance nightly
Runs commands automatically at first boot
Which CLI command lists valid blueprint IDs?
aws lightsail get-blueprints
aws lightsail show-os
aws lightsail list-images
aws ec2 describe-amis

19. What operating systems and applications does Lightsail support?

Lightsail offers Linux and Windows images. Linux options include Amazon Linux, Ubuntu, Debian, AlmaLinux, CentOS, and others, while Windows Server images are available for .NET and other Windows workloads.

On top of those are application blueprints such as WordPress, LAMP, Node.js, MEAN, Ruby on Rails, Drupal, Magento, cPanel & WHM, and Plesk.

The available list changes over time as images are added or retired, so check the blueprint list in your Region before planning a deployment. Compute-optimized bundles support all of them.

Take quiz
Which is available as an application blueprint?
Magento
Hadoop on EMR
SAP HANA
Oracle Exadata
Where should you check for the current blueprint list?
Only the AWS billing page
The Lightsail console or get-blueprints in your Region
A third-party blog
The EC2 AMI marketplace

20. How do Lightsail firewall rules work?

Every instance has its own firewall that controls inbound traffic by protocol, port, and source. Rules only allow traffic. There are no deny rules, so anything not allowed is blocked.

New Linux instances open SSH (22) and HTTP (80). Windows instances open RDP (3389) and HTTP (80). You add rules for HTTPS (443), databases, or custom ports.

Good habits:

  • Restrict SSH and RDP to your own IP address.
  • Manage IPv4 and IPv6 rules separately, since both lists apply.
  • Remember that the OS firewall (ufw, iptables, Windows Firewall) is a second layer.
Take quiz
What kinds of rules does the Lightsail firewall support?
Rules based on username
Allow rules only
Both allow and explicit deny
Deny rules only
What is a good way to harden SSH access?
Use port 22 for HTTP too
Disable the firewall
Limit port 22 to your own IP address
Open port 22 to everyone

21. What is the difference between Lightsail and EC2?

Lightsail trades flexibility for simplicity. You pick from fixed bundles with predictable monthly prices, while EC2 exposes the full AWS toolbox and you assemble and pay for each piece.

Aspect Lightsail EC2
Pricing Flat monthly bundle incl. SSD and transfer Per-second compute plus separate EBS, IP, and transfer
Instance choice Limited set of bundles Hundreds of instance types
Networking Simple, Lightsail-managed VPC Full VPC, subnets, route tables, security groups
Scaling Manual, or add instances behind a load balancer Auto Scaling groups, spot, savings plans
Identity No instance IAM roles Instance profiles with IAM roles
Setup effort Minutes, minimal AWS knowledge More design and configuration

Use Lightsail for small, steady workloads. Choose EC2 when you need fine control, advanced networking, or elasticity.

Take quiz
Which feature is available on EC2 but not on Lightsail instances?
Firewall rules
Static IP addresses
Auto Scaling groups
Snapshots
Which service gives the most predictable monthly bill for a small server?
AWS Outposts
EC2 spot with no limits
AWS Snowball
Lightsail

22. What is the difference between Lightsail and Elastic Beanstalk?

Both aim to ease deployment, but they work differently. Elastic Beanstalk orchestrates standard AWS resources (EC2, Auto Scaling, load balancer) for an application you upload, and you pay for those resources individually. Lightsail gives you a server or container service with a bundled flat price, and you manage the app yourself.

Point Lightsail Elastic Beanstalk
Model VPS or container service Platform that provisions AWS resources
Scaling Manual or via load balancer Built-in auto scaling
Billing Flat bundle price Pay for underlying EC2, ELB, etc.
Best for Simple sites, small apps Apps that need elasticity without managing infrastructure

If the app must grow and shrink automatically, Beanstalk fits better. For one predictable site, Lightsail is simpler and often cheaper.

Take quiz
What does Elastic Beanstalk create for you?
A flat-price VPS bundle only
A DNS zone only
A managed mainframe
Standard AWS resources like EC2, scaling, and load balancing
Which fits a single predictable small site better?
Lightsail
Elastic Beanstalk with auto scaling
AWS Batch
Amazon EMR

23. How does Lightsail pricing work?

Instances are sold as bundles with a flat monthly price that already includes compute, SSD storage, and a data transfer allowance. Billing is hourly but capped at the monthly price.

Other resources are priced on their own:

  • Load balancers, CDN distributions, and container services have fixed monthly plans.
  • Managed databases use bundles with included storage and transfer.
  • Extra block storage disks and snapshots are billed per GB-month.
  • Unattached static IPs and data transfer beyond the allowance are charged.

A key gotcha: a stopped instance still bills. To stop paying, delete the resource. New customers can often use a free trial on selected bundles, so verify the current offer on the pricing page.

Take quiz
Do you stop paying for an instance when you only stop it?
No, billing continues until you delete it
Billing moves to a free tier
Only compute stops billing
Yes, billing stops immediately
Which items are billed separately from the instance bundle?
The default firewall
Extra disks and snapshots
The included transfer allowance
The bundled SSD

24. How does the Lightsail data transfer allowance work?

Each bundle includes a monthly outbound data transfer allowance. Inbound traffic is free. The allowances from your instances in the account are pooled, so one quiet server can cover for a busy one.

When total outbound traffic passes the pooled allowance, the excess is billed per GB at the rate on the pricing page. Traffic between Lightsail resources over private IPs in the same Region does not count against it.

To keep transfer under control:

  1. Put static files in a bucket behind a CDN distribution.
  2. Set up a network-out alarm so you hear about spikes.
  3. Compress responses and cache aggressively.
Take quiz
Which direction of traffic is free?
Outbound only
Inbound
Both directions are free
Neither direction
Which action helps reduce outbound transfer?
Disabling snapshots
Opening more firewall ports
Serving static files through a CDN distribution
Using a larger static IP

25. What are the differences between dual-stack and IPv6-only networking in Lightsail?

Dual-stack instances get both a public IPv4 and an IPv6 address, so any client can reach them. IPv6-only instances have no public IPv4 address, which lowers the bundle price.

Feature Dual-stack IPv6-only
Public addresses IPv4 + IPv6 IPv6 only
Reachable by IPv4-only clients Yes, directly Not directly
Price Higher Lower
Static IPv4 option Yes Not applicable

If you want IPv6-only savings but still serve visitors on IPv4-only networks, put a Lightsail CDN distribution in front. Since May 2026 distributions accept IPv6-only instances as origins and translate for those visitors.

Take quiz
What lowers the price of an IPv6-only bundle?
It has no firewall
It cannot run Linux
No public IPv4 address is included
It has no SSD
How can IPv4-only visitors reach a site on an IPv6-only instance?
By attaching a block storage disk
By renaming the instance
They cannot, ever
Through a CDN distribution in front of it

26. Why should you attach a static IP to your Lightsail instance?

The default public IP is tied to the running instance and can change after a stop/start. Any DNS record, allowlist, or third-party integration that uses the old address then breaks.

A static IP fixes this in three ways:

  • The address survives stop/start cycles.
  • You can move it to a new instance during a rebuild or resize, with no DNS change.
  • Partners can safely allowlist it.

Create the static IP in the same Region, attach it to the instance, then use it in your A record. Remember to release it if you delete the instance, since an unattached static IP is charged.

Take quiz
What problem does a static IP solve?
Slow disk performance
Missing snapshots
Low CPU credits
The public IP changing after stop/start
What should you do when deleting the instance a static IP is attached to?
Release the static IP too
Convert it to a DNS zone
Keep it unattached to save money
Nothing, it self-deletes

27. How do automatic snapshots work in Lightsail?

When you enable automatic snapshots on an instance or a disk, Lightsail takes one snapshot per day at the time you choose. It keeps the seven most recent daily copies and deletes older ones.

The first automatic snapshot appears shortly after you enable the feature, then follows the daily schedule. You can restore from any retained copy, or create a new instance from it.

Important limits:

  • Automatic snapshots expire; copy one to a manual snapshot to keep it long term.
  • They are billed like regular snapshot storage.
  • They protect against loss of the instance, but do not replace application-level or database-level backups.
Take quiz
How many daily automatic snapshots does Lightsail keep?
The seven most recent
Thirty
All of them forever
Only the latest one
How do you keep an automatic snapshot beyond its retention?
Disable the firewall
Copy it to a manual snapshot
Attach a static IP
Rename the instance

28. How do you restore a Lightsail instance from a snapshot?

Lightsail does not overwrite the running server. You create a new instance from the snapshot, which gives a clean copy of the saved state.

  1. Open the snapshot in the console and choose Create new instance.
  2. Pick the Region, Availability Zone, and a bundle the same size or larger.
  3. Name it, create it, and test it.
  4. Move the static IP from the old instance to the new one.
  5. Delete the old instance once you are satisfied.

Since the new instance gets a new private IP and possibly a new public IP, update anything that referenced the old addresses.

Take quiz
How does Lightsail restore an instance from a snapshot?
By overwriting the running instance in place
By creating a new instance from it
By restarting the Region
By replaying CloudTrail logs
What should you move to the new instance after restoring?
The old snapshot
The bundle price
The static IP
The SSH username

29. How do you resize a Lightsail instance?

Lightsail has no in-place resize. You build a bigger copy from a snapshot and swap over.

flowchart LR
A["Running instance"] --> B["Create snapshot"]
B --> C["New instance from snapshot with larger bundle"]
C --> D["Move static IP"]
D --> E["Test, then delete old instance"]

Steps:

  1. Take a snapshot of the current instance.
  2. Create a new instance from it and pick a larger bundle.
  3. Reattach the static IP, or update DNS.
  4. Verify the app, then delete the old instance.

You can move to the same size or larger, but not to a smaller bundle. To downsize, build a fresh smaller instance and migrate the data manually. Schedule a short maintenance window, since data written after the snapshot is not copied.

Take quiz
Can you shrink an instance to a smaller bundle by restoring a snapshot?
Yes, to any smaller bundle
Yes, with a free CLI flag
No, only same or larger bundles are allowed
Yes, but only on Fridays
What risk exists between taking the snapshot and cutover?
The static IP is lost forever
The Region changes
The OS changes to Windows
Data written after the snapshot is not copied

30. What is the difference between an instance snapshot and a disk snapshot?

An instance snapshot captures the system disk and any attached disks, so you can recreate the full server. A disk snapshot captures a single block storage disk.

Point Instance snapshot Disk snapshot
Scope Whole server, incl. attached disks One disk only
Restore as A new instance A new disk
Typical use Cloning, resizing, migrating Backing up data volumes

Use instance snapshots for cloning and resizing. Use disk snapshots when the data disk needs its own backup schedule or must be attached to a different instance.

Take quiz
What does a disk snapshot restore into?
A new CDN distribution
A new DNS zone
A new load balancer
A new block storage disk
Which snapshot type is better for cloning a whole server?
Instance snapshot
Disk snapshot
Bucket snapshot
DNS snapshot

31. How do you add more storage to a Lightsail instance?

Attach a block storage disk. It is the easiest way to add space without changing the bundle.

  1. Create a disk in the same Availability Zone as the instance.
  2. Attach it to the instance in the console or CLI.
  3. Connect over SSH, find the device, format it, and mount it.
  4. Add an entry to /etc/fstab so it mounts after reboot.
lsblk
sudo mkfs -t ext4 /dev/nvme1n1
sudo mkdir /data
sudo mount /dev/nvme1n1 /data

Device names vary, so confirm with lsblk before formatting. Formatting the wrong device destroys data. For files that do not need a filesystem, a bucket is cheaper.

Take quiz
Which tool shows the attached device name on Linux?
lsblk
nslookup
traceroute
ping
Where must the disk be created relative to the instance?
Any Region
The same Availability Zone
A different Availability Zone
Inside a DNS zone

32. How do you set up HTTPS on a Lightsail load balancer?

Lightsail issues free TLS certificates for load balancers. The process uses DNS validation:

  1. Create a certificate for your domain in the load balancer's Inbound traffic tab.
  2. Add the CNAME validation records that Lightsail shows to your DNS zone.
  3. Wait until the certificate status becomes valid.
  4. Attach it, then enable the HTTPS redirect if you want HTTP to forward to HTTPS.

Certificates renew automatically as long as the validation record stays in DNS. Do not delete it. Backend instances can still speak plain HTTP behind the load balancer, because TLS ends at the balancer.

Take quiz
How is domain ownership validated for a Lightsail certificate?
By uploading a PDF
By adding DNS validation records
By buying a static IP
By emailing AWS support
Where does TLS terminate in this setup?
Inside the SSD
At the firewall of the user's laptop
At the load balancer
At the DNS registrar

33. How does a Lightsail load balancer route traffic and check health?

The balancer sends each request to one of the attached healthy instances using a round-robin style approach. Health is decided by a health check on a path you set, such as /health. An instance that fails repeatedly is removed from rotation until it passes again.

Points to configure:

  • Health check path - return HTTP 200 only when the app is truly ready.
  • Session persistence - cookie-based stickiness, useful when sessions live in memory.
  • Instances - up to 20 per balancer, in the same Region.

Prefer keeping session state outside the servers, for example in a managed database, so any instance can serve any request.

Take quiz
What happens when an instance keeps failing its health check?
It is deleted
Traffic doubles to it
It is taken out of rotation
It is resized automatically
Why avoid relying on sticky sessions?
Sticky sessions are not supported on Linux
They remove the health check
They disable HTTPS
Session state outside the servers lets any instance serve any request

34. How does a Lightsail CDN distribution reduce latency?

A distribution places copies of your content at edge locations. A visitor's request reaches the nearest edge. On a cache hit it is answered right there. On a miss, the edge fetches from your origin, stores the result, and serves it.

sequenceDiagram
participant U as Visitor
participant E as Edge location
participant O as Origin
U->>E: Request
alt Cache hit
E-->>U: Cached response
else Cache miss
E->>O: Fetch
O-->>E: Response
E-->>U: Response, now cached
end

You control behavior with cache settings: cache everything, cache only static files, or cache nothing for dynamic paths. Use per-path behaviors so images are cached for a long time while the login page is not. For HTTPS on a custom domain, attach a certificate to the distribution.

Take quiz
What happens on a cache miss?
The visitor sees a 404 always
The DNS zone is deleted
The request is dropped
The edge fetches from the origin and caches it
Which content should usually not be cached?
Personalized or login pages
Static JavaScript
Product images
CSS files

35. How do you deploy a container to Lightsail?

You create a container service, then submit a deployment that describes the containers and the public endpoint.

  1. Create the service and pick its power and scale.
  2. Build the image locally and push it with lightsailctl.
  3. Create a deployment: image, ports, environment variables, and the container that receives public traffic.
  4. Set the health check path, then deploy.
aws lightsail push-container-image \
  --service-name my-app \
  --label web \
  --image my-app:latest

The command returns an image reference such as :my-app.web.1, which you use in the deployment. Lightsail launches the new version, waits for health checks, and then switches traffic. If it fails, the previous deployment stays active.

Take quiz
Which component receives the public traffic in a deployment?
The container you mark as the public endpoint
The block storage disk
The DNS zone
Every container always
What happens if a new deployment fails its health checks?
All data is erased
The previous deployment stays active
The Region changes
The service is deleted

36. What are power and scale in a Lightsail container service?

Power sets the CPU and memory of each node, ranging from nano to xlarge. Scale sets how many nodes run, from 1 up to 20.

Total capacity is power multiplied by scale, and the monthly price follows the same product. For example, a medium power service at scale 3 costs three times the price of a single medium node.

Changing either value triggers a new deployment. Raise power when one container needs more memory or CPU. Raise scale for more concurrency and redundancy across nodes. Lightsail does not auto scale, so you adjust these values yourself, based on metrics.

Take quiz
What does the scale setting control?
The TLS version
How many nodes run
The Region
The CPU of each node only
Which action gives one container more memory?
Attach a static IP
Raise the number of DNS records
Raise power
Lower scale to zero

37. How do you choose between the standard and high-availability database plan?

The standard plan runs one database node in a single Availability Zone. If that zone has a problem, the database is unavailable until it recovers. The high-availability plan adds a standby in a second zone and fails over automatically.

Question Standard High availability
Zones used One Two
Failover Manual recovery Automatic
Cost Lower Higher
Good for Dev, test, low-risk apps Production, revenue-critical apps

Use HA when downtime costs more than the extra monthly price, such as for stores and SaaS products. Both plans keep automatic backups, so HA is about availability rather than backup safety.

Take quiz
What does the HA plan place in a second zone?
A copy of the bucket
The DNS zone
A standby database node
The SSH key
Which environment is a natural fit for the standard plan?
A busy online store
A hospital records system
A payments system
A development or test database

38. How do you connect a Lightsail instance to a managed database?

Both must be in the same Region. Take the database endpoint, port, and master credentials from the database's Connect tab, then use them from the instance.

mysql -h ls-abc123.xyz.us-east-1.rds.amazonaws.com \
  -P 3306 -u dbmasteruser -p

Lightsail databases are reachable from instances in your Lightsail VPC over the private network. That is the setup to prefer, because the database never touches the public internet.

Public mode opens the endpoint to outside clients, such as your laptop or a service in another cloud. Turn it on only when needed and for short periods, and combine it with strong passwords. The default ports are 3306 for MySQL and 5432 for PostgreSQL.

Take quiz
What does public mode on a Lightsail database allow?
Windows authentication
Free unlimited storage
Automatic cross-Region failover
Connections from outside the Lightsail VPC
Which default port does PostgreSQL use?
5432
27017
3306
1433

39. What is VPC peering in Lightsail and when should you use it?

VPC peering creates a private network link between the Lightsail VPC and the default Amazon VPC in the same AWS Region. Resources then talk over private IPs, not the public internet.

Use it when a Lightsail instance needs to reach services running in your regular AWS account, such as an EC2 server, an RDS database, or an internal API.

To use it:

  1. Enable VPC peering for the Region in the Lightsail account settings (Advanced).
  2. Update security groups and firewall rules so the traffic is allowed.
  3. Connect using private IP addresses.

Peering is per Region and not transitive. It reaches the default VPC, not every custom VPC.

Take quiz
What does Lightsail VPC peering connect?
The Lightsail VPC and the default Amazon VPC in the same Region
Two Lightsail buckets
A CDN and a snapshot
Two DNS zones
What kind of IPs carry peered traffic?
Only public IPv4 addresses
Private IP addresses
Only static IPs
Email addresses

40. How do backups and point-in-time restore work for Lightsail databases?

Lightsail takes automatic daily backups of a managed database and keeps transaction logs, which enables point-in-time restore to any moment within the retention window, normally seven days.

A restore never overwrites the original. It creates a new database from the chosen time, and you then point your application at the new endpoint.

For longer retention, create manual snapshots, which stay until you delete them. Take one before a risky schema change or major version upgrade.

Test restores regularly. Also remember that a restore gives a new endpoint, so keep connection strings in config rather than hard-coded.

Take quiz
What does a point-in-time restore create?
A new static IP
A new database
A new SSH key
A new Region
Which backup type stays until you delete it?
A DNS cache entry
A CDN edge copy
A manual snapshot
An automatic backup after its retention

41. How do alarms and notifications work in Lightsail?

Lightsail metric alarms watch a metric and notify you when it crosses a threshold. For instances, you can alarm on CPU utilization, network in and out, status check failures, and burst capacity.

Setup:

  1. Add a notification contact by email or, in supported Regions, SMS, and verify it.
  2. Choose the resource and metric.
  3. Set the comparison, threshold, and number of data points.
  4. Decide how missing data should be treated.

Databases, load balancers, and container services also expose metrics you can alarm on. Pick thresholds from observed baselines, not guesses, so alerts stay meaningful instead of noisy.

Take quiz
Which metric can raise an instance alarm?
Blueprint version
Domain registration date
Status check failed
Number of DNS zones
What must happen before a notification contact receives alerts?
It must run on a bucket
It must be a Linux user
It must own a static IP
It must be verified

42. What is burst capacity in Lightsail and why does it matter?

General-purpose Lightsail instances are burstable. Each one has a baseline CPU level it can sustain, and it can go above that for a while using stored burst capacity. When the capacity runs out, the CPU is throttled to the baseline.

That is why a site can feel fine for weeks, then slow down after a traffic spike or a heavy cron job. The instance is not broken. It has spent its burst.

Watch the burst capacity percentage and burst capacity time metrics and set alarms on them. If capacity stays low, move to a larger bundle, or to a compute-optimized bundle, which offers dedicated CPU performance.

Take quiz
What happens when burst capacity is exhausted?
The Region changes
The instance is deleted
The static IP is released
CPU is limited to the baseline
What is a sensible response to constantly low burst capacity?
Move to a larger or compute-optimized bundle
Disable the firewall
Rename the instance
Add a DNS zone

43. How do you secure a Lightsail instance?

Start with the network, then the OS, then the application:

  • Firewall: open only needed ports and restrict SSH or RDP to trusted IPs.
  • SSH keys: use key authentication, disable password login, and avoid sharing the default key.
  • Patching: apply OS updates regularly and keep apps like WordPress and plugins current.
  • IMDSv2: require token-based metadata access to limit SSRF damage.
  • HTTPS: use TLS through a load balancer certificate or on the server.
  • Backups: enable automatic snapshots and test restores.
  • Databases: keep public mode off unless you need it.

Add alarms for unusual CPU and network use, since a compromised server often shows up as odd traffic.

Take quiz
What is the safest SSH access practice?
Restrict port 22 to trusted IPs and use keys
Allow all IPs with a simple password
Disable the firewall for convenience
Share one private key in chat
Why watch network and CPU alarms for security?
They rotate SSH keys automatically
A compromised server often shows unusual usage
They encrypt data at rest
They patch the OS

44. Why is IMDSv2 enforced on newer Lightsail blueprints?

The Instance Metadata Service at 169.254.169.254 lets software on the instance read details about itself. With version 1, a simple GET request is enough. That makes it a target for SSRF attacks, where a flaw in the app tricks the server into fetching the metadata URL and leaking data.

IMDSv2 requires a session token. The client first sends a PUT request to obtain a token, then includes it in a header on every metadata call.

TOKEN=$(curl -s -X PUT http://169.254.169.254/latest/api/token \
  -H "X-aws-ec2-metadata-token-ttl-seconds: 60")
curl -s -H "X-aws-ec2-metadata-token: $TOKEN" \
  http://169.254.169.254/latest/meta-data/

Simple SSRF bugs cannot make that PUT with the custom header, so they fail. Since January 2026 the Node.js, LAMP, and Ruby on Rails blueprints enforce it by default. On older instances you can change the setting with the CLI, but test old scripts first because anything still using IMDSv1 will break.

Take quiz
What does IMDSv2 require that IMDSv1 does not?
A static IP
A session token
A Windows host
A load balancer
Which attack does IMDSv2 mainly help reduce?
Cookie stuffing
Disk fragmentation
SSRF
DNS zone transfer

45. How do you host a WordPress site on Lightsail?

Create an instance with the WordPress blueprint. WordPress, the web server, PHP, and the database come preinstalled, so the site is up shortly after launch.

  1. Choose a bundle. A small one works for light traffic, but grow it if pages become slow.
  2. Attach a static IP.
  3. Connect over SSH to retrieve the generated admin password. The docs name the file for your blueprint version.
  4. Point your domain to the static IP using a DNS zone, then open /wp-admin.
  5. Enable HTTPS, for example with Let's Encrypt on Bitnami-based blueprints, or put a CDN distribution in front.

After that, enable automatic snapshots, keep plugins updated, and move media files to a bucket if storage or transfer grows.

Take quiz
What do you retrieve over SSH on a new WordPress instance?
The billing invoice
The AWS root password
The generated admin password
The DNS registrar login
Which step keeps the site's address stable for DNS?
Stopping the instance daily
Using port 25
Deleting the firewall
Attaching a static IP

46. How do you point a domain name at a Lightsail instance?

Give the instance a fixed address, then tell the world to use it.

flowchart LR
A["Attach static IP"] --> B["Create DNS zone"]
B --> C["Add A record to static IP"]
C --> D["Set Lightsail name servers at registrar"]
D --> E["Wait for DNS propagation"]
  1. Create and attach a static IP to the instance.
  2. Create a DNS zone for the domain in Lightsail.
  3. Add an A record for the root (@) and for www, pointing to the static IP. Add AAAA records if you use IPv6.
  4. At the registrar, replace the name servers with the four Lightsail values.

Propagation can take from minutes to a day. Check with dig example.com. If you registered the domain with a different provider, you can also keep their DNS and simply add the A record there.

Take quiz
Which record type maps the root domain to an IPv4 address?
TXT record
PTR record
MX record
A record
Which tool checks if the DNS change has propagated?
dig
top
fdisk
lsblk

47. How do you troubleshoot an unreachable Lightsail instance?

Work from the outside in, so you rule out the cheap causes first.

  1. State and status checks: confirm the instance is running and check the status-check metric.
  2. Address: after a stop/start the public IP may have changed if no static IP is attached.
  3. Lightsail firewall: verify the port is open for your source IP, in both the IPv4 and IPv6 rule lists.
  4. Browser SSH: if that works and your client does not, suspect your key, username, or local network.
  5. Inside the OS: check the service is running and listening on the right interface, and review ufw or iptables.
  6. Resources: look for exhausted memory, full disk, or depleted burst capacity.
  7. DNS: make sure records point to the current address.

If the OS is damaged, snapshot it, build a new instance from the snapshot, or attach the disk to a rescue instance to repair files.

Take quiz
What is a common cause after stopping and starting an instance with no static IP?
The public IP changed
The blueprint was replaced
The firewall rules were erased from AWS
The bundle became smaller
If browser SSH works but your local client fails, what should you suspect?
The CDN cache
Your key, username, or local network
The Lightsail Region
The DNS zone
Where else might a blocked port come from besides the Lightsail firewall?
The static IP price
The block storage disk
The OS firewall such as ufw or iptables
The bundle name

48. How can you optimize Lightsail costs?

Costs are predictable, but waste still creeps in. Check these areas:

  • Delete unused resources. A stopped instance still bills, as do idle disks, old snapshots, and unattached static IPs.
  • Right-size bundles. Use CPU and burst metrics to find servers that are over- or under-provisioned.
  • Use IPv6-only bundles where clients and dependencies allow it.
  • Cut transfer. Serve static assets from a bucket behind a CDN distribution and compress responses.
  • Prune snapshots. Keep a sensible retention rather than every copy forever.
  • Set budgets and alarms in AWS Billing so overages surface early.

Review the bill monthly. Small orphaned items add up faster than people expect.

Take quiz
Which resource still bills after you merely stop an instance?
Only the SSH key
The stopped instance itself
Only the blueprint
Nothing, billing stops fully
Which change can reduce outbound transfer?
A bigger SSD
More firewall rules
A CDN distribution in front of static assets
A second DNS zone

49. How can you automate Lightsail with the AWS CLI?

Every console action has an API call, so you can script servers with the aws lightsail commands, SDKs, CloudFormation, or Terraform.

A basic provisioning script:

aws lightsail create-instances --instance-names web-1 \
  --availability-zone us-east-1a \
  --blueprint-id ubuntu_24_04 --bundle-id nano_3_0

aws lightsail allocate-static-ip --static-ip-name web-1-ip
aws lightsail attach-static-ip --static-ip-name web-1-ip --instance-name web-1

aws lightsail open-instance-public-ports --instance-name web-1 \
  --port-info fromPort=443,toPort=443,protocol=TCP

aws lightsail create-instance-snapshot \
  --instance-name web-1 --instance-snapshot-name web-1-pre-deploy

Use a launch script to install packages at first boot. Store scripts in version control, and run them from CI to get repeatable environments. Check bundle and blueprint IDs with get-bundles and get-blueprints, as they change over time.

Take quiz
Which command attaches a static IP to an instance?
aws ec2 associate-address
aws lightsail bind-eip
aws lightsail attach-static-ip
aws lightsail link-ip
Why keep provisioning scripts in version control?
To disable the firewall
To hide them from CloudFormation
To avoid using snapshots
To get repeatable environments

50. When should you migrate from Lightsail to EC2, and how?

Move when you hit Lightsail's limits. Common triggers:

  • You need Auto Scaling or spot capacity.
  • You need an instance type that no bundle offers.
  • You need custom VPC design, IAM instance roles, or advanced networking.
  • Your architecture is growing into many AWS services.

Lightsail can export an instance snapshot to Amazon EC2. The export creates an Amazon EC2 image from the snapshot, which you then launch as an EC2 instance.

  1. Create a fresh instance snapshot.
  2. Choose Export to Amazon EC2 and confirm the IAM permissions.
  3. Launch an EC2 instance from the exported image, picking the instance type and VPC.
  4. Reconfigure security groups, test, then cut over DNS.

Keep the Lightsail server running until the EC2 copy is verified, and plan for a short sync of data written after the snapshot.

Take quiz
Which feature is a typical reason to leave Lightsail for EC2?
Needing a snapshot
Needing a static IP
Needing a firewall
Needing Auto Scaling
What does Lightsail's export feature produce?
An EC2 image that you launch as an EC2 instance
A load balancer certificate
A CDN distribution
A new DNS zone
«
»

Comments & Discussions