Skip to content

AWS

AWS is where the domains and the transactional email live. The hosting moved off it — that's a home VPS behind Pangolin now — but the pieces I still depend on are Route 53 and SES, and the old Lightsail setup is documented because it's still accurate for anyone running a single instance.

What's still in use

Route 53 registers the domains. The nameservers point at Cloudflare, so Route 53 is a registrar here, not the DNS resolver. If you're serving traffic directly from Route 53 you'd create an A record to the static IP; that's what the Route 53 setup covers, and it's superseded for my domains by the Cloudflare delegation.

SES sends email from the applications. Verify the domain and any recipient addresses while in sandbox, get SMTP credentials from SMTP Settings, and note the port: 587 is STARTTLS, not implicit TLS. Setting use_tls=True on 587 gives you SSL: WRONG_VERSION_NUMBER — the server expects STARTTLS negotiation. 465 is the implicit-TLS port. That mismatch is the most common reason a working local mail config fails in production.

SES receives mail through a rule set that hands off to a Lambda, which forwards to Gmail. The receiving setup is the one that needs the IAM role, the policy, and the MX records all lined up at once.

What's historical

Lightsail was the all-in-one: static content, an API, and a database on one $3.50/month instance running Nginx. Certbot for HTTPS, MariaDB for storage, WinSCP over a PuTTY-generated key for file access. Most of it applies to a plain EC2 instance too, as long as you're on a single instance without a load balancer.

S3 static hosting with CloudFront in front is still a legitimate way to serve a single-page app, and the bucket policy and redirect for www are documented. For hobby databases, serverless options beat an always-on RDS — see Serverless Relational Databases.

The docs

  • Lightsail — setup, Nginx, server blocks, Certbot, MariaDB, Route 53
  • S3 static site — buckets, custom domain, CloudFront
  • RDS — connecting SQL Workbench, public access, security group rules
  • SES — verified identities, SMTP credentials, sending from an app, receiving and forwarding

Comments