Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

For a newly launched Amazon Linux 2023 EC2 instance, add a shell script to its user data to update packages, install Docker, start the service and, optionally, grant ec2-user access to the Docker group. User data runs during first boot by default, so allow extra startup time and verify the result after connecting to the instance.

What this setup does—and which AMI it covers

EC2 user data lets you provide launch-time configuration, including Linux shell scripts and cloud-init directives. Amazon Linux 2023 processes user data with its customized cloud-init package. The Docker commands below follow AWS’s Amazon Linux 2023 instructions; they are not universal commands for Ubuntu, Debian, Windows, or other AMIs. For other operating systems, use the installation instructions for the selected distribution.

This is a first-boot installation approach for a standalone host. User-data scripts run only on initial launch by default. Adding or editing user data on a stopped instance does not, by itself, make the script run again when the instance restarts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Install and start Docker with an EC2 user-data script

When launching a new Amazon Linux 2023 instance, enter this script in the EC2 launch flow’s user data field:

#!/bin/bash
yum update -y
yum install docker -y
service docker start
usermod -a -G docker ec2-user

AWS documents the installation command as sudo yum install docker when run interactively. The -y option above is an unattended-script adaptation so package installation can proceed without an interactive confirmation. Startup scripts run with elevated privileges, so the script does not need sudo.

The final command is optional: it adds ec2-user to the Docker group so that user can run Docker commands without prefixing them with sudo. Docker group membership grants privileged access to the daemon, so use it only when that convenience is appropriate for your security model. Docker itself can be installed and started without this group change.

Verify Docker after connecting

  1. Wait a few extra minutes for the first-boot setup to finish, then connect to the EC2 instance.
  2. If you included the group-membership command, start a fresh login session so the new group membership is applied.
  3. Run docker info. AWS documents this command for checking Docker on Amazon Linux 2023.

The user-data script runs during boot, not inside your later interactive shell. A successful SSH connection alone does not establish that every command completed; use the verification command and, if needed, inspect the cloud-init output log.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Troubleshoot user-data execution

Allow for first-boot work

Package updates and installation add time to startup. AWS advises allowing a few minutes for user-data commands to complete. If Docker is not ready immediately after connecting, check the initialization output before concluding that installation failed.

Read the cloud-init output

On the instance, inspect /var/log/cloud-init-output.log for output and errors from user-data execution. This is the first place to look when a command did not complete as expected.

Do not rely on editing user data to rerun it

AWS notes that changed user data on a stopped instance is visible after restart, but the default behavior does not rerun the script. For repeatable configuration changes, use an explicit cloud-init or system-service design, or build the required configuration into an image or launch automation. Choose the mechanism deliberately rather than assuming a user-data edit is a rerun trigger.

Keep ECS bootstrap separate from a standalone Docker host

If the EC2 instance is being bootstrapped as an Amazon ECS container instance, do not treat it as the standalone-host procedure above. AWS explains that Docker and ECS systemd units wait for cloud-init to finish, while cloud-init waits for user data to complete. Synchronously starting Docker or ECS from user data can therefore deadlock in this ECS bootstrap scenario. AWS summarizes the dependency: “The cloud-init process is not considered finished until your Amazon EC2 user data has finished running.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For the ECS agent context, AWS documents this nonblocking command:

systemctl enable --now --no-block ecs.service

This is an ECS-specific workaround, not a general replacement for starting Docker on a standalone EC2 host. AWS also warns that custom Docker daemon configurations are unsupported in ECS because they can conflict with later changes or features. See AWS’s ECS agent installation guidance and ECS container-instance bootstrap guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose the right configuration approach

  • New Amazon Linux 2023 standalone host: use the user-data script above when a one-time installation at launch meets the need.
  • A different AMI or Linux distribution: use that operating system’s current package and service instructions instead of assuming the AL2023 commands apply.
  • Repeatable changes or controlled deployments: use an explicit configuration-management, service, image-building, or launch-automation design rather than relying on default one-time user data.
  • ECS container instance: follow ECS bootstrap guidance and account for the cloud-init/service ordering dependency.

For the current EC2 user-data behavior, consult AWS’s EC2 user-data guide. For Amazon Linux 2023’s cloud-init behavior, see Amazon Linux 2023 customized cloud-init. For the documented Docker commands, see AWS’s Amazon Linux 2023 Docker instructions.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.