Skip to content

AWS

The AWS provider uses the default VPC and public subnets. No new VPCs, no NAT gateways, no EKS, no load balancers.

What gets created

resource purpose
security group gr-<name>-gw inbound 443 to the gateway
security group gr-<name>-node no inbound rules at all
IAM role + policy + profile gr-<name>-gw-role gateway only: RunInstances, TerminateInstances, Describe*, PassRole, pricing:GetProducts
elastic IP stable gateway address (<ip-dashed>.sslip.io)
t4g.micro gateway instance + 12GB gp3 root runs the gateway container; ~$11/month floor
GPU node instances DLAMI base (CUDA driver + docker), spot when requested, IMDSv2 required, no SSH keypair

Everything carries geniusrise:deployment=<name>. destroy deletes by tag and name prefix only.

Node boot

cloud-init runs a single docker run --gpus all --restart always of the engine image with the join token in env. Nodes have no IAM role — they need no cloud permissions.

Quotas

Most new accounts start with zero G/VT vCPU quota. geniusrise doctor checks L-417A185B (on-demand) and L-3819A6DF (spot) and prints the increase request link.

No default VPC?

If your account has no default VPC, create one or set provider.subnet explicitly.