Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Docs / etcd (Hardened) / Install

Install etcd (Hardened)

Launch, connect, and validate — with the expected result after every step.

Prerequisites

AWS

  1. Subscribe and launch.
    Expected result `etcdctl put smoke ok && etcdctl get smoke` round-trips.
  2. For network clients: enable TLS + auth (etcd supports cert and role/user auth), change --listen-client-urls/--advertise-client-urls in the unit, then open 2379 to your subnet only. Never expose etcd without auth — it will happily serve your secrets to anyone.
    Expected result Remote etcdctl with certs works; anonymous requests are refused.

Google Cloud

  1. Deploy from the listing (IAP-only SSH; 2379 closed by the package by default).
    Expected result On the VM: etcdctl --endpoints=http://127.0.0.1:2379 endpoint health reports healthy.
  2. For in-VPC clients: enable TLS + auth, change the client URLs in the unit, restart etcd, then add a firewall rule for 2379 from your subnet only.
    Expected result Remote etcdctl with certs works; anonymous requests are refused.

Validate

etcdctl endpoint health   → 127.0.0.1:2379 is healthy

First boot: Build-time member state (/var/lib/etcd/member) is wiped at capture; a fresh member initializes on your first boot. No credential is generated (etcd ships with no auth; loopback only).

First login / credentials

  1. SSH in with the key pair you chose at launch (AWS: ssh ec2-user@<public-ip>; GCP: gcloud compute ssh <vm> --tunnel-through-iap).
  2. There is no application credential: `etcdctl endpoint health` and `etcdctl put smoke ok` work on 127.0.0.1:2379 without authentication — from the instance only.
  3. Before any remote client: enable TLS and role/user auth, edit --listen-client-urls/--advertise-client-urls in /etc/systemd/system/etcd.service, `sudo systemctl daemon-reload && sudo systemctl restart etcd`, then open 2379 to your subnet only.

Secure it

Costs & quotas

Software is billed by the marketplace at the listed rate; infrastructure (VM, storage, egress) is billed by your cloud at its standard rates. The recommended size fits default service quotas in most accounts — if you scale out, review your cloud's quota console before launch.

Next: configuration · troubleshooting · security notes