AWS
How to Deploy a Spring Boot Application on AWS EC2
By Utility Zone ยท 2026-10-03T09:31:03.504541
Category: AWS, Java, Spring Boot, Cloud Deployment
Level: Beginner to Intermediate
Estimated reading time: 10--12 minutes
Figure 1. Simplified learning architecture. This is an illustrative diagram, not a production network design.
Introduction
Amazon Elastic Compute Cloud (EC2) provides virtual servers on which you can run Java applications. In this tutorial, you will build a Spring Boot executable JAR, launch an EC2 instance, install a compatible Java runtime, copy the JAR to the server, start the application, and review basic security and troubleshooting practices.
Important: This is a learning-oriented single-instance deployment, not a complete production architecture. The console and package options can change; verify current AWS documentation and pricing before deploying.
Prerequisites
- An AWS account with permission to create EC2 resources.
- A Spring Boot project that builds successfully.
- A Java version supported by your Spring Boot version.
- Basic familiarity with Linux, SSH, and Maven or Gradle.
Cost note: EC2 compute, storage, public IPv4 addresses, data transfer, and related resources may incur charges. Review current AWS pricing and remove resources you no longer need.
Step 1: Build the application
For Maven projects, run from the project root:
./mvnw clean package
On Windows, use mvnw.cmd clean package. If you use installed Maven,
run mvn clean package.
For Gradle, the usual command is:
./gradlew clean bootJar
The executable JAR is commonly created under target/ for Maven or
build/libs/ for Gradle. Confirm the build succeeded, then test
locally:
java -jar target/your-application.jar
Replace the example filename with your actual JAR name. Stop the local
process with Ctrl+C.
Step 2: Launch an EC2 instance
Figure 2. Illustrative launch checklist, not an actual AWS console screenshot. Use the labels and options currently shown in your AWS account.
- Sign in to the AWS Management Console and open EC2.
- Choose Launch instance and provide a name such as
spring-boot-demo. - Select a supported Linux AMI, such as a suitable Amazon Linux image.
- Choose an instance type based on your test workload and budget.
- Create or select an SSH key pair if you need SSH access. Keep the private key secure.
- Review networking and storage settings, then launch the instance.
- Wait until the instance is running and its status checks pass.
Step 3: Configure the security group
Figure 3. Illustrative security guidance, not a live security-group screenshot.
A security group is a virtual firewall for your instance.
Purpose Port Recommended source
SSH administration TCP 22 Your current public
IP, not 0.0.0.0/0
Temporary application TCP 8080 Your IP only, if testing direct access is required
Do not expose SSH to the whole internet without a specific reason and compensating controls. For production, prefer controlled administration through options such as AWS Systems Manager Session Manager, a VPN, or a bastion host.
For a public production application, typically expose HTTPS on port
443 through an Application Load Balancer or a properly configured
reverse proxy. Keep port 8080 private when possible.
Step 4: Connect to the instance and copy the JAR
Figure 4. Illustrative terminal workflow. Replace example filenames and host values with your own.
From Linux or macOS, restrict access to your private key and connect using the public DNS name shown in the EC2 console:
chmod 400 my-key.pem
ssh -i my-key.pem ec2-user@YOUR_EC2_PUBLIC_DNS
The login username depends on the selected AMI; ec2-user is common for
Amazon Linux, while other images use different usernames.
Copy the JAR from your local machine (adjust paths, key, username, and host):
scp -i my-key.pem target/your-application.jar ec2-user@YOUR_EC2_PUBLIC_DNS:/home/ec2-user/
For Gradle, use the JAR under build/libs/. On the instance, verify the
file:
ls -lh /home/ec2-user/
Step 5: Install Java
Check your Spring Boot version and project configuration to determine
the supported Java version. Package names vary by Linux image and
release. On an Amazon Linux image using dnf, search for available
packages:
sudo dnf search java
Install a compatible runtime package available for your AMI. For
example, a package may be named java-17-amazon-corretto-headless,
depending on the image and repositories:
sudo dnf install java-17-amazon-corretto-headless
Use the version required by your application and verify the package name
for your operating system. Older images may use yum instead of dnf.
Confirm the installation:
java -version
Step 6: Start the application
java -jar /home/ec2-user/your-application.jar
If the application listens on port 8080 and the security group
temporarily allows your IP to reach it, test:
http://YOUR_EC2_PUBLIC_DNS:8080
Replace the host and path with your actual endpoint. If your application
has no route at /, a 404 at the root path may be expected; test a
valid endpoint.
You can set the port at startup with:
java -jar /home/ec2-user/your-application.jar --server.port=8080
Step 7: Run the application with systemd
Create a service file:
sudo vi /etc/systemd/system/springboot-app.service
Example configuration:
[Unit]
Description=Spring Boot Application
After=network.target
[Service]
User=ec2-user
WorkingDirectory=/home/ec2-user
ExecStart=/usr/bin/java -jar /home/ec2-user/your-application.jar
Restart=on-failure
RestartSec=5
SuccessExitStatus=143
[Install]
WantedBy=multi-user.target
This example is for illustration. Confirm Java's actual path with
which java, and adjust ExecStart if needed. For production, use a
dedicated service account rather than a general SSH account, and store
the application in a dedicated directory with restricted permissions.
Enable and start the service:
sudo systemctl daemon-reload
sudo systemctl enable springboot-app
sudo systemctl start springboot-app
Step 8: Verify the service and inspect logs
Figure 5. Illustrative verification workflow, not a captured terminal screenshot.
sudo systemctl status springboot-app
sudo journalctl -u springboot-app -n 100 --no-pager
To follow logs live:
sudo journalctl -u springboot-app -f
If you change the service file, reload systemd and restart the service.
Step 9: Manage configuration and secrets safely
Spring Boot supports external configuration through command-line arguments, environment variables, and configuration files. Keep environment-specific values outside the application artifact.
For example, a service unit can set a non-secret profile variable:
Environment="SPRING_PROFILES_ACTIVE=prod"
Do not put passwords, API keys, or database credentials in source control, public repositories, or a baked-in JAR. For production, consider AWS Secrets Manager or Systems Manager Parameter Store, with narrowly scoped IAM permissions. Avoid logging secret values.
If the application connects to Amazon RDS or another private service, configure networking and credentials according to that service's security model. Do not make a database public merely to simplify connectivity.
Step 10: Production readiness
- HTTPS: Use a trusted TLS certificate, commonly with an Application Load Balancer and AWS Certificate Manager, or a correctly configured reverse proxy.
- Least privilege: Limit security-group rules and IAM permissions to what is needed.
- Monitoring: Collect logs and metrics, and configure useful alarms.
- Backups and recovery: Define backup, restore, and data-retention procedures.
- Patching: Keep the operating system and runtime updated.
- Deployment: Use CI/CD and a rollback plan rather than manually replacing production files.
- Availability: Consider multiple instances across Availability Zones and a load balancer if required.
- Capacity and cost: Size resources based on observed CPU, memory, traffic, and budget.
A single EC2 instance is useful for learning, but it is a single point of failure unless additional resilience is designed.
Troubleshooting
The application cannot be reached
Confirm the instance is running, the application is listening on the expected port, the endpoint exists, and the security group permits traffic from the intended source. Check subnet routing and network ACLs as well.
sudo ss -lntp
The JAR exits immediately
sudo systemctl status springboot-app
sudo journalctl -u springboot-app -n 200 --no-pager
Common causes include an incompatible Java version, missing environment variables, invalid configuration, port conflicts, or unavailable dependencies.
java: command not found
which java
java -version
Check whether Java is installed and available on the service's PATH.
If it is installed in a custom location, use its full path in the
service file.
It works locally but not on EC2
Review active Spring profiles, environment variables, database connectivity, file paths, firewall rules, and assumptions about local files. Do not fix connectivity problems by opening all ports to the internet.
Deployment checklist
- The application builds and runs locally.
- The JAR uses a supported Java version.
- EC2 access and the private key are configured securely.
- SSH is restricted to an approved access path.
- The JAR is copied to the intended directory.
- A valid application endpoint responds.
- Service status and logs are available.
- Secrets are not embedded in the JAR or source code.
- HTTPS and restricted public access are configured before production.
- Costs and unused resources are reviewed.
What to learn next
- Connect Spring Boot to Amazon RDS for PostgreSQL using private networking.
- Configure an Application Load Balancer and HTTPS.
- Automate deployments with Jenkins or another CI/CD tool.
- Monitor Spring Boot with Amazon CloudWatch.
- Containerize the application with Docker and compare EC2 deployment with Amazon ECS.
Conclusion
Deploying a Spring Boot JAR to EC2 introduces the basics of cloud deployment: packaging, server setup, Java installation, network configuration, process management, and log inspection. Treat this as a learning environment rather than a complete production blueprint. Production applications also need secure secrets management, HTTPS, monitoring, controlled releases, recovery planning, and an appropriate availability design.
Publishing note: The visuals in this Markdown package are illustrative diagrams/mockups, not real captures of the AWS Management Console. Before presenting the article as a verified hands-on tutorial, run the steps in your AWS environment and replace the mockups with genuine, redacted screenshots of the screens you actually used. Do not claim the deployment was tested unless you completed it.