Where to find VM configuration details in AWS
Open the AWS Console, go to EC2, and select Instances from the left menu. Click the instance ID of the VM you want to examine. The Details tab shows the core configuration: instance type, availability zone, VPC, subnet, security groups, and IAM role. The Networking tab displays IP addresses, network interfaces, and DNS names. The Storage tab lists attached volumes with their size and type. Security groups and network ACLs appear under the Networking section.
Each tab organizes different categories of settings so you do not have to hunt through a single overwhelming page. The Details tab is usually where you start because it contains the most frequently needed information.
Key Takeaways
- The Details tab in the EC2 Instances view shows instance type, availability zone, VPC, subnet, security groups, and IAM role in one place.
- The Networking tab displays all IP addresses (public and private), network interfaces, DNS names, and security group associations.
- The Storage tab lists every volume attached to the instance, including volume ID, size, type (gp3, io1, etc.), and whether it deletes on termination.
- You can export instance metadata using the AWS CLI command aws ec2 describe-instances to get configuration details in JSON format for multiple instances at once.
- Tags you have applied to the instance appear in the Tags tab and help you organize and search for instances across your account.
Reading the Details tab
The Details tab contains the settings that define how your instance runs. Instance type (such as t3.medium or m5.large) determines CPU, memory, and network performance. The availability zone shows which physical data center your instance runs in — this matters for latency and disaster recovery planning. The VPC and subnet tell you which network the instance belongs to and whether it has a public IP address.
The IAM role listed here is the permission set the instance uses to call other AWS services. If your application needs to read from S3 or write to DynamoDB, the role determines whether it can. The security groups shown here act as a firewall — they control which ports accept inbound traffic and which destinations the instance can reach outbound.
Networking tab for IP addresses and DNS
The Networking tab shows every way the instance connects to the network. You will see the primary private IP address (always present), the public IP address (if one is assigned), and the Elastic IP address (if you have reserved one). Each network interface attached to the instance appears here with its own IP addresses and security groups.
The DNS name listed here is the public hostname AWS assigns to your instance — it changes if you stop and start the instance unless you have attached an Elastic IP. The subnet ID and VPC ID confirm which network the instance belongs to. If you have multiple network interfaces attached (common in high-availability setups), each one appears with its own configuration.
Storage tab and volume details
The Storage tab lists every EBS volume attached to your instance. For each volume you will see the volume ID, size in GB, volume type (gp3 for general purpose, io1 for high IOPS, st1 for throughput-optimized), and whether it deletes when the instance terminates. The root volume (where the operating system lives) is marked as such.
If a volume is encrypted, that status appears here. The IOPS and throughput settings for the volume also display — these determine how fast the volume can read and write data. You can click the volume ID to see more details like snapshots, tags, and creation time.
Security groups and network ACLs
Security groups appear in both the Details and Networking tabs. Click a security group name to see its inbound and outbound rules. Inbound rules control what traffic can reach the instance (for example, port 443 from anywhere for HTTPS). Outbound rules control where the instance can send traffic — by default, most instances can reach anywhere outbound.
Network ACLs are a second layer of firewall that operates at the subnet level rather than the instance level. They appear in the VPC settings, not on the instance page itself. Most people rely on security groups for day-to-day access control, but understanding both helps you troubleshoot connectivity problems.
Using the AWS CLI to extract configuration
The console is useful for looking at one instance, but the AWS CLI lets you pull configuration from many instances at once. The command aws ec2 describe-instances returns all instance details in JSON format. You can filter by instance ID, tag, or state to narrow the results.
For example, aws ec2 describe-instances --instance-ids i-0123456789abcdef0 returns the full configuration of a single instance. Add --query 'Reservations[0].Instances[0].[InstanceType,State.Name,SubnetId,SecurityGroups]' to extract only the fields you need. The CLI output is easier to parse in scripts or save to a file than copying from the console.
Tags and metadata
The Tags tab shows any labels you or your organization have applied to the instance. Tags are key-value pairs — for example, Environment: Production or Owner: TeamA. They do not affect how the instance runs, but they help you organize, search, and filter instances across your account. You can add or remove tags directly from the console without stopping the instance.
The instance metadata service (a built-in AWS feature) also stores information about the instance that running applications can read. This includes the instance ID, instance type, availability zone, and any IAM role credentials. Applications use this metadata to discover their own configuration without hardcoding values.
Frequently Asked Questions
How do I find the root volume size?
Go to the Storage tab and look for the volume marked as the root device. The Size column shows the volume size in GB. If you need to know the filesystem size inside the instance (which may be smaller), you have to connect to the instance and run a command like df -h on Linux or Get-Volume on Windows.
Where do I see if an instance has a public IP address?
The Networking tab shows the Public IPv4 address field. If it is empty, the instance does not have a public IP. You can assign one by attaching an Elastic IP address. The Details tab also shows whether the instance is in a subnet that auto-assigns public IPs.
Can I see what AMI (image) the instance was launched from?
Yes, the Details tab shows the AMI ID under Image ID. Click the ID to see the image name and other details. If the AMI has been deleted, you will see only the ID. The Launch time field shows when the instance started.
How do I check if an instance can reach the internet?
Check three things: the security group outbound rules (must allow traffic to your destination), the network ACL outbound rules (must also allow it), and whether the subnet has a route to an internet gateway or NAT gateway. The Networking tab shows the route table ID — click it to see the routes.
What does the instance state mean?
Running means the instance is active. Stopped means it is shut down but not deleted (you can start it again). Terminated means it is deleted and cannot be restarted. Stopping and Pending are temporary states during transitions. The Details tab shows the current state.