What you need before you start
Installing WordPress on Amazon Linux 2 means setting up a web server, a database, and WordPress itself on an EC2 instance. You will need SSH access to your instance (the ability to log in via command line), a basic text editor, and about 30 minutes. This guide assumes you have already launched an EC2 instance running Amazon Linux 2 and can connect to it.
You will also need a domain name pointed to your instance's IP address or Elastic IP, though you can test WordPress without one by using the IP address directly. If you are new to EC2, launch your instance first through the AWS console, then return here.
Key Takeaways
- Amazon Linux 2 requires you to install Apache, MySQL, and PHP before WordPress will run — these do not come pre-installed.
- You will connect to your instance using SSH, then run commands to download and configure WordPress in the web server directory.
- The database setup step is where most people get stuck — you must create a WordPress database and a user with a strong password before running the WordPress installer.
- After installation, you will log into WordPress through your browser at yoursite.com/wp-admin and complete the setup wizard.
- File permissions and ownership matter — WordPress needs write access to its own directories, which requires setting the correct user and group.
Install Apache, MySQL, and PHP on your instance
Log into your EC2 instance via SSH. Once connected, update the system package list by running sudo yum update -y. This ensures you have the latest security patches and package information.
Next, install Apache (the web server), MySQL (the database), and PHP (the language WordPress runs on) in one command: sudo yum install -y httpd mysql-server php php-mysql php-gd php-xml. The extra PHP packages (php-gd, php-xml) handle images and other WordPress features. This will take a few minutes.
After installation finishes, start the services and set them to start automatically when your instance reboots. Run these three commands in order:
- sudo systemctl start httpd
- sudo systemctl start mysqld
- sudo systemctl enable httpd
- sudo systemctl enable mysqld
Test that Apache is working by visiting your instance's public IP address in a browser. You should see the Apache test page. If you do not, check that your security group allows inbound traffic on port 80 (HTTP).
Create a WordPress database and database user
WordPress stores all your posts, pages, and settings in a MySQL database. You must create this database and a user account before WordPress can write to it. Log into MySQL by running sudo mysql -u root. You will see a mysql> prompt.
At the MySQL prompt, create the database by typing (or pasting) this command: CREATE DATABASE wordpress; Then press Enter. Next, create a user and give them permission to access only that database. Run these commands one at a time, replacing your_password with a strong password you choose:
CREATE USER 'wpuser'@'localhost' IDENTIFIED BY 'your_password'; GRANT ALL PRIVILEGES ON wordpress.* TO 'wpuser'@'localhost'; FLUSH PRIVILEGES; EXIT;
Write down the database name (wordpress), the username (wpuser), and the password you chose. You will need these in the WordPress setup wizard. Do not use a simple password — WordPress is a common target, and a weak database password is a real security risk.
Download and configure WordPress
WordPress files go in the Apache web directory, which is /var/www/html. Navigate there and download the latest WordPress release by running these commands:
- cd /var/www/html
- sudo wget https://wordpress.org/latest.tar.gz
- sudo tar -xzf latest.tar.gz
This downloads WordPress as a compressed file, then unpacks it into a folder called wordpress. Next, move the WordPress files up one level so they sit directly in /var/www/html instead of in a subfolder. Run sudo mv wordpress/* . (note the period at the end). Then remove the now-empty wordpress folder with sudo rmdir wordpress.
Now you need to set the correct file ownership. Apache runs as a user called apache, and it needs to own the WordPress files so it can write to them. Run sudo chown -R apache:apache /var/www/html. This tells the system that the apache user and apache group own everything in that directory.
Create the WordPress configuration file
WordPress needs a configuration file called wp-config.php that contains your database details. A template file called wp-config-sample.php already exists. Copy it and edit the copy by running sudo cp /var/www/html/wp-config-sample.php /var/www/html/wp-config.php.
Open the file in a text editor. If you are comfortable with nano, run sudo nano /var/www/html/wp-config.php. If you prefer vi, use sudo vi /var/www/html/wp-config.php. Find these four lines and replace them with your database details:
define( 'DB_NAME', 'wordpress' ); define( 'DB_USER', 'wpuser' ); define( 'DB_PASSWORD', 'your_password' ); define( 'DB_HOST', 'localhost' );
The DB_NAME, DB_USER, and DB_PASSWORD must match what you created in MySQL. DB_HOST stays as localhost because MySQL is running on the same instance. Save the file (in nano, press Ctrl+O, then Enter, then Ctrl+X; in vi, press Escape, then type :wq and press Enter).
Complete the WordPress setup through your browser
Open a browser and visit your instance's public IP address (or your domain name if you have pointed it to the instance). You should see the WordPress setup wizard. It will ask you for a site title, username, password, and email address. These are different from your database credentials — they are the login details you will use to manage WordPress.
Choose a strong password for your WordPress admin account. This is what you will type into wp-admin to write posts and manage your site. After you fill in the form and click Install WordPress, the wizard will create the necessary database tables and log you in.
If the wizard does not appear and you see a blank page or an error, check that your security group allows port 80 traffic and that the file permissions are correct. A common mistake is forgetting to run the chown command, which leaves Apache unable to read the WordPress files.
Secure your WordPress installation
Before you start using WordPress, make a few quick security changes. First, delete the wp-config-sample.php file you no longer need by running sudo rm /var/www/html/wp-config-sample.php. This removes a file that could leak information to attackers.
Second, log into WordPress at yoursite.com/wp-admin using the admin username and password you created. Go to Settings > General and make sure your site address is correct. If you are using a domain name, it should be https://yourdomain.com (with https, not http). If you do not have an SSL certificate yet, you can add one later using AWS Certificate Manager and CloudFront, but http is fine for testing.
Third, install a security plugin like Wordfence or All In One WP Security. These monitor for attacks and lock down common vulnerabilities. You can find them in the WordPress plugin directory by logging in and going to Plugins > Add New.
Frequently Asked Questions
What if I get a "connection refused" error when trying to reach my site?
This usually means Apache is not running or your security group does not allow port 80. Check that Apache is running by connecting via SSH and typing sudo systemctl status httpd. If it says "inactive", run sudo systemctl start httpd. If Apache is running, check your EC2 security group in the AWS console and make sure it has an inbound rule allowing HTTP traffic (port 80) from 0.0.0.0/0.
Can I use a different database password than the one I chose?
Yes. When you create the MySQL user, you can use any password you want. Just make sure you use the exact same password in wp-config.php. If you forget the password, you can log back into MySQL as root and change it with ALTER USER 'wpuser'@'localhost' IDENTIFIED BY 'newpassword';
Do I need to use a domain name, or can I just use the IP address?
You can use the IP address to test WordPress right away. Just visit http://your-instance-ip in your browser. If you want to use a domain name later, point it to your instance's Elastic IP (a static IP that does not change when you reboot), then update the WordPress site address in Settings > General.
What if WordPress says "Error establishing a database connection"?
This means WordPress cannot reach MySQL or the credentials in wp-config.php are wrong. Double-check that the DB_NAME, DB_USER, DB_PASSWORD, and DB_HOST in wp-config.php match exactly what you created in MySQL. Also make sure MySQL is running by typing sudo systemctl status mysqld. If it is not running, start it with sudo systemctl start mysqld.
Should I change the WordPress table prefix from wp_ to something else?
It is not necessary, but some people do it for security. If you want to, edit wp-config.php before you run the setup wizard and change the line $table_prefix = 'wp_'; to something like $table_prefix = 'abc_'; This makes it slightly harder for attackers to guess your table names, though it is not a substitute for a strong password and regular updates.