Skip to content

Section 8: Deploying Cloud9 Terraform Workstation ​

In this section, you will deploy an AWS Cloud9 environment using a CloudFormation template.

This Cloud9 environment will be used as the Terraform workstation for the FortiGate Auto Scaling Group deployment.

AWS Cloud9 is used because it provides a browser-based development environment where students can run AWS CLI, Git, and Terraform commands from the same AWS account used for the lab.


Objectives ​

By the end of this section, you will be able to:

  • Launch the Cloud9 New VPC CloudFormation template.
  • Deploy a Cloud9 Terraform workstation.
  • Open the Cloud9 environment.
  • Install and verify Terraform before continuing with the Auto Scaling Group deployment.

Before You Begin ​

Confirm that you have completed the previous sections and have the following information from your instructor:

Important: Use the same AWS region throughout the lab.

Use this AWS region:

eu-central-1


8.1 Launch the Cloud9 CloudFormation Stack ​

Click the Launch Stack button below:

Launch Stack

Confirm that the CloudFormation page opens in:

eu-central-1


8.2 Configure Stack Parameters ​

On the CloudFormation Quick create stack page, review the stack details.

Use the following naming convention:

student<number>-Cloud9-New-VPC

Example:

student01-Cloud9-New-VPC

Set EnvironmentName to the same student-specific name. Keep the default VPC/subnet CIDRs unless instructed otherwise.

The template defaults CreateCloud9SSMPrerequisites to false, which assumes AWSCloud9SSMAccessRole and AWSCloud9SSMInstanceProfile already exist. Use false for prepared accounts. If either prerequisite is missing, have the instructor prepare them or select true only when neither exists; creating duplicate named IAM resources will fail. This prerequisite setting does not remove Cloud9's restriction on new customers.


8.3 Create the Stack ​

  1. Review the stack configuration.

  2. Confirm that:

    • Region is eu-central-1.
    • Stack name follows the student naming convention.
    • Cloud9 environment name is unique.
    • Default template parameters are kept unless instructed otherwise.
  3. Scroll to the bottom of the page.

  4. If CloudFormation shows an IAM acknowledgement checkbox, select it:

    I acknowledge that AWS CloudFormation might create IAM resources with custom names.

  5. Click:

text
Create stack
  1. Wait until the stack status becomes:
text
   CREATE_COMPLETE

This may take several minutes.


8.4 Open the Cloud9 Environment ​

After the stack reaches CREATE_COMPLETE:

  1. Open the AWS Console search bar.

  2. Search for and open:

text
Cloud9
  1. Find the Cloud9 environment created by the stack.

  2. Click:

text
Open

Wait for the Cloud9 IDE to load.


8.5 Install Terraform ​

Run the following commands in Cloud9 IDE:

bash
mkdir -p ~/bin ~/terraform-install
cd ~/terraform-install

Set the Terraform version.

bash
TERRAFORM_VERSION="1.15.6"

Detect the Cloud9 CPU architecture.

bash
ARCH="$(uname -m)"

if [ "$ARCH" = "x86_64" ]; then
  TF_ARCH="amd64"
elif [ "$ARCH" = "aarch64" ]; then
  TF_ARCH="arm64"
else
  echo "Unsupported architecture: $ARCH"
  exit 1
fi

echo "Detected architecture: $ARCH"
echo "Terraform package architecture: $TF_ARCH"

Download the Terraform binary package.

bash
curl -fsSLO "https://releases.hashicorp.com/terraform/${TERRAFORM_VERSION}/terraform_${TERRAFORM_VERSION}_linux_${TF_ARCH}.zip"

Unzip Terraform.

bash
unzip -o "terraform_${TERRAFORM_VERSION}_linux_${TF_ARCH}.zip"

Move Terraform to your Cloud9 user binary directory.

bash
mv terraform ~/bin/
chmod +x ~/bin/terraform

Add ~/bin to your PATH.

bash
export PATH="$HOME/bin:$PATH"

Make the PATH update persistent for future Cloud9 sessions.

bash
grep -qxF 'export PATH="$HOME/bin:$PATH"' ~/.bashrc || echo 'export PATH="$HOME/bin:$PATH"' >> ~/.bashrc

Verify Terraform installation.

bash
terraform version

Expected result:

text
Terraform v1.15.6

Verify AWS Identity ​

bash
aws sts get-caller-identity
aws configure get region

Confirm the account ID matches your assigned student account. Use eu-central-1 in Terraform and the AWS connector even if the CLI has no default region set. If Cloud9 has no usable AWS credentials, use the instructor-provided credentials through the lab's normal configuration method before continuing.

Checkpoint ​

Before continuing, confirm that:

  • The Cloud9 environment is open.
  • AWS region is eu-central-1.
  • Terraform is installed.
  • You are ready to run Terraform commands from Cloud9.

You are now ready to continue with the Terraform deployment section.


AWS UMS Hands-on Lab Guide