AWS Lightsail
IAM credentials, integration permissions, regions, Linux plans, IPv4 and VPS tracking.
These procedures happen in app.WordPane.cloud. For files, databases, SSH users and application configuration, see the control panel guides. Values and options can change; check the summary presented in your account before confirming.
Prepare integration IAM credentials
Where to find: Servers → Create server → My provider → AWS Lightsail
Use an IAM identity dedicated to Lightsail integration. Do not use AWS root account credentials.
- Ask your AWS account administrator for a dedicated IAM identity with the necessary permissions for integration.
- At WordPane, use Connect another account and link Download integration permissions. The administrator must review JSON, create or update the corresponding IAM policy, and associate it with the dedicated identity. Do not replace this policy with general administrative access.
- With the authorized identity, open Security credentials on IAM and locate Access keys. Use Create access key, select the appropriate use case and complete the AWS steps.
- Save Access Key ID and Secret Access Key in a secure location. AWS offers the secret key only in creation; you cannot consult the same secret later.
- If you are using temporary credentials, also have Session Token from the same set and check the validity. Do not mix keys and token from different sessions.
In the customer area: Lightsail integration permissions file. AWS References: creation of IAM keys and Less privileged permissions on Lightsail.
Connect and select your AWS account
Where to find: AWS Lightsail → Choose account
The connection validates the access to the account; the VPS is created only after the revision and confirmation of the configuration.
- Choose the reference application in Create server and advance to My provider → AWS Lightsail.
- Select an existing account in Connected Accounts or click Connect another account.
- Inform Connection Name, Access Key ID and Secret Access Key in the corresponding fields.
- Fill in Session Token (optional) only when using temporary credentials that require this token. For a permanent IAM key, leave this field empty.
- Click Connect Account, check the Connected statement, and select the correct account.
- Click Configure VPS and wait for the query. Check out Destination of the new server; use Change account if necessary.
Understand the fields and options
- Connection name
- Account identification in WordPane; use a name that differentiates environments.
- Access Key ID
- IAM access key identifier.
- Secret Access Key
- Secret of the same key. Do not use AWS login password in this field.
- Session Token
- Part of the temporary credentials; must correspond to the informed keys and not be expired.
Set up the instance and review the hiring
Where to find: AWS Lightsail → Configure VPS → Review and create
This stream uses Lightsail Linux plans with public IPv4 and clean Ubuntu; it is not an EC2 or pre-installed application hiring.
- Inform Server Name and choose Location. São Paulo (sa-east-1) appeared among the regions consulted. Use the current list and confirm availability.
- Select Ubuntu 22.04 or 24.04 and the Lightsail Plans category, identified as Linux with public IPv4.
- Compare each plan by cores, RAM, disk and monthly reference in USD. Plans with similar names may have different features; do not only choose by the name NANO, MICRO or LARGE.
- Select an available plan. Observed cards indicate public IPv4 and fixed IP for VPS. Use Update Plans if you need to re-check.
- Choose web server, database and additional Node.js option when needed and offered. Check out the application recommendation and compatible applications in the installer.
- In Review and create, check out account, region, plan, Ubuntu, technologies and the two costs: AWS infrastructure and WordPane management.
- Read the authorization and, if you decide to hire, check the confirmation and use Create VPS in AWS.
- Follow Account → Operations and check the instance in the same region of the Lightsail console. Install the application in the control panel after completion.
Solve credentials and permissions
Where to find: AWS Lightsail → Connection, catalog and operations
Register the step and message displayed without including credentials. Check the account and region before repeating a creation.
- Confirm that the problem occurs when connecting, consulting plans or creating VPS.
- Check out the status of the operation in WordPane and the resources in the region chosen in Lightsail.
- Check validity of credentials and permissions with the IAM administrator.
- If it persists, open a call with step, region and error message without keys or tokens.
If the result is not expected
Invalid credentials
Check if Access Key ID and Secret Access Key are of the same set, no extra spaces, and if the key is active.
Session Token expired
Temporary credentials cease to work on expiration. Get a new authorized set and use the available connection stream; do not reuse the previous token.
AccessDenied or unauthorized operation
Ask the IAM administrator to compare the denied operation with the policy provided by the integration and the restrictions of the organization. Do not grant general administrative access as automatic correction.
Region or plans do not appear
Wait for the query, check out access to the region and use Update Plans. See the message before choosing another region.
Instance does not appear on console
Check out the AWS account and region chosen in the stream. The instance may be in another region; see also Operations.
Installation failed after creation
Check the instance and associated features in Lightsail before repeating. Closing management or revoking a key does not automatically cancel the infrastructure.
Updated October 8, 2026.
Consult other guides