aws - Universal Command Line Interface for Amazon Web Services (AWS CLI v2)
aws [options] <command> <subcommand> [parameters]
Options you will use
--profile NAME- Use this named profile from ~/.aws/config and ~/.aws/credentials (also AWS_PROFILE). With --profile, AWS_ACCESS_KEY_ID in the environment is ignored.
--region REGION- The Region to send the request to (also AWS_REGION, AWS_DEFAULT_REGION, the profile's region). IAM is global; most services are regional.
--output FORMAT- json (default), text (tab separated, for shell loops), table, yaml, yaml-stream, off.
--query EXPR- A JMESPath expression applied by the CLI to the response, after pagination: Users[].UserName, Buckets[?starts_with(Name,
oncall)].Name. Quote it in single quotes. --no-paginate- Only the first page (the service's own page size), with the service's marker in the output.
--max-items N- Print at most N items and a NextToken to continue with --starting-token (paginated operations).
--page-size N- The size of each API page; the CLI still fetches every page. For calls that time out on big pages.
--debug- Log every step: the credential chain, the request, the response headers. Goes to stderr.
--no-cli-pager- Do not send the output to a pager (also AWS_PAGER="" or cli_pager = in the config).
--cli-error-format FORMAT- enhanced (default since 2.34: aws: [ERROR]: ...), json, yaml, text, table, legacy (the old "An error occurred ..." text).
--cli-binary-format FMT- base64 (default in v2: blob parameters are base64 text) or raw-in-base64-out (blobs given as raw text).
--endpoint-url URL- Send the request to another endpoint (LocalStack, a VPC endpoint, FIPS).
--no-sign-request- Send the request without credentials (anonymous): only works on public resources.
--generate-cli-skeleton- Print the JSON skeleton of the operation's parameters (fill it in, then --cli-input-json file://x.json).
Examples
$ aws sts get-caller-identitywho am I: account, user or role ARN
$ aws configure listwhich credentials and region the CLI would use, and from where
$ aws iam list-users --query 'Users[].UserName' --output textone line of names, for a shell loop
$ aws s3 ls s3://bucket/prefix/ --recursive --human-readable --summarizewhat is in a bucket, how big
$ aws sts assume-role --role-arn ARN --role-session-name metemporary credentials for a role
Gotchas
aws sts get-caller-identityis whoami: it needs no permission and works even under an explicit deny.- AccessDenied messages name the policy type that denied: "because no identity-based policy allows the X action" (nothing allows it), "with an explicit deny in a service control policy: arn:..." (a Deny wins over every Allow), "because no permissions boundary allows", "because no resource-based policy allows" (a KMS key policy).
- Ubuntu 26.04's
apt install awscligives 2.31.35 (Debian's packaging, behind upstream). The official installer (awscli-exe-linux-aarch64.zip) gives the current release under /usr/local/aws-cli. - Credentials in environment variables beat AWS_PROFILE. An old
export AWS_ACCESS_KEY_ID=...in ~/.bashrc silently overrides every profile -aws configure listshows where each value comes from. - Output is sent to a pager (less) on a terminal. Scripts and CI: AWS_PAGER="" or --no-cli-pager.
Taught in
- 35.1 AWS for Azure people: accounts, regions, ARNs and the API
- 35.2 The AWS CLI v2: install, configure, profiles and the credential chain
- 35.5 Output, --query, pagination and reading errors
- 35.8 IAM: principals, groups, policies and the policy language
- 35.10 Policy evaluation: how AWS decides, and reading AccessDenied
- 35.14 Roles and STS: trust policies, assume-role and temporary credentials
- 35.18 Access keys: rotation, leaks and CloudTrail
- 35.22 S3: buckets, keys, prefixes and the s3 commands
Try aws in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.