OnCallReady

Commands

aws - Universal Command Line Interface for Amazon Web Services (AWS CLI v2)

aws [options] <command> <subcommand> [parameters]

Options you will use

--profile NAME
Use this named profile from ~/.aws/config and ~/.aws/credentials (also AWS_PROFILE). With --profile, AWS_ACCESS_KEY_ID in the environment is ignored.
--region REGION
The Region to send the request to (also AWS_REGION, AWS_DEFAULT_REGION, the profile's region). IAM is global; most services are regional.
--output FORMAT
json (default), text (tab separated, for shell loops), table, yaml, yaml-stream, off.
--query EXPR
A JMESPath expression applied by the CLI to the response, after pagination: Users[].UserName, Buckets[?starts_with(Name, oncall)].Name. Quote it in single quotes.
--no-paginate
Only the first page (the service's own page size), with the service's marker in the output.
--max-items N
Print at most N items and a NextToken to continue with --starting-token (paginated operations).
--page-size N
The size of each API page; the CLI still fetches every page. For calls that time out on big pages.
--debug
Log every step: the credential chain, the request, the response headers. Goes to stderr.
--no-cli-pager
Do not send the output to a pager (also AWS_PAGER="" or cli_pager = in the config).
--cli-error-format FORMAT
enhanced (default since 2.34: aws: [ERROR]: ...), json, yaml, text, table, legacy (the old "An error occurred ..." text).
--cli-binary-format FMT
base64 (default in v2: blob parameters are base64 text) or raw-in-base64-out (blobs given as raw text).
--endpoint-url URL
Send the request to another endpoint (LocalStack, a VPC endpoint, FIPS).
--no-sign-request
Send the request without credentials (anonymous): only works on public resources.
--generate-cli-skeleton
Print the JSON skeleton of the operation's parameters (fill it in, then --cli-input-json file://x.json).

Examples

$ aws sts get-caller-identity

who am I: account, user or role ARN

$ aws configure list

which credentials and region the CLI would use, and from where

$ aws iam list-users --query 'Users[].UserName' --output text

one line of names, for a shell loop

$ aws s3 ls s3://bucket/prefix/ --recursive --human-readable --summarize

what is in a bucket, how big

$ aws sts assume-role --role-arn ARN --role-session-name me

temporary credentials for a role

Gotchas

Taught in

Try aws in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.