AWS CLI Cheat Sheet: Profiles, SSO, S3, EC2, IAM and Useful Queries

· 1 min read · AWS Tutorials

AWS CLI quick reference #

The AWS CLI is the base of automation scripts and what Terraform uses for credentials. Installation is in install AWS CLI. This page uses AWS CLI v2.

Configure credentials #

$ aws configure                         # default profile (access keys)
$ aws configure --profile demo
$ aws configure sso                     # recommended: IAM Identity Center
$ aws sso login --profile demo
$ aws sts get-caller-identity           # who am I?
$ export AWS_PROFILE=demo
$ export AWS_REGION=eu-west-1

Prefer SSO or roles to long-lived access keys (IAM Identity Center, IAM roles). Files: ~/.aws/config and ~/.aws/credentials. A profile that assumes a role:

~/.aws/config
[profile admin]
role_arn       = arn:aws:iam::111111111111:role/Admin
source_profile = demo
region         = eu-west-1

Terraform and OpenTofu read the same profile: see the AWS provider.

Output and queries #

$ aws ec2 describe-instances --output table
$ aws ec2 describe-instances --query "Reservations[].Instances[].InstanceId" --output text
$ aws ec2 describe-instances \
    --query "Reservations[].Instances[].{id:InstanceId,type:InstanceType,state:State.Name}" \
    --output table
$ aws ec2 describe-instances --filters "Name=tag:Environment,Values=dev"
$ aws ec2 describe-instances --no-cli-pager

--query uses JMESPath to filter the JSON output in the client, and --filters filters on the server. Use --output json|text|table|yaml.

S3 #

$ aws s3 ls
$ aws s3 ls s3://my-bucket --recursive --human-readable --summarize
$ aws s3 cp file.txt s3://my-bucket/
$ aws s3 sync ./public s3://my-bucket --delete
$ aws s3 rm s3://my-bucket/prefix/ --recursive
$ aws s3 presign s3://my-bucket/file.txt --expires-in 3600
$ aws s3api get-bucket-encryption --bucket my-bucket

See S3 with Terraform.

EC2 and networking #

$ aws ec2 describe-instances --query "Reservations[].Instances[].[InstanceId,State.Name,PrivateIpAddress]" --output table
$ aws ec2 start-instances --instance-ids i-0abc123
$ aws ec2 stop-instances --instance-ids i-0abc123
$ aws ec2 describe-vpcs --query "Vpcs[].[VpcId,CidrBlock]" --output table
$ aws ec2 describe-subnets --filters "Name=vpc-id,Values=vpc-0abc123"
$ aws ec2 describe-security-groups --group-ids sg-0abc123
$ aws ec2 describe-images --owners amazon --filters "Name=name,Values=al2023-ami-*" --query "sort_by(Images,&CreationDate)[-1].ImageId"
$ aws ec2 describe-availability-zones --region eu-west-1

Terraform equivalents: EC2, VPC, security groups.

IAM and STS #

$ aws iam list-users
$ aws iam list-roles --query "Roles[].RoleName"
$ aws iam get-role --role-name my-role
$ aws iam list-attached-role-policies --role-name my-role
$ aws iam simulate-principal-policy --policy-source-arn <arn> --action-names s3:GetObject
$ aws sts assume-role --role-arn <arn> --role-session-name test

Systems Manager and secrets #

$ aws ssm start-session --target i-0abc123
$ aws ssm get-parameter --name /pro/app/key --with-decryption
$ aws secretsmanager get-secret-value --secret-id pro/app/api-key

See Session Manager and KMS and secrets.

Lambda, logs and CloudFormation #

$ aws lambda list-functions --query "Functions[].FunctionName"
$ aws lambda invoke --function-name my-fn --payload '{"a":1}' --cli-binary-format raw-in-base64-out out.json
$ aws logs tail /aws/lambda/my-fn --follow
$ aws logs filter-log-events --log-group-name /my/app --filter-pattern ERROR
$ aws cloudformation list-stacks
$ aws cloudformation describe-stack-events --stack-name my-stack

See Lambda, CloudWatch and CloudFormation.

Containers and Kubernetes #

$ aws ecr get-login-password | docker login --username AWS --password-stdin 111111111111.dkr.ecr.eu-west-1.amazonaws.com
$ aws ecs list-clusters
$ aws eks update-kubeconfig --name my-cluster

Cost and account #

$ aws ce get-cost-and-usage --time-period Start=2026-09-01,End=2026-10-01 \
    --granularity MONTHLY --metrics UnblendedCost --group-by Type=DIMENSION,Key=SERVICE
$ aws organizations list-accounts

See cost optimization.

Pagination and scripts #

  • --max-items, --page-size and --no-paginate control pagination.
  • --dry-run on many EC2 commands checks permissions without doing anything.
  • --cli-input-json file://input.json and --generate-cli-skeleton help with complex calls.
  • aws <service> help and aws <service> <command> help show the manual.
  • In scripts use set -euo pipefail and check the exit code.
  • aws configure list shows where the credentials in use come from, useful when Terraform cannot authenticate.

#AWS #Aws Cli