AWS CLI Cheat Sheet: Profiles, SSO, S3, EC2, IAM and Useful Queries
AWS CLI quick reference #
The AWS CLI is the base of automation scripts and what Terraform uses for credentials. Installation is in install AWS CLI. This page uses AWS CLI v2.
Configure credentials #
$ aws configure # default profile (access keys)
$ aws configure --profile demo
$ aws configure sso # recommended: IAM Identity Center
$ aws sso login --profile demo
$ aws sts get-caller-identity # who am I?
$ export AWS_PROFILE=demo
$ export AWS_REGION=eu-west-1
Prefer SSO or roles to long-lived access keys (IAM Identity Center, IAM roles). Files: ~/.aws/config and ~/.aws/credentials. A profile that assumes a role:
[profile admin]
role_arn = arn:aws:iam::111111111111:role/Admin
source_profile = demo
region = eu-west-1Terraform and OpenTofu read the same profile: see the AWS provider.
Output and queries #
$ aws ec2 describe-instances --output table
$ aws ec2 describe-instances --query "Reservations[].Instances[].InstanceId" --output text
$ aws ec2 describe-instances \
--query "Reservations[].Instances[].{id:InstanceId,type:InstanceType,state:State.Name}" \
--output table
$ aws ec2 describe-instances --filters "Name=tag:Environment,Values=dev"
$ aws ec2 describe-instances --no-cli-pager
--query uses JMESPath to filter the JSON output in the client, and --filters filters on the server. Use --output json|text|table|yaml.
S3 #
$ aws s3 ls
$ aws s3 ls s3://my-bucket --recursive --human-readable --summarize
$ aws s3 cp file.txt s3://my-bucket/
$ aws s3 sync ./public s3://my-bucket --delete
$ aws s3 rm s3://my-bucket/prefix/ --recursive
$ aws s3 presign s3://my-bucket/file.txt --expires-in 3600
$ aws s3api get-bucket-encryption --bucket my-bucket
See S3 with Terraform.
EC2 and networking #
$ aws ec2 describe-instances --query "Reservations[].Instances[].[InstanceId,State.Name,PrivateIpAddress]" --output table
$ aws ec2 start-instances --instance-ids i-0abc123
$ aws ec2 stop-instances --instance-ids i-0abc123
$ aws ec2 describe-vpcs --query "Vpcs[].[VpcId,CidrBlock]" --output table
$ aws ec2 describe-subnets --filters "Name=vpc-id,Values=vpc-0abc123"
$ aws ec2 describe-security-groups --group-ids sg-0abc123
$ aws ec2 describe-images --owners amazon --filters "Name=name,Values=al2023-ami-*" --query "sort_by(Images,&CreationDate)[-1].ImageId"
$ aws ec2 describe-availability-zones --region eu-west-1
Terraform equivalents: EC2, VPC, security groups.
IAM and STS #
$ aws iam list-users
$ aws iam list-roles --query "Roles[].RoleName"
$ aws iam get-role --role-name my-role
$ aws iam list-attached-role-policies --role-name my-role
$ aws iam simulate-principal-policy --policy-source-arn <arn> --action-names s3:GetObject
$ aws sts assume-role --role-arn <arn> --role-session-name test
Systems Manager and secrets #
$ aws ssm start-session --target i-0abc123
$ aws ssm get-parameter --name /pro/app/key --with-decryption
$ aws secretsmanager get-secret-value --secret-id pro/app/api-key
See Session Manager and KMS and secrets.
Lambda, logs and CloudFormation #
$ aws lambda list-functions --query "Functions[].FunctionName"
$ aws lambda invoke --function-name my-fn --payload '{"a":1}' --cli-binary-format raw-in-base64-out out.json
$ aws logs tail /aws/lambda/my-fn --follow
$ aws logs filter-log-events --log-group-name /my/app --filter-pattern ERROR
$ aws cloudformation list-stacks
$ aws cloudformation describe-stack-events --stack-name my-stack
See Lambda, CloudWatch and CloudFormation.
Containers and Kubernetes #
$ aws ecr get-login-password | docker login --username AWS --password-stdin 111111111111.dkr.ecr.eu-west-1.amazonaws.com
$ aws ecs list-clusters
$ aws eks update-kubeconfig --name my-cluster
Cost and account #
$ aws ce get-cost-and-usage --time-period Start=2026-09-01,End=2026-10-01 \
--granularity MONTHLY --metrics UnblendedCost --group-by Type=DIMENSION,Key=SERVICE
$ aws organizations list-accounts
See cost optimization.
Pagination and scripts #
--max-items,--page-sizeand--no-paginatecontrol pagination.--dry-runon many EC2 commands checks permissions without doing anything.--cli-input-json file://input.jsonand--generate-cli-skeletonhelp with complex calls.aws <service> helpandaws <service> <command> helpshow the manual.- In scripts use
set -euo pipefailand check the exit code. aws configure listshows where the credentials in use come from, useful when Terraform cannot authenticate.