# AWS CLI Cheat Sheet: Profiles, SSO, S3, EC2, IAM and Useful Queries

> A quick reference for the AWS CLI: profiles and SSO, plus the most used commands for S3, EC2, IAM, Lambda and logs, with --query and --output examples.

- Source: https://www.itwonderlab.com/aws-cli-cheat-sheet/
- Published: 2026-01-28
- Updated: 2026-01-28
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

## AWS CLI quick reference

The AWS CLI is the base of automation scripts and what Terraform uses for credentials. Installation is in [install AWS CLI](https://www.itwonderlab.com/install-aws-cli/). This page uses AWS CLI v2.

### Configure credentials

```shell
$ aws configure                         # default profile (access keys)
$ aws configure --profile demo
$ aws configure sso                     # recommended: IAM Identity Center
$ aws sso login --profile demo
$ aws sts get-caller-identity           # who am I?
$ export AWS_PROFILE=demo
$ export AWS_REGION=eu-west-1
```

Prefer **SSO or roles** to long-lived access keys ([IAM Identity Center](https://www.itwonderlab.com/aws-iam-identity-center/), [IAM roles](https://www.itwonderlab.com/aws-terraform-tutorial-aws-iam-roles-policies/)). Files: `~/.aws/config` and `~/.aws/credentials`. A profile that assumes a role:

```ini title="~/.aws/config"
[profile admin]
role_arn       = arn:aws:iam::111111111111:role/Admin
source_profile = demo
region         = eu-west-1
```

Terraform and OpenTofu read the same profile: see [the AWS provider](https://www.itwonderlab.com/aws-terraform-tutorial-terraform-aws-provider/).

### Output and queries

```shell
$ aws ec2 describe-instances --output table
$ aws ec2 describe-instances --query "Reservations[].Instances[].InstanceId" --output text
$ aws ec2 describe-instances \
    --query "Reservations[].Instances[].{id:InstanceId,type:InstanceType,state:State.Name}" \
    --output table
$ aws ec2 describe-instances --filters "Name=tag:Environment,Values=dev"
$ aws ec2 describe-instances --no-cli-pager
```

`--query` uses JMESPath to filter the JSON output in the client, and `--filters` filters on the server. Use `--output json|text|table|yaml`.

### S3

```shell
$ aws s3 ls
$ aws s3 ls s3://my-bucket --recursive --human-readable --summarize
$ aws s3 cp file.txt s3://my-bucket/
$ aws s3 sync ./public s3://my-bucket --delete
$ aws s3 rm s3://my-bucket/prefix/ --recursive
$ aws s3 presign s3://my-bucket/file.txt --expires-in 3600
$ aws s3api get-bucket-encryption --bucket my-bucket
```

See [S3 with Terraform](https://www.itwonderlab.com/aws-terraform-tutorial-aws-s3/).

### EC2 and networking

```shell
$ aws ec2 describe-instances --query "Reservations[].Instances[].[InstanceId,State.Name,PrivateIpAddress]" --output table
$ aws ec2 start-instances --instance-ids i-0abc123
$ aws ec2 stop-instances --instance-ids i-0abc123
$ aws ec2 describe-vpcs --query "Vpcs[].[VpcId,CidrBlock]" --output table
$ aws ec2 describe-subnets --filters "Name=vpc-id,Values=vpc-0abc123"
$ aws ec2 describe-security-groups --group-ids sg-0abc123
$ aws ec2 describe-images --owners amazon --filters "Name=name,Values=al2023-ami-*" --query "sort_by(Images,&CreationDate)[-1].ImageId"
$ aws ec2 describe-availability-zones --region eu-west-1
```

Terraform equivalents: [EC2](https://www.itwonderlab.com/aws-terraform-tutorial-aws-ec2/), [VPC](https://www.itwonderlab.com/aws-terraform-tutorial-aws-vpc/), [security groups](https://www.itwonderlab.com/aws-terraform-tutorial-aws-security-groups/).

### IAM and STS

```shell
$ aws iam list-users
$ aws iam list-roles --query "Roles[].RoleName"
$ aws iam get-role --role-name my-role
$ aws iam list-attached-role-policies --role-name my-role
$ aws iam simulate-principal-policy --policy-source-arn <arn> --action-names s3:GetObject
$ aws sts assume-role --role-arn <arn> --role-session-name test
```

### Systems Manager and secrets

```shell
$ aws ssm start-session --target i-0abc123
$ aws ssm get-parameter --name /pro/app/key --with-decryption
$ aws secretsmanager get-secret-value --secret-id pro/app/api-key
```

See [Session Manager](https://www.itwonderlab.com/terraform-aws-ssm-session-manager/) and [KMS and secrets](https://www.itwonderlab.com/terraform-aws-kms-secrets-manager/).

### Lambda, logs and CloudFormation

```shell
$ aws lambda list-functions --query "Functions[].FunctionName"
$ aws lambda invoke --function-name my-fn --payload '{"a":1}' --cli-binary-format raw-in-base64-out out.json
$ aws logs tail /aws/lambda/my-fn --follow
$ aws logs filter-log-events --log-group-name /my/app --filter-pattern ERROR
$ aws cloudformation list-stacks
$ aws cloudformation describe-stack-events --stack-name my-stack
```

See [Lambda](https://www.itwonderlab.com/terraform-aws-lambda-api-gateway/), [CloudWatch](https://www.itwonderlab.com/terraform-aws-cloudwatch-alarms/) and [CloudFormation](https://www.itwonderlab.com/aws-cloudformation/).

### Containers and Kubernetes

```shell
$ aws ecr get-login-password | docker login --username AWS --password-stdin 111111111111.dkr.ecr.eu-west-1.amazonaws.com
$ aws ecs list-clusters
$ aws eks update-kubeconfig --name my-cluster
```

### Cost and account

```shell
$ aws ce get-cost-and-usage --time-period Start=2026-09-01,End=2026-10-01 \
    --granularity MONTHLY --metrics UnblendedCost --group-by Type=DIMENSION,Key=SERVICE
$ aws organizations list-accounts
```

See [cost optimization](https://www.itwonderlab.com/aws-cost-optimization-finops/).

### Pagination and scripts

- `--max-items`, `--page-size` and `--no-paginate` control pagination.
- `--dry-run` on many EC2 commands checks permissions without doing anything.
- `--cli-input-json file://input.json` and `--generate-cli-skeleton` help with complex calls.
- `aws <service> help` and `aws <service> <command> help` show the manual.
- In scripts use `set -euo pipefail` and check the exit code.
- `aws configure list` shows where the credentials in use come from, useful when [Terraform cannot authenticate](https://www.itwonderlab.com/terraform-common-errors/).
