AWS CLI Cheat Sheet
AWS CLI Cheat Sheet
Section titled “AWS CLI Cheat Sheet”One-page quick reference for AWS CLI commands. Bookmark this for daily use. All commands use the
awsCLI v2.
AWS Services Overview
Section titled “AWS Services Overview”flowchart TB AWS[\"☁️ AWS Cloud\"] --> Compute[\"🖥️ Compute\"] --> EC2[\"EC2<br/>Virtual Servers\"] Compute --> Lambda[\"⚡ Lambda<br/>Serverless Functions\"] Compute --> EB[\"Beanstalk<br/>PaaS Deploy\"]
AWS --> Storage[\"💾 Storage\"] --> S3[\"S3<br/>Object Storage\"] Storage --> EBS[\"EBS<br/>Block Storage\"] Storage --> EFS[\"EFS<br/>File Storage\"]
AWS --> DB[\"🗄️ Database\"] --> RDS[\"RDS<br/>SQL Databases\"] DB --> DynamoDB[\"DynamoDB<br/>NoSQL\"] DB --> ElastiCache[\"ElastiCache<br/>Redis/Memcached\"]
AWS --> Network[\"🌐 Networking\"] --> VPC[\"VPC<br/>Virtual Network\"] Network --> CF[\"CloudFront<br/>CDN\"] Network --> R53[\"Route53<br/>DNS\"] Network --> ELB[\"ELB<br/>Load Balancer\"]
AWS --> Security[\"🔒 Security\"] --> IAM[\"IAM<br/>Access Control\"] Security --> KMS[\"KMS<br/>Encryption\"] Security --> WAF[\"WAF<br/>Web Firewall\"]
AWS --> Integration[\"🔗 Integration\"] --> SQS[\"SQS<br/>Message Queues\"] Integration --> SNS[\"SNS<br/>Notifications\"] Integration --> APIGW[\"API Gateway<br/>HTTP APIs\"]
AWS --> Tools[\"🛠️ DevOps\"] --> CFT[\"CloudFormation<br/>IaC\"] Tools --> CW[\"CloudWatch<br/>Monitoring\"] Tools --> CodePipeline[\"CodePipeline<br/>CI/CD\"]
style AWS fill:#7c3aed,color:#fff style Compute fill:#3b82f6,color:#fff style Storage fill:#059669,color:#fff style DB fill:#f59e0b,color:#fff style Network fill:#ef4444,color:#fff style Security fill:#dc2626,color:#fff style Integration fill:#6366f1,color:#fff style Tools fill:#10b981,color:#fff🔧 CLI Setup & Common Flags
Section titled “🔧 CLI Setup & Common Flags”# Configure CLIaws configure # Set access key, secret, region, outputaws configure set region us-east-1 # Set default regionaws configure list # Show current config
# Profile managementaws configure --profile production # Create named profileaws s3 ls --profile production # Use named profileexport AWS_PROFILE=production # Set active profile
# Common flags--region us-east-1 # Override region--output json | table | text # Output format--profile my-profile # Use specific profile--query 'Reservations[].Instances[].InstanceId' # JMESPath query filter--no-sign-request # Access public resources without auth--dry-run # Validate without executing
# Helpaws help # General helpaws ec2 help # Service-specific helpaws ec2 run-instances help # Command-specific help👤 IAM — Identity & Access Management
Section titled “👤 IAM — Identity & Access Management”# Usersaws iam create-user --user-name aliceaws iam list-users --query 'Users[*].[UserName,UserId]' --output tableaws iam get-user --user-name aliceaws iam delete-user --user-name alice
# Groupsaws iam create-group --group-name developersaws iam add-user-to-group --user-name alice --group-name developersaws iam list-groups-for-user --user-name aliceaws iam remove-user-from-group --user-name alice --group-name developers
# Policiesaws iam create-policy --policy-name my-policy --policy-document file://policy.jsonaws iam attach-user-policy --user-name alice --policy-arn arn:aws:iam::123:policy/my-policyaws iam attach-group-policy --group-name developers --policy-arn arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccessaws iam list-attached-user-policies --user-name alice
# Rolesaws iam create-role --role-name ec2-s3-access --assume-role-policy-document file://trust-policy.jsonaws iam attach-role-policy --role-name ec2-s3-access --policy-arn arn:aws:iam::aws:policy/AmazonS3FullAccess
# Keys & securityaws iam create-access-key --user-name aliceaws iam list-access-keys --user-name aliceaws iam update-access-key --access-key-id AKIA... --status Inactive --user-name aliceaws iam delete-access-key --access-key-id AKIA... --user-name alice🖥️ EC2 — Virtual Servers
Section titled “🖥️ EC2 — Virtual Servers”# Instancesaws ec2 run-instances --image-id ami-0c55b159cbfafe1f0 --instance-type t2.micro --key-name my-key --security-groups web-sgaws ec2 describe-instances --filters "Name=instance-state-name,Values=running"aws ec2 describe-instances --query 'Reservations[].Instances[].{ID:InstanceId,Type:InstanceType,State:State.Name}'aws ec2 stop-instances --instance-ids i-1234567890abcdef0aws ec2 start-instances --instance-ids i-1234567890abcdef0aws ec2 terminate-instances --instance-ids i-1234567890abcdef0aws ec2 reboot-instances --instance-ids i-1234567890abcdef0
# Security groupsaws ec2 create-security-group --group-name web-sg --description "Web server SG"aws ec2 authorize-security-group-ingress --group-id sg-123 --protocol tcp --port 80 --cidr 0.0.0.0/0aws ec2 authorize-security-group-ingress --group-id sg-123 --protocol tcp --port 22 --cidr 203.0.113.0/32aws ec2 revoke-security-group-ingress --group-id sg-123 --protocol tcp --port 22 --cidr 0.0.0.0/0aws ec2 describe-security-groups --group-ids sg-123
# Key pairsaws ec2 create-key-pair --key-name my-key --query 'KeyMaterial' --output text > my-key.pemaws ec2 describe-key-pairsaws ec2 delete-key-pair --key-name my-key
# AMIs & snapshotsaws ec2 describe-images --owners amazon --filters "Name=name,Values=amzn2-ami-*" --query 'Images[*].[ImageId,Name]' --output tableaws ec2 create-image --instance-id i-123 --name "My Backup $(date +%Y-%m-%d)"aws ec2 describe-snapshots --owner-ids selfaws ec2 create-snapshot --volume-id vol-123 --description "Pre-update snapshot"
# EBS volumesaws ec2 describe-volumesaws ec2 attach-volume --volume-id vol-123 --instance-id i-456 --device /dev/xvdfaws ec2 create-volume --volume-type gp3 --size 100 --availability-zone us-east-1a
# Tagsaws ec2 create-tags --resources i-123 --tags Key=Environment,Value=Production Key=Name,Value=WebServeraws ec2 describe-tags --filters "Name=resource-id,Values=i-123"
# Elastic IPaws ec2 allocate-address --domain vpcaws ec2 associate-address --instance-id i-123 --allocation-id eipalloc-456aws ec2 release-address --allocation-id eipalloc-456⚡ Lambda — Serverless Functions
Section titled “⚡ Lambda — Serverless Functions”# Functionsaws lambda create-function --function-name process-uploads --runtime python3.12 --role arn:aws:iam::123:role/lambda-exec --handler lambda_function.lambda_handler --zip-file fileb://function.zipaws lambda list-functions --query 'Functions[*].[FunctionName,Runtime,MemorySize]' --output tableaws lambda get-function --function-name process-uploadsaws lambda update-function-code --function-name process-uploads --zip-file fileb://function.zipaws lambda update-function-configuration --function-name process-uploads --memory-size 512 --timeout 30aws lambda delete-function --function-name process-uploads
# Invokeaws lambda invoke --function-name process-uploads --payload '{"key":"value"}' response.jsonaws lambda invoke --function-name process-uploads --invocation-type Event --payload file://event.json output.txt
# Permissionsaws lambda add-permission --function-name process-uploads --statement-id s3-invoke --action lambda:InvokeFunction --principal s3.amazonaws.com --source-arn arn:aws:s3:::my-bucket
# Event source mappingsaws lambda create-event-source-mapping --function-name process-uploads --event-source-arn arn:aws:sqs:us-east-1:123:my-queue --batch-size 10aws lambda list-event-source-mappings --function-name process-uploads
# Versions & aliasesaws lambda publish-version --function-name process-uploadsaws lambda create-alias --function-name process-uploads --name prod --function-version 2aws lambda update-alias --function-name process-uploads --name prod --function-version 3
# Concurrencyaws lambda put-function-concurrency --function-name process-uploads --reserved-concurrent-executions 10aws lambda delete-function-concurrency --function-name process-uploads💾 S3 — Object Storage
Section titled “💾 S3 — Object Storage”# Bucketsaws s3 mb s3://my-app-assets --region us-east-1aws s3 ls # List all bucketsaws s3api list-buckets --query 'Buckets[*].[Name,CreationDate]' --output tableaws s3 rb s3://my-app-assets --force # Remove bucket (must be empty first)
# Objectsaws s3 cp index.html s3://my-app-assets/aws s3 cp logo.png s3://my-app-assets/images/ --acl public-readaws s3 cp s3://my-app-assets/index.html ./downloads/aws s3 sync ./build s3://my-app-assets/ # Sync local folder → S3aws s3 sync s3://my-app-assets ./backup/ # Sync S3 → localaws s3 mv s3://bucket/old.jpg s3://bucket/new.jpgaws s3 rm s3://my-app-assets/old-file.txtaws s3 rm s3://my-app-assets/ --recursive # Delete all objects
# Listing & filtersaws s3 ls s3://my-app-assets/ # List rootaws s3 ls s3://my-app-assets/images/ # List "folder"aws s3 ls s3://my-app-assets/ --recursive # List allaws s3 ls s3://my-app-assets/ --human-readable --summarizeaws s3api list-objects --bucket my-app-assets --query 'Contents[?Size > `1000000`].[Key,Size]'
# Presigned URLsaws s3 presign s3://my-app-assets/private-file.pdf --expires-in 3600 # 1 hour URLaws s3 presign s3://my-app-assets/private-file.pdf --expires-in 86400 # 24 hours
# Static websiteaws s3 website s3://my-app-assets --index-document index.html --error-document error.html
# Bucket policyaws s3api get-bucket-policy --bucket my-app-assetsaws s3api put-bucket-policy --bucket my-app-assets --policy file://policy.json
# Versioning & encryptionaws s3api put-bucket-versioning --bucket my-app-assets --versioning-configuration Status=Enabledaws s3api put-bucket-encryption --bucket my-app-assets --server-side-encryption-configuration '{"Rules":[{"ApplyServerSideEncryptionByDefault":{"SSEAlgorithm":"AES256"}}]}'
# Lifecycle rulesaws s3api put-bucket-lifecycle-configuration --bucket my-app-assets --lifecycle-configuration file://lifecycle.json
# Multipart (large files)aws s3 cp large-file.iso s3://my-app-assets/ # Auto-uses multipart for files > 100MB🗄️ RDS & DynamoDB — Databases
Section titled “🗄️ RDS & DynamoDB — Databases”# RDSaws rds create-db-instance --db-instance-identifier mydb --db-instance-class db.t3.micro --engine postgres --master-username admin --master-user-password secret123 --allocated-storage 20aws rds describe-db-instances --query 'DBInstances[*].[DBInstanceIdentifier,DBInstanceClass,DBInstanceStatus]' --output tableaws rds modify-db-instance --db-instance-identifier mydb --db-instance-class db.t3.small --apply-immediatelyaws rds reboot-db-instance --db-instance-identifier mydbaws rds delete-db-instance --db-instance-identifier mydb --skip-final-snapshot
# RDS snapshotsaws rds create-db-snapshot --db-instance-identifier mydb --db-snapshot-identifier mydb-pre-upgradeaws rds describe-db-snapshots --db-instance-identifier mydbaws rds restore-db-instance-from-db-snapshot --db-instance-identifier mydb-restored --db-snapshot-identifier mydb-pre-upgrade
# RDS read replicasaws rds create-db-instance-read-replica --db-instance-identifier mydb-read --source-db-instance-identifier mydb
# DynamoDBaws dynamodb create-table --table-name users --attribute-definitions AttributeName=userId,AttributeType=S --key-schema AttributeName=userId,KeyType=HASH --billing-mode PAY_PER_REQUESTaws dynamodb list-tablesaws dynamodb describe-table --table-name usersaws dynamodb put-item --table-name users --item '{"userId":{"S":"u123"},"name":{"S":"Alice"},"email":{"S":"alice@example.com"}}'aws dynamodb get-item --table-name users --key '{"userId":{"S":"u123"}}'aws dynamodb query --table-name users --key-condition-expression "userId = :id" --expression-attribute-values '{":id":{"S":"u123"}}'aws dynamodb scan --table-name usersaws dynamodb update-item --table-name users --key '{"userId":{"S":"u123"}}' --update-expression "SET #n = :n" --expression-attribute-names '{"#n":"name"}' --expression-attribute-values '{":n":{"S":"Alice Smith"}}'aws dynamodb delete-table --table-name users🌐 VPC, Route53 & CloudFront — Networking
Section titled “🌐 VPC, Route53 & CloudFront — Networking”# VPCaws ec2 create-vpc --cidr-block 10.0.0.0/16aws ec2 describe-vpcsaws ec2 create-subnet --vpc-id vpc-123 --cidr-block 10.0.1.0/24 --availability-zone us-east-1aaws ec2 describe-subnets --filters "Name=vpc-id,Values=vpc-123"aws ec2 create-internet-gatewayaws ec2 attach-internet-gateway --vpc-id vpc-123 --internet-gateway-id igw-456aws ec2 create-nat-gateway --subnet-id subnet-pub --allocation-id eipalloc-789aws ec2 describe-route-tables --filters "Name=vpc-id,Values=vpc-123"aws ec2 create-route --route-table-id rtb-abc --destination-cidr-block 0.0.0.0/0 --gateway-id igw-456
# VPC Peeringaws ec2 create-vpc-peering-connection --vpc-id vpc-123 --peer-vpc-id vpc-456aws ec2 accept-vpc-peering-connection --vpc-peering-connection-id pcx-789aws ec2 create-route --route-table-id rtb-abc --destination-cidr-block 10.1.0.0/16 --vpc-peering-connection-id pcx-789
# Route53aws route53 create-hosted-zone --name example.com --caller-reference 2024-01-01aws route53 list-hosted-zonesaws route53 change-resource-record-sets --hosted-zone-id Z123 --change-batch file://records.jsonaws route53 list-resource-record-sets --hosted-zone-id Z123# records.json format: {"Changes":[{"Action":"UPSERT","ResourceRecordSet":{"Name":"www.example.com.","Type":"A","AliasTarget":{"HostedZoneId":"Z2FDTNDATAQYW2","DNSName":"d123.cloudfront.net"}}}]}
# CloudFrontaws cloudfront create-distribution --origin-domain-name my-app-assets.s3.us-east-1.amazonaws.com --default-root-object index.html --enabledaws cloudfront list-distributions --query 'DistributionList.Items[*].[Id,DomainName,Status]' --output tableaws cloudfront get-distribution --id E123456aws cloudfront create-invalidation --distribution-id E123456 --paths "/*" "/images/*"aws cloudfront update-distribution --id E123456 --distribution-config file://config.json
# ELB (Load Balancer)aws elbv2 create-load-balancer --name my-alb --subnets subnet-pub1 subnet-pub2 --security-groups sg-123aws elbv2 describe-load-balancersaws elbv2 create-target-group --name my-tg --protocol HTTP --port 80 --vpc-id vpc-123 --health-check-path /healthaws elbv2 register-targets --target-group-arn arn:aws:elasticloadbalancing:.../my-tg --targets Id=i-123 Id=i-456aws elbv2 create-listener --load-balancer-arn arn:aws:elasticloadbalancing:.../my-alb --protocol HTTP --port 80 --default-actions Type=forward,TargetGroupArn=arn:aws:.../my-tg
# Auto Scalingaws autoscaling create-auto-scaling-group --auto-scaling-group-name my-asg --launch-configuration-name my-lc --min-size 2 --max-size 10 --desired-capacity 2 --vpc-zone-identifier subnet-pub1,subnet-pub2aws autoscaling describe-auto-scaling-groupsaws autoscaling update-auto-scaling-group --auto-scaling-group-name my-asg --desired-capacity 4aws autoscaling attach-load-balancer-target-groups --auto-scaling-group-name my-asg --target-group-arns arn:aws:.../my-tgaws autoscaling put-scaling-policy --auto-scaling-group-name my-asg --policy-name cpu-target --policy-type TargetTrackingScaling --target-tracking-configuration '{ "TargetValue": 70.0, "PredefinedMetricSpecification": { "PredefinedMetricType": "ASGAverageCPUUtilization" } }'🔗 SQS, SNS & API Gateway — Messaging
Section titled “🔗 SQS, SNS & API Gateway — Messaging”# SQSaws sqs create-queue --queue-name my-app-queueaws sqs list-queuesaws sqs get-queue-url --queue-name my-app-queueaws sqs send-message --queue-url https://sqs.us-east-1.amazonaws.com/123/my-app-queue --message-body '{"orderId":123}'aws sqs send-message --queue-url https://sqs.us-east-1.amazonaws.com/123/my-app-queue --message-body '{"type":"urgent"}' --message-group-id orders --message-deduplication-id unique123aws sqs receive-message --queue-url https://sqs.us-east-1.amazonaws.com/123/my-app-queue --max-number-of-messages 10 --visibility-timeout 30aws sqs delete-message --queue-url https://sqs.us-east-1.amazonaws.com/123/my-app-queue --receipt-handle AQEB...aws sqs purge-queue --queue-url https://sqs.us-east-1.amazonaws.com/123/my-app-queueaws sqs delete-queue --queue-url https://sqs.us-east-1.amazonaws.com/123/my-app-queue
# SQS FIFO (strict ordering, exactly-once)aws sqs create-queue --queue-name my-app-queue.fifo --attributes FifoQueue=true,ContentBasedDeduplication=true
# SNSaws sns create-topic --name order-alertsaws sns list-topicsaws sns subscribe --topic-arn arn:aws:sns:us-east-1:123:order-alerts --protocol email --notification-endpoint admin@example.comaws sns subscribe --topic-arn arn:aws:sns:us-east-1:123:order-alerts --protocol lambda --notification-endpoint arn:aws:lambda:us-east-1:123:function:process-orderaws sns list-subscriptions-by-topic --topic-arn arn:aws:sns:us-east-1:123:order-alertsaws sns publish --topic-arn arn:aws:sns:us-east-1:123:order-alerts --message "New order #12345 received"aws sns publish --topic-arn arn:aws:sns:us-east-1:123:order-alerts --message-structure json --message '{"default":"New order","email":"<html>New order</html>"}'aws sns unsubscribe --subscription-arn arn:aws:sns:us-east-1:123:order-alerts:sub-xyzaws sns delete-topic --topic-arn arn:aws:sns:us-east-1:123:order-alerts
# API Gatewayaws apigateway create-rest-api --name my-api --region us-east-1aws apigateway get-rest-apisaws apigateway create-resource --rest-api-id abc123 --parent-id root-id --path-part usersaws apigateway put-method --rest-api-id abc123 --resource-id res456 --http-method GET --authorization-type NONEaws apigateway put-integration --rest-api-id abc123 --resource-id res456 --http-method GET --type AWS_PROXY --integration-http-method POST --uri arn:aws:apigateway:us-east-1:lambda:path/2015-03-31/functions/arn:aws:lambda:us-east-1:123:function:get-users/invocationsaws apigateway create-deployment --rest-api-id abc123 --stage-name prod🛠️ CloudFormation & CloudWatch — DevOps
Section titled “🛠️ CloudFormation & CloudWatch — DevOps”# CloudFormationaws cloudformation create-stack --stack-name my-web-app --template-body file://template.yaml --parameters ParameterKey=InstanceType,ParameterValue=t2.microaws cloudformation create-stack --stack-name my-web-app --template-url https://s3.amazonaws.com/bucket/template.yamlaws cloudformation list-stacks --stack-status-filter CREATE_COMPLETE UPDATE_COMPLETEaws cloudformation describe-stacks --stack-name my-web-appaws cloudformation describe-stack-events --stack-name my-web-appaws cloudformation update-stack --stack-name my-web-app --template-body file://template.yamlaws cloudformation delete-stack --stack-name my-web-app
# CloudFormation change sets (preview before applying)aws cloudformation create-change-set --stack-name my-web-app --template-body file://template.yaml --change-set-name my-changeaws cloudformation describe-change-set --change-set-name my-change --stack-name my-web-appaws cloudformation execute-change-set --change-set-name my-change --stack-name my-web-app
# CloudWatchaws logs describe-log-groups --query 'logGroups[*].[logGroupName,storedBytes]' --output tableaws logs describe-log-streams --log-group-name /aws/lambda/process-uploads --order-by LastEventTime --descending --limit 5aws logs filter-log-events --log-group-name /aws/lambda/process-uploads --filter-pattern "ERROR" --start-time $(date -d '1 hour ago' +%s%3N)aws logs get-log-events --log-group-name /aws/lambda/process-uploads --log-stream-name "2024/01/01/[$LATEST]abc123"
# CloudWatch metrics & alarmsaws cloudwatch list-metrics --namespace AWS/EC2 --metric-name CPUUtilizationaws cloudwatch get-metric-statistics --namespace AWS/EC2 --metric-name CPUUtilization --dimensions Name=InstanceId,Value=i-123 --start-time 2024-01-01T00:00:00Z --end-time 2024-01-02T00:00:00Z --period 3600 --statistics Averageaws cloudwatch put-metric-alarm --alarm-name high-cpu --alarm-description "CPU > 80%" --metric-name CPUUtilization --namespace AWS/EC2 --statistic Average --period 300 --evaluation-periods 2 --threshold 80 --comparison-operator GreaterThanThreshold --dimensions Name=InstanceId,Value=i-123 --alarm-actions arn:aws:sns:us-east-1:123:alerts
# CloudWatch logs to S3 (export)aws logs create-export-task --log-group-name /aws/lambda/process-uploads --from $(date -d '7 days ago' +%s%3N) --to $(date +%s%3N) --destination my-logs-bucket --destination-prefix lambda-logs💰 Cost Management
Section titled “💰 Cost Management”# Budgetsaws budgets create-budget --account-id 123456789012 --budget file://budget.json --notifications-with-subscribers file://subscribers.json# budget.json: {"BudgetName":"monthly-budget","BudgetLimit":{"Amount":"100","Unit":"USD"},"TimeUnit":"MONTHLY","BudgetType":"COST"}
# Cost Explorer (outputs JSON)aws ce get-cost-and-usage --time-period Start=2024-01-01,End=2024-01-31 --granularity MONTHLY --metrics BlendedCost --group-by Type=DIMENSION,Key=SERVICE
# Resource groups & taggingaws resourcegroupstaggingapi get-resources --tag-filters Key=Environment,Values=Productionaws resourcegroupstaggingapi get-tag-keys🚀 Quick Reference Tables
Section titled “🚀 Quick Reference Tables”EC2 Instance Families
| Family | Use Case | Example |
|---|---|---|
| t (burstable) | General purpose, low cost | t2.micro, t3.medium |
| m (general) | Balanced apps | m5.large, m6g.xlarge |
| c (compute) | CPU-intensive | c5.xlarge, c6g.2xlarge |
| r (memory) | RAM-intensive | r5.large, x1e.xlarge |
| g/p (GPU) | ML, rendering | g4dn.xlarge, p3.2xlarge |
S3 Storage Classes
| Class | Retrieval | Cost | Use Case |
|---|---|---|---|
| Standard | Instant | $$$ | Active data |
| Intelligent-Tiering | Instant | $$ | Unknown patterns |
| Standard-IA | Instant | $$ | Infrequent access |
| Glacier | Minutes | $ | Archives |
| Glacier Deep Archive | Hours | ¢ | Long-term |
AWS Regions Quick Pick
| Code | Location | Notes |
|---|---|---|
us-east-1 | N. Virginia | Oldest, most services |
us-east-2 | Ohio | Low latency for US |
us-west-2 | Oregon | Popular west coast |
eu-west-1 | Ireland | EU main region |
ap-southeast-1 | Singapore | Asia-Pacific |
📝 Pro Tips
Section titled “📝 Pro Tips”# JMESPath queries — filter JSON output like a proaws ec2 describe-instances --query 'Reservations[].Instances[?State.Name==`running`].{ID:InstanceId,Type:InstanceType,IP:PublicIpAddress}' --output table
# Combine with jq for complex processingaws ec2 describe-instances --region us-east-1 | jq '.Reservations[].Instances[] | {id: .InstanceId, type: .InstanceType}'
# Shell aliases for speedalias aws-instances='aws ec2 describe-instances --query "Reservations[].Instances[].{ID:InstanceId,Type:InstanceType,State:State.Name,IP:PublicIpAddress}" --output table'alias aws-cost='aws ce get-cost-and-usage --time-period Start=$(date +%Y-%m-01),End=$(date +%Y-%m-%d) --granularity MONTHLY --metrics BlendedCost --group-by Type=DIMENSION,Key=SERVICE --output table'
# Environment variables (instead of aws configure)export AWS_ACCESS_KEY_ID=AKIA...export AWS_SECRET_ACCESS_KEY=...export AWS_SESSION_TOKEN=... # For temporary credentials (STS)export AWS_DEFAULT_REGION=us-east-1export AWS_DEFAULT_OUTPUT=json
# MFA with STS (get temp credentials)aws sts get-session-token --serial-number arn:aws:iam::123:mfa/user --token-code 123456
# Assume role (cross-account access)aws sts assume-role --role-arn arn:aws:iam::456:role/deploy-role --role-session-name deploy-session
# Wait for resource state (great for scripts)aws ec2 wait instance-running --instance-ids i-123aws ec2 wait instance-terminated --instance-ids i-123aws s3api wait bucket-exists --bucket my-app-assetsIn Simple Words
Section titled “In Simple Words”aws configureis your first command — set up access keys, region, and output format- Use
--querywith JMESPath to filter JSON output without piping tojq - Tag everything (
Key=Environment,Value=Production) — makes cost tracking and filtering easy - Use
aws <service> waitin scripts to pause until resources are ready; enable tab completion withcomplete -C aws_completer aws - The
dateexamples (-d '1 hour ago') use GNU date — on macOS/BSD replace with-v-1H