AWS CLI
Profiles and identity, S3, EC2, CloudWatch logs, SSM sessions and ECR login.
Profiles and identity
Who am I
aws sts get-caller-identityConfigure a profile
aws configure --profile <profile>
Log in with SSO
aws sso login --profile <profile>
Use a profile for the whole shell
export AWS_PROFILE=<profile>
S3
List buckets
aws s3 lsList objects with sizes
aws s3 ls s3://<bucket>/<prefix> --recursive --human-readable --summarize
Upload or download a file
aws s3 cp <file> s3://<bucket>/<prefix>
Sync a directory
aws s3 sync ./dist s3://<bucket>/ --delete
Temporary download link (1 hour)
aws s3 presign s3://<bucket>/<s3_key> --expires-in 3600
EC2
Running instances: id, type, IP, name
aws ec2 describe-instances \
--filters Name=instance-state-name,Values=running \
--query 'Reservations[].Instances[].[InstanceId,InstanceType,PrivateIpAddress,Tags[?Key==`Name`]|[0].Value]' \
--output tableStart or stop an instance
aws ec2 stop-instances --instance-ids <instance_id>
Shell into an instance via SSM (no SSH)advanced
aws ssm start-session --target <instance_id>
Logs and containers
Follow CloudWatch logs
aws logs tail <log_group> --follow --since 10m
Filter logs by a patternadvanced
aws logs tail <log_group> --since 1h --filter-pattern ERROR
Docker login to ECR
aws ecr get-login-password --region <region> | docker login --username AWS --password-stdin <account_id>.dkr.ecr.<region>.amazonaws.com
Update kubeconfig for an EKS cluster
aws eks update-kubeconfig --name <cluster> --region <region>
Read a secret from Secrets Manageradvanced
aws secretsmanager get-secret-value --secret-id <aws_secret> --query SecretString --output text