All Exam Questions
Back to All Posts
Programming

AWS CLI Installation and Usage Guide: Setup, Commands, S3 Operations and Tutorial

September 4, 2026
AWS CLI Installation and Usage Guide: Setup, Commands, S3 Operations and Tutorial

What Is the AWS Command Line Interface

The AWS Command Line Interface, or AWS CLI, is a unified tool that lets you control AWS services directly from your terminal instead of navigating the web console. Once installed, a single command line tool gives you access to nearly every AWS service, from EC2 and S3 to IAM and Lambda.

The current version, AWS CLI v2, replaced the older pip based v1 installer with a proper standalone installer for each operating system. If you are setting this up for the first time, there is no reason to install v1 at all. Go straight to v2, since it includes newer features like SSO login support and better auto completion that v1 never received.

Why Use the AWS CLI Instead of the Console

A few reasons the CLI earns a permanent spot in most engineers' toolkits:

  • Repetitive tasks, like uploading hundreds of files or tagging dozens of resources, take one command instead of dozens of clicks

  • It integrates naturally into shell scripts, CI/CD pipelines, and cron jobs

  • Commands are reproducible and can be version controlled alongside your infrastructure code

  • It is often faster than waiting for console pages to load, especially over a slow connection

AWS CLI Installation

Installation differs slightly depending on your operating system, but the process is straightforward on all three major platforms.

Installing AWS CLI on Linux

AWS distributes a single zip installer that works across most modern Linux distributions, including Ubuntu, Debian, Amazon Linux, Fedora, and anything running a standard glibc environment.

curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip"
unzip awscliv2.zip
sudo ./aws/install

Once that finishes, confirm the install worked:

aws --version

Installing AWS CLI on macOS

macOS uses a standard PKG installer that works as a universal binary on both Intel and Apple Silicon Macs, so you do not need to worry about choosing the right architecture.

curl -o "AWSCLIV2.pkg" "https://awscli.amazonaws.com/AWSCLIV2.pkg"
sudo installer -pkg AWSCLIV2.pkg -target /

If you already use Homebrew, that route works too, though the official PKG installer is what AWS recommends and tends to get new releases first:

brew install awscli

Installing AWS CLI on Windows

Download the official MSI installer from AWS and run it, following the setup wizard through to completion. Once installed, open Command Prompt or PowerShell and confirm the install:

aws --version

You should see output similar to aws-cli/2.x.x confirming version 2 installed correctly.

Configuring the AWS CLI

Before you can run commands against your AWS account, you need to configure your credentials. Run the following command and follow the prompts:

aws configure

You will be asked for four pieces of information: your AWS Access Key ID, your AWS Secret Access Key, your default region, such as us-east-1, and your preferred output format, typically json.

Using Named Profiles

If you manage multiple AWS accounts, whether personal, work, or client accounts, named profiles let you switch between them without reconfiguring every time.

aws configure --profile myprofile

You can then run any command against that specific profile by adding the flag:

aws s3 ls --profile myprofile

A Safer Alternative: AWS SSO Login

If your organization uses IAM Identity Center, formerly AWS SSO, you can authenticate without storing long lived access keys locally at all.

aws configure sso
aws sso login --profile myprofile

This approach is worth adopting where available, since long lived access keys sitting in a config file are a common source of accidental credential leaks.

Essential AWS CLI Commands

Once configured, most AWS CLI commands follow a predictable pattern: aws, followed by the service name, followed by the action.

aws <service> <action> [options]

Here are commands you will reach for constantly across almost any AWS workflow.

Checking Your Identity and Account

aws sts get-caller-identity

This confirms exactly which account and IAM identity your CLI session is currently authenticated as, which is the first thing to check when a command behaves unexpectedly.

Listing and Managing EC2 Instances

aws ec2 describe-instances
aws ec2 start-instances --instance-ids i-0abcd1234efgh5678
aws ec2 stop-instances --instance-ids i-0abcd1234efgh5678

Working with IAM

aws iam list-users
aws iam list-roles

Filtering Output with Query

The CLI supports JMESPath queries through the --query flag, which lets you pull out exactly the fields you need instead of parsing full JSON responses manually.

aws ec2 describe-instances --query "Reservations[].Instances[].InstanceId"

AWS CLI Commands for S3

S3 is one of the services people script against most heavily, since moving files in bulk through the console gets tedious fast. Here are the AWS CLI S3 commands you will use most often.

Listing Buckets and Objects

aws s3 ls
aws s3 ls s3://your-bucket-name

The first command lists every bucket in your account. The second lists the objects inside a specific bucket.

Creating and Removing Buckets

aws s3 mb s3://your-new-bucket-name
aws s3 rb s3://your-bucket-name

Add --force to the remove bucket command if the bucket still contains objects and you want to delete everything inside it along with the bucket itself.

Uploading and Downloading Files

aws s3 cp localfile.txt s3://your-bucket-name/
aws s3 cp s3://your-bucket-name/remotefile.txt ./

Syncing Entire Directories

The sync command is where the CLI really saves time, since it only transfers files that have changed rather than re-uploading everything every time.

aws s3 sync ./local-folder s3://your-bucket-name/folder

This is commonly used in deployment scripts to push a static website or build artifact to S3 without manually tracking which files changed.

Deleting Objects

aws s3 rm s3://your-bucket-name/filename.txt
aws s3 rm s3://your-bucket-name/folder --recursive

The --recursive flag is required when deleting a folder's worth of objects rather than a single file.

Setting Object Permissions

aws s3 cp localfile.txt s3://your-bucket-name/ --acl public-read

Be deliberate with this one. Making objects public read is sometimes exactly what you want for static website hosting, but it is also a common source of accidental data exposure when applied without thinking through who should actually have access.

Common AWS CLI Mistakes to Avoid

A few mistakes come up repeatedly with people newer to the CLI.

  1. Forgetting to set a default region, which causes commands to fail or silently target the wrong region.

  2. Hardcoding access keys into scripts instead of using named profiles or IAM roles, which creates a security risk if that script ends up in version control.

  3. Using rm without --recursive on a folder and being confused when nothing gets deleted, since S3 does not have real folders, only key prefixes.

  4. Not using --dry-run on destructive sync or delete commands before running them for real, which the CLI supports on most commands that modify or remove data.

Conclusion

The AWS CLI turns repetitive console clicking into commands you can run in seconds, script into automation, and reuse across projects. Once you have it installed and configured with either access keys or SSO login, the pattern of aws followed by a service and an action covers the vast majority of what you will do day to day, and the S3 commands covered here handle the file management tasks that come up constantly in real projects. From here, the best next step is opening a terminal and running aws configure against a test account so the commands become familiar before you rely on them for production work.

Frequently Asked Questions

AllExamQuestions Editorial Team

AllExamQuestions Editorial Team

AllExamQuestions Editorial Team creates high-quality exam preparation content, practice resources, and certification guides to help learners achieve their goals.

Our content is carefully researched, regularly updated, and reviewed for accuracy and relevance.