3.1 KiB
aws (AWS CLI v2)
What it is
The official AWS command line (v2): S3, IAM, Lambda, IoT Core, CloudFormation — every AWS API from the shell, with named profiles for multi-account work.
Install
Official Linux x86_64 installer (always current stable; use the -aarch64 URL
on arm64):
curl -fsSL "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o /tmp/awscliv2.zip
unzip -q /tmp/awscliv2.zip -d /tmp
sudo /tmp/aws/install # add --update to upgrade in place
Do not use the distro awscli package — it is usually the legacy v1.
Authenticate
aws configure --profile prod
# AWS Access Key ID: <from Vaultwarden>
# AWS Secret Access Key: <from Vaultwarden>
# Default region name: eu-west-1
# Default output format: json
Credentials live in ~/.aws/credentials (chmod 600). Keep the root copies of
all access keys in Vaultwarden (https://vault.portugalfuturista.org); rotate
rather than leak.
Configure for this environment
~/.aws/config — real AWS plus the local emulators:
[default]
region = eu-west-1
output = json
[profile prod]
region = eu-west-1
[profile localstack]
region = us-east-1
output = json
~/.aws/credentials:
[localstack]
aws_access_key_id = test
aws_secret_access_key = test
Self-hosted equivalent
LocalStack (AWS emulator, lattepanda http://192.168.0.40:4566) and
MinIO (S3-compatible, http://192.168.0.40:9000, console :9001).
# LocalStack: everything behind one endpoint
aws --profile localstack --endpoint-url http://192.168.0.40:4566 s3 ls
aws --profile localstack --endpoint-url http://192.168.0.40:4566 lambda list-functions
# MinIO: S3 only
aws --profile localstack --endpoint-url http://192.168.0.40:9000 s3 mb s3://firmware
aws --profile localstack --endpoint-url http://192.168.0.40:9000 s3 cp build.bin s3://firmware/
For MinIO use its own access/secret keys (console at :9001), stored in
Vaultwarden — not test/test.
Alternative: pipx install awscli-local gives awslocal, which wraps aws
with the LocalStack endpoint pre-set (awslocal s3 ls).
Aurélio integration
The cli-aws skill wraps aws (and awslocal) for infra and IoT Core
tasks. Connector registry ids: aws (real), aws-localstack (emulator),
minio (S3 storage).
Verify
aws --version
# aws-cli/2.x.y Python/3.x Linux/x86_64 ...
aws --profile localstack --endpoint-url http://192.168.0.40:4566 sts get-caller-identity
# { "Account": "000000000000", "Arn": "arn:aws:iam::000000000000:root", ... }
Troubleshooting
aws: command not foundafter install — installer puts it in/usr/local/bin; check yourPATH.- Signature errors against MinIO — wrong keys or clock skew; verify keys in the MinIO console and that the laptop clock is NTP-synced.
Connection refusedto LocalStack — the emulator stack on lattepanda (192.168.0.40) isn't up; check its Docker stack before debuggingaws.- Real AWS used by accident — always pass
--profile localstack --endpoint-url ...in dev scripts; exportAWS_PROFILE=localstackin your dev shell as a seatbelt.