AWS basics · Lesson 1 · 30 min

The cloud & AWS: getting started

"The cloud" sounds fluffy, but it's very solid: huge buildings full of servers that someone else runs. You rent a slice by the second, through an API, and hand it back when you're done. AWS (Amazon Web Services) is the biggest cloud. Everything you learned about Linux still applies. The servers you'll launch here are Linux machines, just ones you never touch with your hands.

You will learn

  • What the cloud is, and what regions and availability zones are
  • Accounts: the root user, IAM users, MFA, and why the bill matters
  • Installing AWS CLI v2 the official way, on both families
  • aws configure, ~/.aws/credentials and aws sts get-caller-identity
  • Output formats and --query for picking out what you need
This path uses a pretend AWS account

The practice terminals talk to a simulated AWS inside your browser. It answers like the real thing (same commands, same JSON, same error messages), but nothing is real and nothing costs money. The account and its keys live in ~/aws-sandbox.txt. When you move to a real account, every command here works the same way. So does the bill, so read the money parts carefully.

What "the cloud" really is

Before the cloud, a company that needed a server bought one, waited weeks for delivery, racked it, cabled it and ran it for five years. In the cloud you ask for one and have it in a minute, and you stop paying the moment you delete it. Three ideas make that work:

IdeaWhat it means for you
On demandServers, disks and networks appear when you ask, and disappear when you delete them
Pay for what you usePer second, per GB stored, per request. Cheap when small, and expensive if you forget things
Everything is an APIThe web console, the aws command and tools like Terraform all make the same API calls

Regions and availability zones

AWS is split into regions: separate groups of data centres in one part of the world, like us-east-1 (N. Virginia) or eu-west-2 (London). Each region has several availability zones (AZs): us-east-1a, us-east-1b and so on. Each AZ is one or more data centres with its own power and network, a few miles from the others.

Your account: guard it like your bank login

When you sign up, you get a root user: the email address you signed up with. Root can do everything, including closing the account. So:

Access keys are passwords

The CLI signs in with an access key ID (starts with AKIA) and a secret access key. Anyone who has both can spend your money. Bots scan GitHub for leaked keys within minutes of a push. Never put keys in code, chat, screenshots or git.

Install AWS CLI v2

AWS publishes one installer that works on every Linux, and it's the version the AWS docs assume. It's a zip file with an install script inside, and it needs root because it installs into /usr/local.

curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o awscliv2.zip
unzip awscliv2.zip             # makes a folder called aws/
sudo ./aws/install             # → /usr/local/aws-cli, with a link at /usr/local/bin/aws
aws --version
aws-cli/2.31.3 Python/3.13.7 Linux/5.14.0-570.22.1.el9_6.x86_64 exe/x86_64.rocky.9
Rocky / RHEL

A minimal install has no unzip: sudo dnf install unzip. Rocky's repositories don't carry the AWS CLI, so the official installer is the way.

Ubuntu / Debian

Ubuntu will offer sudo snap install aws-cli --classic or an older apt package. Both work, but the official installer gives you the same current version as everyone else. It needs sudo apt install unzip first.

To update later, run the installer again with sudo ./aws/install --update.

Tell the CLI who you are

aws configure
AWS Access Key ID [None]: AKIAIOSFODNN7EXAMPLE
AWS Secret Access Key [None]: wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
Default region name [None]: us-east-1
Default output format [None]: json

That writes two small files in your home folder:

~/.aws/credentials (mode 600: only you can read it)
[default]
aws_access_key_id = AKIAIOSFODNN7EXAMPLE
aws_secret_access_key = wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
~/.aws/config
[default]
region = us-east-1
output = json

Now the most useful first command in AWS, the cloud's whoami:

aws sts get-caller-identity
{
    "UserId": "AIDA466E5744250593AA",
    "Account": "123456789012",
    "Arn": "arn:aws:iam::123456789012:user/sandbox-admin"
}

That long arn:aws:… string is an ARN (Amazon Resource Name): the full address of anything in AWS. When something says "access denied", check this first. Often you're simply not who you think you are.

Reading the answers: --output and --query

Every command answers in JSON. Two options make that friendlier:

aws ec2 describe-regions --output table                            # json (default), table, text, yaml
aws ec2 describe-regions --query 'Regions[].RegionName' --output text
aws ec2 describe-availability-zones --query 'AvailabilityZones[].ZoneName'
aws sts get-caller-identity --query Account --output text          # just 123456789012

--query uses a little language called JMESPath: Regions[] means "every item of the Regions list", then .RegionName picks one field from each. With --output text you get plain words, perfect for shell variables: ACCOUNT=$(aws sts get-caller-identity --query Account --output text). You'll do that a lot in this path.

Change region for one command

Add --region eu-west-1 to any command, or set AWS_REGION for the whole shell. The region in ~/.aws/config is only the default.

Practice: your first AWS commands ☁️

This fresh server has no AWS CLI yet. Install it, connect it to the sandbox account, and look around.

Quick check

1. You launched a server in us-east-1, but aws ec2 describe-instances shows nothing. What's the most likely reason?

2. Why should you not use the root user for everyday work?

3. What does aws sts get-caller-identity tell you?

Finished the missions and the quiz? Mark it done to track your progress.