The cloud & AWS: getting started
"The cloud" sounds fluffy, but it's very solid: huge buildings full of servers that someone else runs. You rent a slice by the second, through an API, and hand it back when you're done. AWS (Amazon Web Services) is the biggest cloud. Everything you learned about Linux still applies. The servers you'll launch here are Linux machines, just ones you never touch with your hands.
You will learn
- What the cloud is, and what regions and availability zones are
- Accounts: the root user, IAM users, MFA, and why the bill matters
- Installing AWS CLI v2 the official way, on both families
aws configure,~/.aws/credentialsandaws sts get-caller-identity- Output formats and
--queryfor picking out what you need
The practice terminals talk to a simulated AWS inside your browser. It answers like the real thing (same commands, same JSON, same error messages), but nothing is real and nothing costs money. The account and its keys live in ~/aws-sandbox.txt. When you move to a real account, every command here works the same way. So does the bill, so read the money parts carefully.
What "the cloud" really is
Before the cloud, a company that needed a server bought one, waited weeks for delivery, racked it, cabled it and ran it for five years. In the cloud you ask for one and have it in a minute, and you stop paying the moment you delete it. Three ideas make that work:
| Idea | What it means for you |
|---|---|
| On demand | Servers, disks and networks appear when you ask, and disappear when you delete them |
| Pay for what you use | Per second, per GB stored, per request. Cheap when small, and expensive if you forget things |
| Everything is an API | The web console, the aws command and tools like Terraform all make the same API calls |
Regions and availability zones
AWS is split into regions: separate groups of data centres in one part of the world, like us-east-1 (N. Virginia) or eu-west-2 (London). Each region has several availability zones (AZs): us-east-1a, us-east-1b and so on. Each AZ is one or more data centres with its own power and network, a few miles from the others.
- Most things you create live in one region. A server in
us-east-1is invisible when your CLI points ateu-west-1. (That's how people "lose" servers and keep paying for them.) - Spread important things over two or more AZs, so one broken data centre doesn't take you down.
- A few services are global: IAM (users and permissions), Route 53 (DNS), and the bucket names of S3.
Your account: guard it like your bank login
When you sign up, you get a root user: the email address you signed up with. Root can do everything, including closing the account. So:
- Turn on MFA (a code from an app on your phone) for root on day one.
- Don't use root for daily work. Create an IAM user or use IAM Identity Center, and lock root away. The next lesson is all about IAM.
- Set a budget alarm before you build anything. New accounts get free-tier credits for a while, but the rules change, so check AWS's current Free Tier page. The CloudWatch lesson shows how to get an email before a bill surprises you.
The CLI signs in with an access key ID (starts with AKIA) and a secret access key. Anyone who has both can spend your money. Bots scan GitHub for leaked keys within minutes of a push. Never put keys in code, chat, screenshots or git.
Install AWS CLI v2
AWS publishes one installer that works on every Linux, and it's the version the AWS docs assume. It's a zip file with an install script inside, and it needs root because it installs into /usr/local.
curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o awscliv2.zip unzip awscliv2.zip # makes a folder called aws/ sudo ./aws/install # → /usr/local/aws-cli, with a link at /usr/local/bin/aws aws --version
aws-cli/2.31.3 Python/3.13.7 Linux/5.14.0-570.22.1.el9_6.x86_64 exe/x86_64.rocky.9
A minimal install has no unzip: sudo dnf install unzip. Rocky's repositories don't carry the AWS CLI, so the official installer is the way.
Ubuntu will offer sudo snap install aws-cli --classic or an older apt package. Both work, but the official installer gives you the same current version as everyone else. It needs sudo apt install unzip first.
To update later, run the installer again with sudo ./aws/install --update.
Tell the CLI who you are
aws configure
AWS Access Key ID [None]: AKIAIOSFODNN7EXAMPLE AWS Secret Access Key [None]: wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY Default region name [None]: us-east-1 Default output format [None]: json
That writes two small files in your home folder:
[default] aws_access_key_id = AKIAIOSFODNN7EXAMPLE aws_secret_access_key = wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
[default] region = us-east-1 output = json
Now the most useful first command in AWS, the cloud's whoami:
aws sts get-caller-identity
{
"UserId": "AIDA466E5744250593AA",
"Account": "123456789012",
"Arn": "arn:aws:iam::123456789012:user/sandbox-admin"
}
That long arn:aws:… string is an ARN (Amazon Resource Name): the full address of anything in AWS. When something says "access denied", check this first. Often you're simply not who you think you are.
Reading the answers: --output and --query
Every command answers in JSON. Two options make that friendlier:
aws ec2 describe-regions --output table # json (default), table, text, yaml aws ec2 describe-regions --query 'Regions[].RegionName' --output text aws ec2 describe-availability-zones --query 'AvailabilityZones[].ZoneName' aws sts get-caller-identity --query Account --output text # just 123456789012
--query uses a little language called JMESPath: Regions[] means "every item of the Regions list", then .RegionName picks one field from each. With --output text you get plain words, perfect for shell variables: ACCOUNT=$(aws sts get-caller-identity --query Account --output text). You'll do that a lot in this path.
Add --region eu-west-1 to any command, or set AWS_REGION for the whole shell. The region in ~/.aws/config is only the default.
Practice: your first AWS commands ☁️
This fresh server has no AWS CLI yet. Install it, connect it to the sandbox account, and look around.
Quick check
1. You launched a server in us-east-1, but aws ec2 describe-instances shows nothing. What's the most likely reason?
✓ Regions are separate. Add --region us-east-1 or check aws configure get region.
2. Why should you not use the root user for everyday work?
✓ Same idea as not logging in to Linux as root: use a less powerful identity day to day.
3. What does aws sts get-caller-identity tell you?
✓ It's the whoami of AWS, and it works even for users with no permissions at all.