The AWS Command Line Interface (AWS CLI) lets you manage Amazon Web Services from a terminal: copy files to S3, start and stop EC2 instances, or script any other AWS API call. In this tutorial you will install AWS CLI version 2 on an Ubuntu 24.04 server, create an IAM access key with limited permissions, configure it as a profile, and verify everything with real commands against S3.
Prerequisites
To follow this guide you need:
- A server running Ubuntu 24.04 LTS (x86_64 or arm64), for example a CubePath VPS.
- A non-root user with
sudoprivileges. - An AWS account where you can create IAM users, or an administrator who can create an access key for you.
Step 1 - Installing the required tools
AWS CLI v2 is shipped by Amazon as a self-contained zip archive that bundles its own Python runtime, so it does not interfere with the system Python. Ubuntu 24.04 does not package it, which is why you install it from the official archive. You only need curl and unzip:
sudo apt update
sudo apt install -y curl unzip
Step 2 - Downloading and installing AWS CLI v2
The installer URL depends on the CPU architecture. This command picks the right one using uname -m, which returns x86_64 or aarch64:
cd /tmp
curl -fsSL "https://awscli.amazonaws.com/awscli-exe-linux-$(uname -m).zip" -o awscliv2.zip
Extract the archive and run the installer. By default it installs the program under /usr/local/aws-cli and creates symlinks in /usr/local/bin:
unzip -q awscliv2.zip
sudo ./aws/install
Check that the aws command is on your PATH:
aws --version
aws-cli/2.x.x Python/3.x.x Linux/6.8.0-xx-generic exe/x86_64.ubuntu.24
Remove the installer files once the command works:
rm -rf /tmp/aws /tmp/awscliv2.zip
To enable tab completion for aws subcommands in Bash, add the completer to your shell profile:
echo "complete -C '/usr/local/bin/aws_completer' aws" >> ~/.bashrc
source ~/.bashrc
Step 3 - Creating an IAM access key
The CLI authenticates with an access key ID and a secret access key. Never create access keys for the AWS root account. Instead, create a dedicated IAM user whose permissions match what the server actually needs.
In the AWS Management Console:
- Open IAM and go to Users, then choose Create user.
- Give the user a descriptive name such as
cubepath-cliand do not enable console access. - On the permissions page, attach only the policies this server needs. For this tutorial,
AmazonS3ReadOnlyAccessis enough to follow the examples; you can add more permissions later. - Open the new user, go to the Security credentials tab and choose Create access key. Select Command Line Interface (CLI) as the use case.
- Copy the Access key ID and Secret access key. The secret is only shown once.
WarningAnyone with these two values can act as the IAM user. Do not commit them to Git, paste them into tickets or store them in world-readable files.
Step 4 - Configuring the default profile
Run aws configure and paste the values from the previous step when prompted. Use the region where your resources live (for example eu-west-1 or us-east-1) and json as the output format:
aws configure
AWS Access Key ID [None]: AKIAXXXXXXXXXXXXXXXX
AWS Secret Access Key [None]: ****************************************
Default region name [None]: eu-west-1
Default output format [None]: json
The command writes two files in your home directory:
~/.aws/credentialsholds the access key and secret.~/.aws/configholds non-secret settings such as region and output format.
Make sure only your user can read them:
chmod 700 ~/.aws
chmod 600 ~/.aws/credentials ~/.aws/config
Now confirm that AWS accepts the key. aws sts get-caller-identity works for any valid credentials, regardless of the permissions attached:
aws sts get-caller-identity
{
"UserId": "AIDAXXXXXXXXXXXXXXXXX",
"Account": "123456789012",
"Arn": "arn:aws:iam::123456789012:user/cubepath-cli"
}
If you see your account ID and the IAM user ARN, the CLI is configured correctly.
Step 5 - Using named profiles
Named profiles let you keep credentials for several accounts or users on the same machine, for example a read-only profile for daily use and a separate one for production changes. Create a profile called production:
aws configure --profile production
The profile is stored as its own section in both files. ~/.aws/credentials now looks like this:
[default]
aws_access_key_id = AKIAXXXXXXXXXXXXXXXX
aws_secret_access_key = your_secret_key
[production]
aws_access_key_id = AKIAYYYYYYYYYYYYYYYY
aws_secret_access_key = your_other_secret_key
Select a profile per command with --profile, or for the whole shell session with the AWS_PROFILE environment variable:
aws sts get-caller-identity --profile production
export AWS_PROFILE=production
List the profiles the CLI knows about:
aws configure list-profiles
default
production
If your organization uses IAM roles, you can define a profile that assumes a role using the credentials of another profile. Edit ~/.aws/config:
nano ~/.aws/config
[profile admin-role]
role_arn = arn:aws:iam::123456789012:role/your_role_name
source_profile = default
region = eu-west-1
Commands run with --profile admin-role call STS to obtain temporary credentials for that role, which is safer than giving the IAM user broad permissions directly.
For scripts and CI jobs you can also pass credentials through environment variables, which take precedence over the files:
export AWS_ACCESS_KEY_ID=AKIAXXXXXXXXXXXXXXXX
export AWS_SECRET_ACCESS_KEY=your_secret_key
export AWS_DEFAULT_REGION=eu-west-1
Step 6 - Controlling output with formats and queries
Every command accepts --output (json, yaml, text or table) and --query, which filters the response with a JMESPath expression on the client side. table is easy to read, while text is the best choice when you feed the result into another shell command.
For example, list your S3 bucket names as a table:
aws s3api list-buckets --query 'Buckets[].Name' --output table
-----------------------
| ListBuckets |
+---------------------+
| my-app-assets |
| my-server-backups |
+---------------------+
The same query with --output text prints the names separated by tabs, ready to use in a loop.
You can override the region for a single command without touching the configuration:
aws ec2 describe-regions --region us-east-1 --query 'Regions[].RegionName' --output text
Step 7 - Running your first S3 commands
With the AmazonS3ReadOnlyAccess policy from Step 3 you can already list buckets and download objects. Replace your_bucket_name with a bucket in your account:
aws s3 ls
aws s3 ls s3://your_bucket_name/ --human-readable --summarize
2026-09-01 10:12:44 4.2 KiB index.html
2026-09-01 10:12:45 18.0 MiB video.mp4
Total Objects: 2
Total Size: 18.0 MiB
Download a file:
aws s3 cp s3://your_bucket_name/index.html ./index.html
Uploading (aws s3 cp local s3://...) and synchronizing directories (aws s3 sync) require write permissions such as s3:PutObject on that bucket. If you try them with the read-only policy you will get an AccessDenied error, which is the expected result of least privilege.
Step 8 - Updating AWS CLI
The CLI does not update itself. To upgrade, download the latest archive again and run the installer with --update:
cd /tmp
curl -fsSL "https://awscli.amazonaws.com/awscli-exe-linux-$(uname -m).zip" -o awscliv2.zip
unzip -qo awscliv2.zip
sudo ./aws/install --update
aws --version
rm -rf /tmp/aws /tmp/awscliv2.zip
Troubleshooting
Unable to locate credentials: the CLI found no key. Run aws configure list to see which profile and source it is using, and check that AWS_PROFILE does not point to a profile that does not exist.
An error occurred (InvalidClientTokenId) or SignatureDoesNotMatch: the access key ID or secret is wrong or the key was deactivated. Create a new access key in IAM and run aws configure again.
An error occurred (AccessDenied): the credentials are valid but the IAM user lacks permission for that action. The error message names the missing action (for example s3:PutObject); add it to the user's policy rather than attaching AdministratorAccess.
aws: command not found after installing: /usr/local/bin is not in your PATH, or the installer was run with a custom --bin-dir. Check with ls -l /usr/local/bin/aws.
Conclusion
You installed AWS CLI v2 on Ubuntu 24.04, created a scoped IAM access key, configured default and named profiles, and used queries and output formats to get exactly the data you need. From here you can automate server backups with aws s3 sync, rotate your access keys periodically from the IAM console, or move to IAM Identity Center with aws configure sso if your organization uses single sign-on.
