The AWS Command Line Interface (AWS CLI) lets you manage Amazon Web Services from a terminal: copy files to S3, start and stop EC2 instances, or script any other AWS API call. In this tutorial you will install AWS CLI version 2 on an Ubuntu 24.04 server, create an IAM access key with limited permissions, configure it as a profile, and verify everything with real commands against S3.

Prerequisites

To follow this guide you need:

  • A server running Ubuntu 24.04 LTS (x86_64 or arm64), for example a CubePath VPS.
  • A non-root user with sudo privileges.
  • An AWS account where you can create IAM users, or an administrator who can create an access key for you.

Step 1 - Installing the required tools

AWS CLI v2 is shipped by Amazon as a self-contained zip archive that bundles its own Python runtime, so it does not interfere with the system Python. Ubuntu 24.04 does not package it, which is why you install it from the official archive. You only need curl and unzip:

sudo apt update
sudo apt install -y curl unzip

Step 2 - Downloading and installing AWS CLI v2

The installer URL depends on the CPU architecture. This command picks the right one using uname -m, which returns x86_64 or aarch64:

cd /tmp
curl -fsSL "https://awscli.amazonaws.com/awscli-exe-linux-$(uname -m).zip" -o awscliv2.zip

Extract the archive and run the installer. By default it installs the program under /usr/local/aws-cli and creates symlinks in /usr/local/bin:

unzip -q awscliv2.zip
sudo ./aws/install

Check that the aws command is on your PATH:

aws --version
aws-cli/2.x.x Python/3.x.x Linux/6.8.0-xx-generic exe/x86_64.ubuntu.24

Remove the installer files once the command works:

rm -rf /tmp/aws /tmp/awscliv2.zip

To enable tab completion for aws subcommands in Bash, add the completer to your shell profile:

echo "complete -C '/usr/local/bin/aws_completer' aws" >> ~/.bashrc
source ~/.bashrc

Step 3 - Creating an IAM access key

The CLI authenticates with an access key ID and a secret access key. Never create access keys for the AWS root account. Instead, create a dedicated IAM user whose permissions match what the server actually needs.

In the AWS Management Console:

  1. Open IAM and go to Users, then choose Create user.
  2. Give the user a descriptive name such as cubepath-cli and do not enable console access.
  3. On the permissions page, attach only the policies this server needs. For this tutorial, AmazonS3ReadOnlyAccess is enough to follow the examples; you can add more permissions later.
  4. Open the new user, go to the Security credentials tab and choose Create access key. Select Command Line Interface (CLI) as the use case.
  5. Copy the Access key ID and Secret access key. The secret is only shown once.

Step 4 - Configuring the default profile

Run aws configure and paste the values from the previous step when prompted. Use the region where your resources live (for example eu-west-1 or us-east-1) and json as the output format:

aws configure
AWS Access Key ID [None]: AKIAXXXXXXXXXXXXXXXX
AWS Secret Access Key [None]: ****************************************
Default region name [None]: eu-west-1
Default output format [None]: json

The command writes two files in your home directory:

  • ~/.aws/credentials holds the access key and secret.
  • ~/.aws/config holds non-secret settings such as region and output format.

Make sure only your user can read them:

chmod 700 ~/.aws
chmod 600 ~/.aws/credentials ~/.aws/config

Now confirm that AWS accepts the key. aws sts get-caller-identity works for any valid credentials, regardless of the permissions attached:

aws sts get-caller-identity
{
    "UserId": "AIDAXXXXXXXXXXXXXXXXX",
    "Account": "123456789012",
    "Arn": "arn:aws:iam::123456789012:user/cubepath-cli"
}

If you see your account ID and the IAM user ARN, the CLI is configured correctly.

Step 5 - Using named profiles

Named profiles let you keep credentials for several accounts or users on the same machine, for example a read-only profile for daily use and a separate one for production changes. Create a profile called production:

aws configure --profile production

The profile is stored as its own section in both files. ~/.aws/credentials now looks like this:

[default]
aws_access_key_id = AKIAXXXXXXXXXXXXXXXX
aws_secret_access_key = your_secret_key

[production]
aws_access_key_id = AKIAYYYYYYYYYYYYYYYY
aws_secret_access_key = your_other_secret_key

Select a profile per command with --profile, or for the whole shell session with the AWS_PROFILE environment variable:

aws sts get-caller-identity --profile production
export AWS_PROFILE=production

List the profiles the CLI knows about:

aws configure list-profiles
default
production

If your organization uses IAM roles, you can define a profile that assumes a role using the credentials of another profile. Edit ~/.aws/config:

nano ~/.aws/config
[profile admin-role]
role_arn = arn:aws:iam::123456789012:role/your_role_name
source_profile = default
region = eu-west-1

Commands run with --profile admin-role call STS to obtain temporary credentials for that role, which is safer than giving the IAM user broad permissions directly.

For scripts and CI jobs you can also pass credentials through environment variables, which take precedence over the files:

export AWS_ACCESS_KEY_ID=AKIAXXXXXXXXXXXXXXXX
export AWS_SECRET_ACCESS_KEY=your_secret_key
export AWS_DEFAULT_REGION=eu-west-1

Step 6 - Controlling output with formats and queries

Every command accepts --output (json, yaml, text or table) and --query, which filters the response with a JMESPath expression on the client side. table is easy to read, while text is the best choice when you feed the result into another shell command.

For example, list your S3 bucket names as a table:

aws s3api list-buckets --query 'Buckets[].Name' --output table
-----------------------
|     ListBuckets     |
+---------------------+
|  my-app-assets      |
|  my-server-backups  |
+---------------------+

The same query with --output text prints the names separated by tabs, ready to use in a loop.

You can override the region for a single command without touching the configuration:

aws ec2 describe-regions --region us-east-1 --query 'Regions[].RegionName' --output text

Step 7 - Running your first S3 commands

With the AmazonS3ReadOnlyAccess policy from Step 3 you can already list buckets and download objects. Replace your_bucket_name with a bucket in your account:

aws s3 ls
aws s3 ls s3://your_bucket_name/ --human-readable --summarize
2026-09-01 10:12:44    4.2 KiB index.html
2026-09-01 10:12:45   18.0 MiB video.mp4

Total Objects: 2
   Total Size: 18.0 MiB

Download a file:

aws s3 cp s3://your_bucket_name/index.html ./index.html

Uploading (aws s3 cp local s3://...) and synchronizing directories (aws s3 sync) require write permissions such as s3:PutObject on that bucket. If you try them with the read-only policy you will get an AccessDenied error, which is the expected result of least privilege.

Step 8 - Updating AWS CLI

The CLI does not update itself. To upgrade, download the latest archive again and run the installer with --update:

cd /tmp
curl -fsSL "https://awscli.amazonaws.com/awscli-exe-linux-$(uname -m).zip" -o awscliv2.zip
unzip -qo awscliv2.zip
sudo ./aws/install --update
aws --version
rm -rf /tmp/aws /tmp/awscliv2.zip

Troubleshooting

Unable to locate credentials: the CLI found no key. Run aws configure list to see which profile and source it is using, and check that AWS_PROFILE does not point to a profile that does not exist.

An error occurred (InvalidClientTokenId) or SignatureDoesNotMatch: the access key ID or secret is wrong or the key was deactivated. Create a new access key in IAM and run aws configure again.

An error occurred (AccessDenied): the credentials are valid but the IAM user lacks permission for that action. The error message names the missing action (for example s3:PutObject); add it to the user's policy rather than attaching AdministratorAccess.

aws: command not found after installing: /usr/local/bin is not in your PATH, or the installer was run with a custom --bin-dir. Check with ls -l /usr/local/bin/aws.

Conclusion

You installed AWS CLI v2 on Ubuntu 24.04, created a scoped IAM access key, configured default and named profiles, and used queries and output formats to get exactly the data you need. From here you can automate server backups with aws s3 sync, rotate your access keys periodically from the IAM console, or move to IAM Identity Center with aws configure sso if your organization uses single sign-on.