Quick reference — AWS CLI commands for EC2, S3, IAM, VPC, Lambda, plus instance families and service equivalents.
EC2S3IAMVPC
CLI Setup & Identity
aws configure # static keys (dev only)
aws configure sso # IAM Identity Center (preferred)
aws sts get-caller-identity # who am I?
aws iam create-role --role-name r --assume-role-policy-document file://trust.json
aws iam attach-role-policy --role-name r --policy-arn arn:aws:iam::acct:policy/P
IAM is global and free. Prefer roles over long-lived keys. Enable MFA; never use root.
EC2
aws ec2 run-instances --image-id ami-xxx --instance-type t4g.micro \
--key-name k --security-group-ids sg-xxx --subnet-id subnet-xxx
aws ec2 describe-instances --filters Name=instance-state-name,Values=running
aws ec2 stop-instances --instance-ids i-xxx
aws ec2 start-instances --instance-ids i-xxx
aws ec2 terminate-instances --instance-ids i-xxx
Instance families
| Family | For |
| T / M | General purpose |
| C | Compute optimized |
| R / X | Memory optimized |
| P / G | GPU (ML, graphics) |
g suffix = ARM Graviton (best price-performance).
S3
aws s3 ls
aws s3 mb s3://bucket # make bucket
aws s3 cp file s3://bucket/key # upload
aws s3 sync ./dir s3://bucket/prefix --delete
aws s3 rm s3://bucket/key
aws s3api put-bucket-versioning --bucket b --versioning-configuration Status=Enabled
aws s3api put-public-access-block --bucket b \
--public-access-block-configuration BlockPublicAcls=true,IgnorePublicAcls=true,\
BlockPublicPolicy=true,RestrictPublicBuckets=true
Storage classes
| Class | Use |
| Standard | Hot data |
| Intelligent-Tiering | Unknown patterns |
| Standard-IA | Infrequent, still fast |
| Glacier / Deep Archive | Archive |
VPC & Networking
aws ec2 create-vpc --cidr-block 10.0.0.0/16
aws ec2 create-subnet --vpc-id vpc-xxx --cidr-block 10.0.1.0/24 --availability-zone us-east-1a
aws ec2 authorize-security-group-ingress --group-id sg-xxx \
--protocol tcp --port 443 --cidr 0.0.0.0/0
| Control | Scope | State |
| Security Group | Instance / ENI | Stateful, allow-only |
| Network ACL | Subnet | Stateless, allow+deny |
Databases & Lambda
aws rds create-db-instance --db-instance-identifier db --engine postgres \
--db-instance-class db.t4g.medium --allocated-storage 50 --multi-az \
--master-username admin --manage-master-user-password
aws dynamodb create-table --table-name t --billing-mode PAY_PER_REQUEST \
--attribute-definitions AttributeName=id,AttributeType=S \
--key-schema AttributeName=id,KeyType=HASH
aws lambda create-function --function-name f --runtime nodejs20.x \
--handler index.handler --role arn:...:role/exec --zip-file fileb://f.zip
aws lambda invoke --function-name f --payload '{}' out.json
Cross-Cloud Equivalents
| AWS | Azure | GCP |
| EC2 | Virtual Machines | Compute Engine |
| S3 | Blob Storage | Cloud Storage |
| Lambda | Azure Functions | Cloud Run functions |
| RDS / Aurora | Azure SQL | Cloud SQL |
| EKS | AKS | GKE |
| IAM | Entra ID + RBAC | Cloud IAM |