contentintech

AWS Core Services Cheatsheet

Quick reference — AWS CLI commands for EC2, S3, IAM, VPC, Lambda, plus instance families and service equivalents.

EC2S3IAMVPC
NotesCheatsheet

CLI Setup & Identity

aws configure                 # static keys (dev only)
aws configure sso             # IAM Identity Center (preferred)
aws sts get-caller-identity   # who am I?
aws iam create-role --role-name r --assume-role-policy-document file://trust.json
aws iam attach-role-policy --role-name r --policy-arn arn:aws:iam::acct:policy/P

IAM is global and free. Prefer roles over long-lived keys. Enable MFA; never use root.

EC2

aws ec2 run-instances --image-id ami-xxx --instance-type t4g.micro \
  --key-name k --security-group-ids sg-xxx --subnet-id subnet-xxx
aws ec2 describe-instances --filters Name=instance-state-name,Values=running
aws ec2 stop-instances  --instance-ids i-xxx
aws ec2 start-instances --instance-ids i-xxx
aws ec2 terminate-instances --instance-ids i-xxx

Instance families

FamilyFor
T / MGeneral purpose
CCompute optimized
R / XMemory optimized
P / GGPU (ML, graphics)

g suffix = ARM Graviton (best price-performance).

S3

aws s3 ls
aws s3 mb s3://bucket                     # make bucket
aws s3 cp file s3://bucket/key            # upload
aws s3 sync ./dir s3://bucket/prefix --delete
aws s3 rm s3://bucket/key
aws s3api put-bucket-versioning --bucket b --versioning-configuration Status=Enabled
aws s3api put-public-access-block --bucket b \
  --public-access-block-configuration BlockPublicAcls=true,IgnorePublicAcls=true,\
BlockPublicPolicy=true,RestrictPublicBuckets=true

Storage classes

ClassUse
StandardHot data
Intelligent-TieringUnknown patterns
Standard-IAInfrequent, still fast
Glacier / Deep ArchiveArchive

VPC & Networking

aws ec2 create-vpc --cidr-block 10.0.0.0/16
aws ec2 create-subnet --vpc-id vpc-xxx --cidr-block 10.0.1.0/24 --availability-zone us-east-1a
aws ec2 authorize-security-group-ingress --group-id sg-xxx \
  --protocol tcp --port 443 --cidr 0.0.0.0/0
ControlScopeState
Security GroupInstance / ENIStateful, allow-only
Network ACLSubnetStateless, allow+deny

Databases & Lambda

aws rds create-db-instance --db-instance-identifier db --engine postgres \
  --db-instance-class db.t4g.medium --allocated-storage 50 --multi-az \
  --master-username admin --manage-master-user-password
aws dynamodb create-table --table-name t --billing-mode PAY_PER_REQUEST \
  --attribute-definitions AttributeName=id,AttributeType=S \
  --key-schema AttributeName=id,KeyType=HASH

aws lambda create-function --function-name f --runtime nodejs20.x \
  --handler index.handler --role arn:...:role/exec --zip-file fileb://f.zip
aws lambda invoke --function-name f --payload '{}' out.json

Cross-Cloud Equivalents

AWSAzureGCP
EC2Virtual MachinesCompute Engine
S3Blob StorageCloud Storage
LambdaAzure FunctionsCloud Run functions
RDS / AuroraAzure SQLCloud SQL
EKSAKSGKE
IAMEntra ID + RBACCloud IAM

Section navigation