AWS No KYC Account AWS EC2 CLI tool usage guide
Introduction: Welcome to the Command Line Rollercoaster
\nIf you’ve ever said, “I’ll just spin up a quick instance,” and then spent the next thirty minutes clicking through menus like you’re assembling IKEA furniture, congratulations: you’re ready for the AWS EC2 CLI tool. The AWS EC2 Command Line Interface (CLI) lets you manage your Amazon EC2 resources using typed commands—fast, repeatable, scriptable, and surprisingly satisfying.
\nThis guide is for humans who want clarity. We’ll cover what the EC2 CLI is, how to install and configure it, how to use it for everyday tasks, and how to troubleshoot the most common problems. We’ll also discuss how to avoid the classic “works in one region, fails in another” trap—because the CLI won’t read your mind, and AWS definitely won’t apologize for it.
\nAWS No KYC Account We’ll focus on practical usage: listing instances, starting/stopping, retrieving instance details, inspecting security groups, and using helpful parameters so your commands don’t turn into cryptic spellbooks.
\n\nWhat Is the EC2 CLI Tool?
\nWhen people say “EC2 CLI tool,” they usually mean the AWS Command Line Interface (AWS CLI) running commands for Amazon EC2. AWS CLI is the Swiss Army knife. The EC2 “portion” is simply the set of commands under the ec2 service.
For example, you’ll often use commands like:
\n- \n
aws ec2 describe-instancesto list instances and their properties \n aws ec2 start-instancesto power on instances \n aws ec2 stop-instancesto power them down \n aws ec2 create-security-groupand friends to manage networking permissions \n
Because it’s AWS CLI, you also get consistent authentication, consistent output options, and the ability to run commands in scripts and automation pipelines. In other words: less clicking, more controlling.
\n\nPrerequisites: Your Identity, Your Permissions, and Your Keyboard
\nBefore you run anything, you need a few ingredients:
\n- \n
- An AWS account (obviously—unless you’re planning to summon instances from another dimension) \n
- A way to authenticate AWS CLI (access key/secret key, SSO, or other supported methods) \n
- Permissions for EC2 actions you intend to use (like describing instances, starting/stopping, etc.) \n
- Your AWS CLI installed on your machine \n
Tip: Least Privilege Is Great, Until You Need One More Permission
\nSecurity best practice is to grant only the permissions you need. That’s excellent. But when something fails, it might be because you lack one small permission like ec2:DescribeInstances. When you see authorization errors, don’t panic—check your IAM policies or ask whoever manages them.
Step 1: Install AWS CLI
\nAWS CLI is commonly preinstalled on some developer environments, but not always. Here are typical installation approaches:
\n\nOn macOS (Homebrew)
\nIf you use Homebrew, you can install AWS CLI using:
\nAWS No KYC Account brew install awscli
After installing, verify:
\naws --version
On Linux (Common approaches)
\nDepending on the distro, you might use a package manager, a bundled installer, or a virtual environment. Many teams use:
\npip install --upgrade awscli
Or they use the official installer approach. If your environment is locked down, ask your administrator what’s allowed. (Yes, sometimes your keyboard is permitted; the internet might not be.)
\n\nOn Windows
\nWindows users can install via MSI, package managers, or PowerShell-based installers. Once installed, verify:
\naws --version
Step 2: Configure AWS CLI Credentials
\nConfiguration is the heart of CLI success. Without credentials, AWS CLI is like a bicycle without wheels: technically present, emotionally unhelpful.
\n\nQuick Start Configuration
\nRun:
\naws configure
You’ll be prompted for:
\n- \n
- AWS Access Key ID \n
- AWS Secret Access Key \n
- Default region name (for example,
us-east-1) \n - Default output format (like
json) \n
You can choose json for readability during learning. Later, many people prefer table for humans and json for scripts.
Where Configuration Lives
\nAWS CLI typically stores config and credentials here:
\n- \n
~/.aws/credentials(access keys and secrets) \n ~/.aws/config(region, default settings, profiles) \n
If you have multiple accounts or roles, you’ll likely use profiles, which we’ll cover next.
\n\nProfiles: Because One Account Is Never Enough
\nIf you work with multiple AWS accounts (dev, staging, prod) you should use profiles. Create or select a profile:
\naws configure --profile myprofile
Then run commands like:
\naws ec2 describe-instances --profile myprofile
You can also set an environment variable:
\nAWS_PROFILE=myprofile
Then you can omit --profile on each command. Handy, but don’t forget you changed it—future-you may be confused and future-you deserves kindness.
Step 3: Verify CLI Works (Before You Start Spinning Up Resources)
\nLet’s confirm everything is set. A simple command is:
\naws ec2 describe-regions
This lists regions you can access. If this works, you’ve cleared the “authentication + basic access” hurdle.
\nYou can also check your identity:
\nAWS No KYC Account aws sts get-caller-identity
AWS No KYC Account This tells you which AWS user or role you are using.
\n\nStep 4: Use Helpful Output Formats (Your Sanity Matters)
\nBy default, AWS CLI outputs JSON. That’s powerful, but not always friendly while learning. You can choose output formats using --output or in your config.
Common formats:
\n- \n
json(full detail, machine-friendly) \n text(less structure) \n table(great for quick viewing) \n
Example:
\naws ec2 describe-instances --output table
Be aware: some EC2 commands can output large tables. If you have lots of instances, you might prefer to filter results using query options (more on that soon).
\n\nCore EC2 CLI Workflows (What You’ll Do Every Day)
\nNow for the fun part: real tasks you’ll probably repeat. We’ll build from discovery to action, and then to inspection and cleanup.
\n\nListing Instances: “What’s Running, and Why Is It Still Running?”
\nTo list instances, use:
\naws ec2 describe-instances
This returns a lot of data. For readability, you’ll want to filter or extract specific fields.
\n\nList Instance IDs Only
\nUse a JMESPath query with --query. For example, to extract instance IDs:
AWS No KYC Account aws ec2 describe-instances --query "Reservations[].Instances[].InstanceId" --output text
You’ll get output like:
\ni-0123456789abcdef0 i-0fedcba9876543210
List Instances with Names and States
\nMost teams tag instances with a Name. You can query for state and name like this:
aws ec2 describe-instances --query "Reservations[].Instances[].[InstanceId, State.Name, Tags[?Key=='Name']|[0].Value]" --output table
If that query looks spicy, don’t worry. The main idea is: filter the results to the fields you care about.
\nIf you don’t have a Name tag, the “Name” column might appear blank. This is normal. AWS doesn’t require names, only existence. Though in practice, lack of names leads to confusion, which leads to regret, which leads to extra coffee.
Filter by Instance State
\nWant only running instances? You can filter using --filters:
aws ec2 describe-instances --filters "Name=instance-state-name,Values=running" --query "Reservations[].Instances[].InstanceId" --output text
Filter by Tag (Example: Environment=dev)
\nIf your instances are tagged:
\naws ec2 describe-instances --filters "Name=tag:Environment,Values=dev" --query "Reservations[].Instances[].InstanceId" --output text
This is useful for separating dev from prod without relying on your memory (a notoriously unreliable system).
\n\nStarting and Stopping Instances: The “Do I Really Want to Pay for This?” Buttons
\nStarting and stopping are among the most common actions. Always identify the instance IDs first.
\n\nStart Instances
\nTo start one or more instances:
\naws ec2 start-instances --instance-ids i-0123456789abcdef0
If you have multiple:
\naws ec2 start-instances --instance-ids i-0123456789abcdef0 i-0fedcba9876543210
Stop Instances
\nTo stop instances:
\naws ec2 stop-instances --instance-ids i-0123456789abcdef0
Note: stopping an instance keeps the EBS volumes (if using them). Terminating would delete many associated resources depending on configuration.
\n\nReboot Instances (Because Sometimes “Turn It Off and On Again” Works)
\nTo reboot:
\naws ec2 reboot-instances --instance-ids i-0123456789abcdef0
Wait Until State Changes: Avoid Race Conditions
\nSometimes scripts need to wait for state transitions. AWS CLI provides waiters, such as:
\naws ec2 wait instance-running --instance-ids i-0123456789abcdef0
Or:
\naws ec2 wait instance-stopped --instance-ids i-0123456789abcdef0
This helps avoid commands that fail because the instance is still transitioning.
\n\nDescribing Instance Details: The Detective Work
\nWhen something isn’t behaving, instance details are your evidence. Use:
\naws ec2 describe-instances --instance-ids i-0123456789abcdef0
Show Key Fields (State, Type, AMI, Launch Time)
\nExample query:
\naws ec2 describe-instances --instance-ids i-0123456789abcdef0 --query "Reservations[].Instances[].[InstanceId, State.Name, InstanceType, ImageId, LaunchTime]" --output table
That gives a compact overview you can scan quickly.
\n\nGet Private and Public IPs
\nTo extract IP addresses:
\naws ec2 describe-instances --instance-ids i-0123456789abcdef0 --query "Reservations[].Instances[].[PrivateIpAddress, PublicIpAddress]" --output table
If PublicIpAddress is blank, the instance might not have a public IP, or it might be in a configuration where no public address is assigned. This is often expected, especially in private subnets.
View Subnet and VPC Information
\nUseful when troubleshooting routing and connectivity:
\naws ec2 describe-instances --instance-ids i-0123456789abcdef0 --query "Reservations[].Instances[].[SubnetId, VpcId]" --output table
Security Groups: Where Networking Goes to Get Messy
\nSecurity groups control inbound/outbound traffic rules. Let’s inspect them.
\n\nFind Security Groups Attached to an Instance
\nExample:
\naws ec2 describe-instances --instance-ids i-0123456789abcdef0 --query "Reservations[].Instances[].SecurityGroups[].GroupId" --output text
Or include names too:
\nAWS No KYC Account aws ec2 describe-instances --instance-ids i-0123456789abcdef0 --query "Reservations[].Instances[].SecurityGroups[].[GroupId, GroupName]" --output table
Describe a Security Group
\nOnce you have a GroupId, use:
aws ec2 describe-security-groups --group-ids sg-0123456789abcdef0
List Inbound Rules Only
\nExample query:
\naws ec2 describe-security-groups --group-ids sg-0123456789abcdef0 --query "SecurityGroups[].IpPermissions" --output json
This outputs raw permission details. For scripts you can parse the JSON. For humans, you might want a better filter, but the exact query varies based on your needs.
\n\nCommon Beginner Mistake: “I Updated the Security Group, But It Still Doesn’t Work”
\nThat can happen if you updated the wrong security group, attached it to the wrong instance, or forgot about additional layers like NACLs, route tables, or a firewall on the instance itself. Security groups are only one part of the networking puzzle. They are helpful, but they are not magic.
\n\nTags: Your Instance’s Personality (and Your Best Friend)
\nTags are metadata. They help you find, organize, and manage resources. Without them, you’ll eventually start naming instances like “server-1,” “server-2,” and “server-2-final-final.”
\n\nList Tags on Instances
\nExample:
\naws ec2 describe-instances --instance-ids i-0123456789abcdef0 --query "Reservations[].Instances[].Tags[].[Key,Value]" --output table
Filter Instances by a Tag
\nExample environment filter:
\naws ec2 describe-instances --filters "Name=tag:Environment,Values=production" --query "Reservations[].Instances[].InstanceId" --output text
Reminder: Tags Are Case-Sensitive
\nIf you tag Environment=Dev but filter for Environment=dev, you may get zero results. AWS won’t send you a sympathy email. It will simply not find anything. This is one of the most common “my command returns nothing” problems.
Working with AMIs: What Image Are You Actually Running?
\nAMI IDs show up in instance details. If you need to see which AMI an instance is using:
\naws ec2 describe-instances --instance-ids i-0123456789abcdef0 --query "Reservations[].Instances[].ImageId" --output text
Describe the AMI
\nOnce you have the AMI ID (like ami-0abc1234def567890), describe it:
aws ec2 describe-images --image-ids ami-0abc1234def567890 --query "Images[].[ImageId, Name, CreationDate]" --output table
This helps you understand whether the instance is on the latest image or on something… inherited from the past.
\n\nListing Volumes: Storage, Where Dreams Go (Mostly)
\nEBS volumes attach to instances. To list volumes attached to your instances, you can describe instances and look at block device mappings.
\n\nShow Attached Volume IDs
\nExample:
\naws ec2 describe-instances --instance-ids i-0123456789abcdef0 --query "Reservations[].Instances[].BlockDeviceMappings[].Ebs.VolumeId" --output text
Describe Volume Details
\nFor a given volume ID:
\naws ec2 describe-volumes --volume-ids vol-0123456789abcdef0 --query "Volumes[].[VolumeId, VolumeType, Size, State]" --output table
Working with Key Pairs: Access Credentials, But Not the Password Kind
\nKey pairs are used for SSH access (for Linux instances) and sometimes for other uses. Listing key pairs:
\naws ec2 describe-key-pairs
If you’re missing access, you might need to verify which key pair an instance is associated with. Instance-level details can contain the key name:
\naws ec2 describe-instances --instance-ids i-0123456789abcdef0 --query "Reservations[].Instances[].KeyName" --output text
If that key name is blank, you might have launched the instance without a key pair (or the instance was managed differently).
\n\nAWS No KYC Account Using Regions Correctly: The Most Common CLI Problem (Probably)
\nAWS CLI runs in a region. If you forget to specify the correct region, your commands will return empty results or errors. It’s like looking for your keys in the wrong coat pocket, except the wrong pocket also contains zero keys and no coat.
\n\nCheck Your Default Region
\nRun:
\nAWS No KYC Account aws configure get region
Or see it in ~/.aws/config under your profile.
Override Region per Command
\nAdd:
\n--region us-east-1
Example:
\naws ec2 describe-instances --region us-west-2 --filters "Name=instance-state-name,Values=running"
Switch Profiles and Regions Together
\nIf you use profiles, you might set region per profile. Just ensure you’re using the right combination of profile and region. This prevents the dreaded “I swear it exists!” confusion.
\n\nCommon “Why Is This Failing?” Troubleshooting
\nAWS No KYC Account Let’s cover some classic problems and how to respond without throwing your laptop into a river.
\n\nError: “Unable to locate credentials”
\nMeaning: AWS CLI cannot find authentication credentials. Fix by:
\n- \n
- Running
aws configure(or configuring a profile with--profile) \n - Ensuring environment variables like
AWS_ACCESS_KEY_IDaren’t incorrectly set \n - Using the correct profile via
--profileorAWS_PROFILE\n
Error: “You are not authorized to perform this operation”
\nMeaning: your IAM role/user lacks permission. Ask your AWS admin to grant the needed action, such as:
\n- \n
ec2:DescribeInstances\n ec2:StartInstances\n ec2:StopInstances\n ec2:DescribeSecurityGroups\n
If you’re operating with assumed roles, confirm the trust policy and the role permissions.
\n\nError: “InvalidInstanceID.NotFound”
\nMeaning: the instance ID doesn’t exist in the selected region (or the ID is wrong). Fix by:
\n- \n
- Double-checking instance ID spelling \n
- Verifying region \n
- Listing instances in the region to confirm \n
Command Returns Nothing
\nMeaning: your filters are too strict (or wrong tags/values). Check:
\n- \n
- Case sensitivity for tag values \n
- Correct tag key name (like
Environmentvsenvironment) \n - Instance state filters (stopped vs running) \n
- Region correctness \n
Stop/Start Does Nothing (Or Feels Slow)
\nInstances take time to transition states. Use waiters:
\naws ec2 wait instance-stopped --instance-ids i-0123456789abcdef0
Also verify that the instance is in a state where the action is allowed. You can’t always start an instance that’s already running (AWS will complain politely, but still complain).
\n\nPower Moves: Querying with JMESPath for Cleaner Results
\nOne of the best parts of AWS CLI is --query. It lets you extract the specific bits you care about without manually sifting through mountains of JSON.
At a high level, --query uses JMESPath expressions. You don’t need to become a wizard, but learning a few patterns will make your CLI life dramatically easier.
Common Pattern: Extract a Field from Nested Results
\nWhen describing instances, you often see:
\n- \n
Reservations[]\n Instances[]\n - then fields like
InstanceId,State.Name, etc. \n
So you might do something like:
\n--query "Reservations[].Instances[].InstanceId"
Filter by Condition (Example: Only Instances with a Name Tag)
\nYou can use tag queries to locate instances with Name. This is helpful if you rely on naming for humans and automation.
Example idea (conceptually): filter instances whose Tags include key Name and then return those values.
Exact expressions can vary, but the main tool is the same: query, filter, extract.
\n\nAutomating with Shell Scripts (When You’re Ready to Level Up)
\nAfter you can run commands manually, the next step is automation. This is where CLI really earns its keep.
\n\nExample: Stop All Dev Instances
\nFirst, list instance IDs:
\naws ec2 describe-instances --filters "Name=tag:Environment,Values=dev" --query "Reservations[].Instances[?State.Name=='running'].InstanceId" --output text
Then stop them. You might do this in a script using command substitution, depending on your shell:
\nINSTANCE_IDS=$(aws ec2 describe-instances --filters "Name=tag:Environment,Values=dev" --query "Reservations[].Instances[?State.Name=='running'].InstanceId" --output text)
aws ec2 stop-instances --instance-ids $INSTANCE_IDS
Be careful when using command substitution and whitespace. If the query returns multiple IDs, make sure your shell treats them correctly. Test with echo first:
\necho $INSTANCE_IDS
Example: Start Instances and Wait Until Running
\nYou can combine action with waiters:
\naws ec2 start-instances --instance-ids i-0123456789abcdef0
aws ec2 wait instance-running --instance-ids i-0123456789abcdef0
Then proceed to dependent steps like health checks or deployment tasks.
\n\nSafety Tips: Don’t Summon Costs Like a Chaotic Mage
\nAWS No KYC Account Starting instances can cost money. Stopping saves money. Terminating can save money even faster (but can also delete data), so use caution.
\n\nUse Dry Runs When Supported
\nSome AWS API calls support --dry-run. Not all EC2 operations do, but when available, it’s a good way to validate permissions and request correctness without actually changing resources.
Prefer Stopping Over Terminating (Usually)
\nFor many workloads, stopping is safer. Terminating deletes the instance and often the root disk unless you took special precautions. If you’re unsure, stop first and confirm access to needed resources.
\n\nTag Everything You Can
\nTags make it easier to stop the right things later. If you tag instances with Environment, Owner, CostCenter, or Project, your future self will thank your present self. Your future self is not particularly nice to past self unless the past self made good tagging decisions.
Frequently Used EC2 CLI Commands (Quick Reference)
\nAWS No KYC Account Here’s a compact list of commands you’ll likely use repeatedly:
\n- \n
aws ec2 describe-instances\n aws ec2 start-instances\n aws ec2 stop-instances\n aws ec2 reboot-instances\n aws ec2 describe-security-groups\n aws ec2 describe-volumes\n aws ec2 describe-images\n aws ec2 describe-key-pairs\n - AWS No KYC Account
aws sts get-caller-identity\n aws ec2 describe-regions\n
Example Mini-Playbook: From Zero to “I Know What’s Happening”
\nLet’s walk through a realistic scenario: you need to restart a service running on an EC2 instance. You suspect the instance might be in a stopped state or the network rules might have changed.
\n\n1) Identify Running Instances
\naws ec2 describe-instances --filters "Name=instance-state-name,Values=running" --query "Reservations[].Instances[].[InstanceId,State.Name,Tags[?Key=='Name']|[0].Value]" --output table
2) Pick the Correct Instance by Name Tag
\nIf your table shows something like “web-server-prod,” choose that instance ID.
\n\n3) Check the Instance State and Networking
\naws ec2 describe-instances --instance-ids i-0123456789abcdef0 --query "Reservations[].Instances[].[InstanceId, State.Name, PrivateIpAddress, PublicIpAddress, VpcId, SubnetId]" --output table
4) Inspect Security Groups
\nFind security groups attached to the instance:
\naws ec2 describe-instances --instance-ids i-0123456789abcdef0 --query "Reservations[].Instances[].SecurityGroups[].[GroupId,GroupName]" --output table
Then describe one of those security groups:
\naws ec2 describe-security-groups --group-ids sg-0123456789abcdef0
5) Reboot the Instance (or Start/Stop if Needed)
\nIf it’s running and you just need a restart:
\naws ec2 reboot-instances --instance-ids i-0123456789abcdef0
If it’s stopped, start it and wait:
\naws ec2 start-instances --instance-ids i-0123456789abcdef0
aws ec2 wait instance-running --instance-ids i-0123456789abcdef0
Extending Beyond Basics: What to Explore Next
\nOnce you’re comfortable, you can expand into more advanced topics:
\n- \n
- Creating and terminating instances \n
- Managing launch templates and autoscaling groups \n
- Handling Elastic IPs \n
- Working with load balancers \n
- Managing IAM roles for EC2 (instance profiles) \n
- Using scripts for lifecycle management \n
The core lesson stays the same: list resources first, identify the correct IDs, then take action with confidence.
\n\nClosing Thoughts: You’re Now Dangerous (In a Good Way)
\nLearning the AWS EC2 CLI tool is like learning to drive a stick shift. At first you stall a lot. Then you get smoother. Then you realize you’re actually faster than your friends who only know automatics, and you start making hill starts without fear.
\nRemember these golden rules:
\n- \n
- Always verify region and profile \n
- List instances and security groups before taking action \n
- Use
--queryand--outputto keep results readable \n - Use waiters to avoid timing issues \n
- Expect permissions errors and treat them as feedback, not betrayal \n
If you apply those rules, you’ll spend less time clicking and more time shipping. And if you’re anything like the rest of us, that means more time for the important tasks, like celebrating small wins and refusing to pay for idle servers that have been “running” since last Tuesday.
\n\nAppendix: Command Snippet Collection (Copy-Friendly)
\nCheck AWS CLI identity
\naws sts get-caller-identity
List regions
\naws ec2 describe-regions --output table
List running instance IDs
\naws ec2 describe-instances --filters "Name=instance-state-name,Values=running" --query "Reservations[].Instances[].InstanceId" --output text
List instances with IDs and states
\naws ec2 describe-instances --query "Reservations[].Instances[].[InstanceId,State.Name]" --output table
Start instance
\naws ec2 start-instances --instance-ids i-0123456789abcdef0
AWS No KYC Account Stop instance
\naws ec2 stop-instances --instance-ids i-0123456789abcdef0
Wait for running
\naws ec2 wait instance-running --instance-ids i-0123456789abcdef0
Wait for stopped
\naws ec2 wait instance-stopped --instance-ids i-0123456789abcdef0
Get IP addresses
\naws ec2 describe-instances --instance-ids i-0123456789abcdef0 --query "Reservations[].Instances[].[InstanceId,PrivateIpAddress,PublicIpAddress]" --output table
Get security groups for an instance
\naws ec2 describe-instances --instance-ids i-0123456789abcdef0 --query "Reservations[].Instances[].SecurityGroups[].[GroupId,GroupName]" --output table
Describe a security group
\naws ec2 describe-security-groups --group-ids sg-0123456789abcdef0
Describe volumes attached to an instance
\naws ec2 describe-instances --instance-ids i-0123456789abcdef0 --query "Reservations[].Instances[].BlockDeviceMappings[].Ebs.VolumeId" --output text
Describe a volume
\naws ec2 describe-volumes --volume-ids vol-0123456789abcdef0 --query "Volumes[].[VolumeId,VolumeType,Size,State]" --output table
Filter instances by Environment tag
\naws ec2 describe-instances --filters "Name=tag:Environment,Values=dev" --query "Reservations[].Instances[].InstanceId" --output text

