aws cli
AWS CLI v2AWS Command Line Interface 命令快速參考:設定憑證、IAM 身分、EC2/Lambda/S3/DynamoDB/IAM、profiles、SSO,以及分頁/輸出格式化——附常用參數與實作範例。
40 條命令
說明
aws --version印出 awscli 版本(v2.x)。
aws --versionaws help頂層說明——列出服務群組與基本用法。
aws helpaws <service> help顯示單一服務的所有指令。
<service> help;aws <service> <command> help
aws s3 helpaws <service> <command> help顯示單一 API 呼叫的所有旗標與參數。
aws ec2 run-instances helpaws <service> <command> --generate-cli-skeleton印出 JSON skeleton,含該指令的所有必填/選填欄位——可貼回作為輸入。
--generate-cli-skeleton <input|output>;--cli-input-json <file>;--cli-input-yaml <file>
aws ec2 run-instances --generate-cli-skeleton > ec2.json設定
aws configure互動式精靈——設定 access key、secret、output 格式、region,並寫入 `~/.aws/credentials` 與 `~/.aws/config`。
aws configureaws configure --profile <name>同 `aws configure`,但寫入指定名稱的 profile。
--profile dev;--profile prod;--no-prompt
aws configure --profile prodaws configure get <key>從當前設定中讀取單一值。
default.region;default.output;<key>;--profile <name>
aws configure get region --profile prodaws configure set <key> <value>設定單一設定值。
<key> <value>;--profile <name>
aws configure set region us-west-2aws configure list顯示當前設定(profile、region、access-key id、遮罩後的 secret)。
aws configure listSSO/身分
aws sso login --profile <name>啟動 SSO device-flow 登入(或瀏覽器重新導向)。為 profile 設定短期憑證。
--profile dev;--no-browser;--use-device-code
aws sso login --profile devaws sso configure互動式設定 SSO profile(start URL、region、account、role)。
aws sso configureaws sts get-caller-identity印出當前憑證的 IAM 主體(account/arn/user-id)——設定後的基本健全性檢查。
--profile <name>;--no-verify-ssl;--endpoint-url <url>
aws sts get-caller-identityaws sts assume-role --role-arn <arn> --role-session-name <name>切換到 IAM role,取得臨時憑證——適用於跨帳號存取。
--role-arn;--role-session-name;--external-id;--mfa-serial <arn>;--serial-number <arn>;--token-code <mfa>
aws sts assume-role --role-arn arn:aws:iam::123456789012:role/Admin --role-session-name admin輸出
aws <service> <command> --output <format>選擇輸出格式:`json`(預設)、`text`、`table`。搭配 `--query` 可進行類似 jq 的投影。
json;text;table;yaml;yaml-stream
aws ec2 describe-instances --output tableaws <service> <command> --query '<JMES>'用 JMESPath 運算式(類似 jq)投影回應。
--query 'Reservations[].Instances[].InstanceId';--query 'Reservations[].Instances[].[InstanceId,State.Name]'
aws ec2 describe-instances --query 'Reservations[].Instances[].[InstanceId,State.Name]' --output tableaws <service> <command> --no-paginate停用自動分頁——只回傳第一頁(更快;只需計數時有用)。
aws s3 ls --no-paginateaws <service> <command> --cli-binary-format raw-in-base64-out把輸入參數以 base64 讀取——像 `--zip-file fileb://lambda.zip` 這類二進位參數需要。
raw-in-base64-out;base64
aws lambda update-function-code --function-name fn --zip-file fileb://out.zip --cli-binary-format raw-in-base64-outEC2
aws ec2 describe-instances列出所有 EC2 執行個體含完整資訊。
--instance-ids i-xxx;--filters Name=tag:Name,Values=prod;--query;--output
aws ec2 describe-instances --query 'Reservations[].Instances[].{ID:InstanceId,State:State.Name}' --output tableaws ec2 start-instances --instance-ids <id>啟動一個或多個已停止的執行個體。
--instance-ids i-xxx i-yyy
aws ec2 start-instances --instance-ids i-0abc123aws ec2 stop-instances --instance-ids <id>停止一個或多個執行中的執行個體(不會終止)。
aws ec2 stop-instances --instance-ids i-0abc123aws ec2 create-key-pair --key-name <name> --query 'KeyMaterial' --output text > key.pem建立新的 SSH key pair,並把私密金鑰以正確權限存為 `.pem` 檔。
aws ec2 create-key-pair --key-name dev --query 'KeyMaterial' --output text > dev.pem && chmod 400 dev.pemS3
aws s3 ls列出 bucket(無參數時)或某個前綴下的檔案。
s3://<bucket>/<prefix>;--recursive;--human-readable;--summarize
aws s3 ls s3://my-bucket/data/aws s3 cp <local> s3://<bucket>/<key>上傳或複製檔案。`s3://...` 可為來源或目的地。
--recursive;--exclude '*';--include '*.log';--storage-class STANDARD|GLACIER|...;--acl public-read
aws s3 cp ./build/ s3://my-bucket/release/ --recursiveaws s3 sync <src> s3://<bucket>/<dst>S3 雙向目錄同步(上傳新/變更的檔案,除非傳 `--delete` 否則不會刪除目的地多出的檔案)。
--delete;--exclude;--include;--no-progress;--exact-timestamps
aws s3 sync ./dist s3://my-bucket/app/ --deleteaws s3 mb s3://<bucket>建立新的 S3 bucket。Region 預設 us-east-1;用 `--region` 覆寫。
--region eu-west-1
aws s3 mb s3://my-new-bucket --region eu-west-1aws s3 rb s3://<bucket>移除 bucket(搭配 `--force` 可先刪除所有物件)。
--force;--no-progress
aws s3 rb s3://old-bucket --forceaws s3 presign s3://<bucket>/<key> --expires-in <seconds>產生在 `<seconds>` 秒後到期的預簽 URL——適合分享私有檔案。
aws s3 presign s3://my-bucket/file.pdf --expires-in 3600Lambda
aws lambda list-functions列出當前 region 中的所有 Lambda 函式。
--function-version ALL;--max-items 50;--query 'Functions[].FunctionName'
aws lambda list-functions --query 'Functions[].FunctionName' --output textaws lambda update-function-code --function-name <name> --zip-file fileb://fn.zip用本地 zip 更新函式程式碼。某些環境需加上 `--cli-binary-format raw-in-base64-out`。
aws lambda update-function-code --function-name my-fn --zip-file fileb://out.zip --cli-binary-format raw-in-base64-outaws lambda invoke --function-name <name> --payload '{}' out.json同步呼叫函式——回應寫入 `out.json`。
--invocation-type Event|RequestResponse|DryRun;--log-type Tail;--cli-binary-format
aws lambda invoke --function-name my-fn --payload '{"key":"value"}' out.json && cat out.jsonDynamoDB
aws dynamodb scan --table-name <name>掃描 DynamoDB 資料表——讀取每個項目(盡可能改用帶 key 條件的 `query`)。
--table-name;--filter-expression;--projection-expression;--select;--max-items
aws dynamodb scan --table-name users --max-items 5aws dynamodb query --table-name <name> --key-condition-expression 'pk = :v' --expression-attribute-values '{":v":{"S":"u1"}}'依 partition key 與 key 條件運算式查詢項目。
aws dynamodb query --table-name users --key-condition-expression '#u = :u' --expression-attribute-names '{"#u":"userId"}' --expression-attribute-values '{":u":{"S":"u1"}}'IAM
aws iam list-users列出帳號中的所有 IAM 使用者。
--path-prefix /;--max-items
aws iam list-users --query 'Users[].UserName' --output textaws iam create-user --user-name <name>建立新的 IAM 使用者。
aws iam create-user --user-name new-devaws iam attach-user-policy --user-name <name> --policy-arn <arn>把受管政策掛到使用者。
aws iam attach-user-policy --user-name new-dev --policy-arn arn:aws:iam::aws:policy/ReadOnlyAccessProfiles
aws --profile <name> <service> <cmd>在指定 profile 下執行任何指令(必須已設定)。
--profile prod;--profile dev;--profile staging
aws --profile prod s3 lsAWS_PROFILE=<name> aws <service> <cmd>透過環境變數設定 profile——腳本中很實用。
AWS_PROFILE=prod aws lambda list-functions診斷
aws --debug <service> <cmd>把 HTTP 線層級日誌傾印到 stderr——診斷簽章或 payload 錯誤時很有用。
--debug;--no-verify-ssl;--ca-bundle <file>;--cli-read-timeout <seconds>
aws --debug s3 ls 2> aws.logaws --no-sign-request <service> <cmd>發出未簽章的請求——適合公開 bucket/測試端點。
aws --no-sign-request s3 cp public.txt s3://public-bucket/x相關命令速查
azure cli
Azure CLI(az)命令快速參考:驗證、subscription/資源管理、VM/AKS/Storage/App Service/Key Vault、query 格式化、CI 友善工作流——附常用參數與實作範例。
43 條命令
Azure CLI 2.60+
gcloud
gcloud(Google Cloud CLI)、gsutil、bq 命令快速參考:驗證、project/IAM、Compute/GKE/BigQuery/Cloud Storage、設定、Cloud Build/Deploy——附常用參數與實作範例。
48 條命令
gcloud 480+
kubectl
kubectl(Kubernetes 命令列工具)快速參考:context、get/describe、apply、logs/exec、rollout、scaling 及除錯——附常用參數與實作範例。
40 條命令
kubectl 1.28+
docker
日常高頻 Docker CLI 命令快速參考:容器生命週期、映像檔建置、日誌 / exec、網絡、磁碟區、Compose、Registry 與系統清理——附常用參數與實作範例。
46 條命令
Docker Engine 24.0+
商標與使用聲明
本批命令列工具速查手冊為開源社群參考資料。文中涉及的各工具的名稱、標識、商標(如 Git™、Docker™、Kubernetes®、kubectl、PostgreSQL®、MySQL®、Redis™、MongoDB®、Linux™、PowerShell™、Vim™ 等)均歸對應權利人所有,此處僅為識別與參考之目的使用。
本速查手冊的全部內容均為獨立編寫的簡化自包含參考,**與任何官方文件不存在隸屬、被認可或引用關係**。命令列表、參數說明、範例均為作者原創簡化表達;如需權威資訊,請參閱各工具的官方文件。
命令語法與參數可能在不同工具版本中有所差異。所示版本標籤對應穩定發佈版本;其他版本行為可能有所不同。本速查手冊**不代表**商標權利人的任何偏好或推薦。
如商標或版權方認為本站部分內容存在權益侵害,請發送電郵至[email protected],我們在收到有效權屬證明後,會在合理期限內修改或移除相關內容。
本網站不對因使用本站資訊而產生的任何直接或間接損失承擔法律責任。
關於 AWS CLI
AWS Command Line Interface(awscli)是 Amazon 官方的終端機工具,用於控制 AWS 服務。目前版本線為 AWS CLI v2(2020 年發佈;awscli 1.x 處於維護模式)。v2 以單一安裝檔(msi/pkg/已簽署 zip)發佈,支援 SSO、`aws sso login` 流程、自動分頁與二進位參數(可處理像 Lambda zip 上傳這種 base64 編碼的 blob)。設定分為 `~/.aws/config`(region、output 格式)與 `~/.aws/credentials`(access key),但使用 IAM Identity Center/SSO 時,通常改用 `aws sso configure` 而非長期 key。每個 AWS 服務都可透過 `aws <service> <command>` 存取——`aws ec2 describe-instances`、`aws s3 sync`、`aws lambda invoke`、`aws dynamodb scan`。CLI 以 Apache-2.0 授權。較新的替代方案包括 `aws-shell`(互動式補完)與 AWS CDK(`cdk`)用於基礎架構即程式碼。AWS CLI v2 不會上傳你的源碼到任何地方,只會執行你明確呼叫的 API。
速查頁版本 1.0.0