๐ค The interview question
"How do you use the AWS CLI without an access key, and how do you know a policy works before you attach it?"
The strong answer is two things you have actually run: sign the CLI in with aws login, and prove the policy in the IAM policy simulator first. 20 minutes. ๐
๐ Flow: Sign in without a key โ Write the policy โ Prove it in the simulator โ Store it, look, delete
๐งฐ Before you start
- ๐ป AWS CLI v2, version 2.32.0 or later (
aws loginneeds it). Check withaws --version. - ๐ค Signed in to the console as your everyday admin IAM user (not root). It needs the
SignInLocalDevelopmentAccessmanaged policy or broader, e.g.AdministratorAccess. - ๐ Permissions used:
iam:SimulateCustomPolicy,iam:CreatePolicy,iam:GetPolicyVersion,iam:DeletePolicy. - ๐ Region:
ap-south-1, or your usual one. - ๐ต Cost: $0. IAM and STS are free, and the simulator sends no real request to any service. No Free plan credits used.
๐ Step 1: Sign the CLI in without a key
Why: an access key works until someone deletes it; one pushed to GitHub is a stolen account. aws login reuses your console sign-in and gives the CLI temporary credentials (refreshed every 15 minutes, 12 hours max).
aws --version
aws login
At AWS Region [us-east-1]: type ap-south-1. In the browser, pick your user, then return.
โ
Expected: aws-cli/2.32.0 or newer, then Updated profile default to use arn:aws:....
Now ask "who am I?" (it needs no permissions, so run it first whenever something is denied):
aws sts get-caller-identity
aws configure list
โ
Expected: an Arn ending in your user name, and login in the TYPE column.
โ ๏ธ If aws login is rejected as an unknown command โ your CLI is older than 2.32.0. Update: curl -fsSL https://awscli.amazonaws.com/v2/install.sh | bash. If you see an old user or ExpiredToken โ an access key in ~/.aws/credentials wins. Delete it and log in again.
๐ Step 2: Write a read-only policy
Why: interviewers listen for "least privilege": list one bucket, read its objects, nothing else. The bucket needn't exist yet.
BUCKET=hoc-site-ar-4821
mkdir -p ~/hoc-unit2 && cd ~/hoc-unit2
cat > hoc-read-policy.json << EOF
{
"Version": "2012-10-17",
"Statement": [
{"Sid": "ListTheBucket", "Effect": "Allow", "Action": "s3:ListBucket", "Resource": "arn:aws:s3:::${BUCKET}"},
{"Sid": "ReadItsObjects", "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::${BUCKET}/*"}
]
}
EOF
๐ Note the two ARNs: ListBucket acts on the bucket, GetObject on the objects (/*).
๐งช Step 3: Prove it in the simulator
Why: the simulator answers "would this be allowed?" without touching anything or saving the policy. A helper makes each test one line:
sim() { aws iam simulate-custom-policy --policy-input-list "$(cat "$1")" \
--action-names "$2" --resource-arns "$3" \
--query 'EvaluationResults[0].EvalDecision' --output text; }
sim hoc-read-policy.json s3:ListBucket arn:aws:s3:::$BUCKET
sim hoc-read-policy.json s3:GetObject arn:aws:s3:::$BUCKET/index.html
sim hoc-read-policy.json s3:PutObject arn:aws:s3:::$BUCKET/index.html
โ
Expected: allowed, allowed, implicitDeny (the only other answer is explicitDeny).
๐ Why implicitDeny? The full chapter explains how AWS decides, with an eight-request test list for this policy.
๐งจ Break it on purpose
Put ListBucket on the object ARN, a classic beginner bug:
sed "s#\"arn:aws:s3:::${BUCKET}\"}#\"arn:aws:s3:::${BUCKET}/*\"}#" hoc-read-policy.json > broken.json
sim broken.json s3:ListBucket arn:aws:s3:::$BUCKET
โ
Expected: implicitDeny. Wrong resource ARN, so listing fails, and you caught it before a real user did.
๐ฆ Step 4: Store it, look at it, delete it
Why: the clean-up habit. Created, never attached, deleted.
POLICY_ARN=$(aws iam create-policy --policy-name hoc-read-site-bucket \
--policy-document "$(cat hoc-read-policy.json)" \
--tags Key=project,Value=hands-on-cloud \
--query Policy.Arn --output text)
echo "$POLICY_ARN"
aws iam get-policy-version --policy-arn "$POLICY_ARN" --version-id v1 \
--query 'PolicyVersion.Document.Statement[].Sid'
โ
Expected: arn:aws:iam::<your account ID>:policy/hoc-read-site-bucket, then ["ListTheBucket", "ReadItsObjects"].
๐งน Cleanup
aws iam delete-policy --policy-arn "$POLICY_ARN"
rm -f ~/hoc-unit2/broken.json
aws logout
โ
delete-policy prints nothing. After aws logout, get-caller-identity fails: no credentials left. ๐
๐ฌ Say it in the interview
"I never create access keys for my own CLI: aws login gives it temporary credentials that expire on their own. Before a policy goes anywhere, I run the requests that must be allowed and must be denied through the IAM policy simulator, and fix it until they match."
๐ฏ What you can now say
โ
"My CLI signs in with aws login, not a key"
โ
"First command when denied: aws sts get-caller-identity"
โ
"ListBucket needs the bucket ARN, GetObject the object ARN"
โ
"I prove a policy in the simulator before I attach it"
๐ Go deeper
This is the hands-on cut of Session 2 of our free Hands-on Cloud for Freshers course: the three rules AWS decides by, and the model answer.
๐ Read the full chapter on TechEazy Consulting
๐ Real projects and a real internship certificate get you hired. Start at TechEazy Consulting.
Top comments (0)