DEV Community

TechEazy Consulting
TechEazy Consulting

Posted on Originally published at techeazyconsulting.com

๐Ÿ” Use the AWS CLI Without Access Keys, and Prove a Policy Before You Attach It (Hands-on)

๐ŸŽค The interview question

"How do you use the AWS CLI without an access key, and how do you know a policy works before you attach it?"

The strong answer is two things you have actually run: sign the CLI in with aws login, and prove the policy in the IAM policy simulator first. 20 minutes. ๐Ÿ‘‡

๐Ÿ‘‰ Flow: Sign in without a key โ†’ Write the policy โ†’ Prove it in the simulator โ†’ Store it, look, delete


๐Ÿงฐ Before you start

  • ๐Ÿ’ป AWS CLI v2, version 2.32.0 or later (aws login needs it). Check with aws --version.
  • ๐Ÿ‘ค Signed in to the console as your everyday admin IAM user (not root). It needs the SignInLocalDevelopmentAccess managed policy or broader, e.g. AdministratorAccess.
  • ๐Ÿ”‘ Permissions used: iam:SimulateCustomPolicy, iam:CreatePolicy, iam:GetPolicyVersion, iam:DeletePolicy.
  • ๐ŸŒ Region: ap-south-1, or your usual one.
  • ๐Ÿ’ต Cost: $0. IAM and STS are free, and the simulator sends no real request to any service. No Free plan credits used.

๐Ÿ” Step 1: Sign the CLI in without a key

Why: an access key works until someone deletes it; one pushed to GitHub is a stolen account. aws login reuses your console sign-in and gives the CLI temporary credentials (refreshed every 15 minutes, 12 hours max).

aws --version
aws login
Enter fullscreen mode Exit fullscreen mode

At AWS Region [us-east-1]: type ap-south-1. In the browser, pick your user, then return.

โœ… Expected: aws-cli/2.32.0 or newer, then Updated profile default to use arn:aws:....

Now ask "who am I?" (it needs no permissions, so run it first whenever something is denied):

aws sts get-caller-identity
aws configure list
Enter fullscreen mode Exit fullscreen mode

โœ… Expected: an Arn ending in your user name, and login in the TYPE column.

โš ๏ธ If aws login is rejected as an unknown command โ†’ your CLI is older than 2.32.0. Update: curl -fsSL https://awscli.amazonaws.com/v2/install.sh | bash. If you see an old user or ExpiredToken โ†’ an access key in ~/.aws/credentials wins. Delete it and log in again.


๐Ÿ“ Step 2: Write a read-only policy

Why: interviewers listen for "least privilege": list one bucket, read its objects, nothing else. The bucket needn't exist yet.

BUCKET=hoc-site-ar-4821
mkdir -p ~/hoc-unit2 && cd ~/hoc-unit2
cat > hoc-read-policy.json << EOF
{
  "Version": "2012-10-17",
  "Statement": [
    {"Sid": "ListTheBucket", "Effect": "Allow", "Action": "s3:ListBucket", "Resource": "arn:aws:s3:::${BUCKET}"},
    {"Sid": "ReadItsObjects", "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::${BUCKET}/*"}
  ]
}
EOF
Enter fullscreen mode Exit fullscreen mode

๐Ÿ‘€ Note the two ARNs: ListBucket acts on the bucket, GetObject on the objects (/*).


๐Ÿงช Step 3: Prove it in the simulator

Why: the simulator answers "would this be allowed?" without touching anything or saving the policy. A helper makes each test one line:

sim() { aws iam simulate-custom-policy --policy-input-list "$(cat "$1")" \
  --action-names "$2" --resource-arns "$3" \
  --query 'EvaluationResults[0].EvalDecision' --output text; }

sim hoc-read-policy.json s3:ListBucket arn:aws:s3:::$BUCKET
sim hoc-read-policy.json s3:GetObject  arn:aws:s3:::$BUCKET/index.html
sim hoc-read-policy.json s3:PutObject  arn:aws:s3:::$BUCKET/index.html
Enter fullscreen mode Exit fullscreen mode

โœ… Expected: allowed, allowed, implicitDeny (the only other answer is explicitDeny).

๐Ÿ“š Why implicitDeny? The full chapter explains how AWS decides, with an eight-request test list for this policy.


๐Ÿงจ Break it on purpose

Put ListBucket on the object ARN, a classic beginner bug:

sed "s#\"arn:aws:s3:::${BUCKET}\"}#\"arn:aws:s3:::${BUCKET}/*\"}#" hoc-read-policy.json > broken.json
sim broken.json s3:ListBucket arn:aws:s3:::$BUCKET
Enter fullscreen mode Exit fullscreen mode

โœ… Expected: implicitDeny. Wrong resource ARN, so listing fails, and you caught it before a real user did.


๐Ÿ“ฆ Step 4: Store it, look at it, delete it

Why: the clean-up habit. Created, never attached, deleted.

POLICY_ARN=$(aws iam create-policy --policy-name hoc-read-site-bucket \
  --policy-document "$(cat hoc-read-policy.json)" \
  --tags Key=project,Value=hands-on-cloud \
  --query Policy.Arn --output text)
echo "$POLICY_ARN"
aws iam get-policy-version --policy-arn "$POLICY_ARN" --version-id v1 \
  --query 'PolicyVersion.Document.Statement[].Sid'
Enter fullscreen mode Exit fullscreen mode

โœ… Expected: arn:aws:iam::<your account ID>:policy/hoc-read-site-bucket, then ["ListTheBucket", "ReadItsObjects"].


๐Ÿงน Cleanup

aws iam delete-policy --policy-arn "$POLICY_ARN"
rm -f ~/hoc-unit2/broken.json
aws logout
Enter fullscreen mode Exit fullscreen mode

โœ… delete-policy prints nothing. After aws logout, get-caller-identity fails: no credentials left. ๐ŸŽ‰


๐Ÿ’ฌ Say it in the interview

"I never create access keys for my own CLI: aws login gives it temporary credentials that expire on their own. Before a policy goes anywhere, I run the requests that must be allowed and must be denied through the IAM policy simulator, and fix it until they match."


๐ŸŽฏ What you can now say

โœ… "My CLI signs in with aws login, not a key"
โœ… "First command when denied: aws sts get-caller-identity"
โœ… "ListBucket needs the bucket ARN, GetObject the object ARN"
โœ… "I prove a policy in the simulator before I attach it"


๐Ÿ“š Go deeper

This is the hands-on cut of Session 2 of our free Hands-on Cloud for Freshers course: the three rules AWS decides by, and the model answer.

๐Ÿ‘‰ Read the full chapter on TechEazy Consulting

๐Ÿš€ Real projects and a real internship certificate get you hired. Start at TechEazy Consulting.

Top comments (0)