AWS CLI Beast Mode
Overview
Advanced AWS CLI patterns for speed, precision, and security-first automation. Covers JMESPath queries, bulk operations, waiters, cross-account access, and destructive operation safety.
When to Use
- Bulk operations across thousands of AWS resources
- Advanced JMESPath filtering and output transformation
- Automated scripts for AWS routines
- Multi-profile and multi-region management
- Security auditing and compliance checks
- CLI-driven infrastructure-as-code workflows
Instructions
Step 1: Categorize the Request
| Category |
Services |
Commands |
| Compute |
EC2, Lambda |
describe-instances, invoke, publish-version |
| Storage |
S3 |
sync, cp, mb, rb, presign |
| Database |
DynamoDB, RDS |
query, scan, batch-write-item |
| Networking |
VPC, Route53 |
describe-vpcs, describe-security-groups |
| Security |
IAM |
simulate-principal-policy, get-policy-version |
| Observability |
CloudWatch |
get-metric-statistics, filter-log-events |
Step 2: Apply Beast Mode Principles
- Dry-run first: Always validate with
--dryrun or --dry-run
- Query server-side: Use
--query with JMESPath to filter before transfer
- Batch intelligently: Paginate with
--max-results and parallelize with xargs
- Wait properly: Use built-in waiters or exponential backoff polling
- Switch contexts: Use
--profile and --region for multi-account operations
Step 3: Validate Destructive Operations
MANDATORY for any destructive operation:
# S3 sync with delete - MUST dry-run first
aws s3 sync s3://source/ s3://dest/ --delete --dryrun
# Review output, then remove --dryrun only if satisfied
# Bulk EC2 stop - validate targets first
aws ec2 describe-instances \
--filters "Name=tag:Environment,Values=development" \
--query 'Reservations[].Instances[?State.Name==`running`].InstanceId' \
--output text
# Confirm list, then pipe to stop command
# IAM policy attachment - simulate first
aws iam simulate-principal-policy \
--policy-source-arn arn:aws:iam::123456789012:user/myuser \
--action-names s3:DeleteObject \
--resource-arns arn:aws:s3:::my-bucket/*
Step 4: Reference Detailed Guides
compute-mastery.md - EC2, Lambda, Spot Fleets, ASG
data-ops-beast.md - S3 multipart, DynamoDB batch, RDS snapshots
networking-security-hardened.md - VPC Flow Logs, IAM policies, security groups
automation-patterns.md - Shell aliases, JMESPath templates, CI/CD integration
Examples
Example 1: Bulk EC2 Stop
"Stop all development instances"
# 1. Dry-run: identify targets
aws ec2 describe-instances \
--filters "Name=tag:Environment,Values=development" \
"Name=instance-state-name,Values=running" \
--query 'Reservations[].Instances[].InstanceId' \
--output text
# 2. Confirm IDs, then execute
aws ec2 describe-instances \
--filters "Name=tag:Environment,Values=development" \
"Name=instance-state-name,Values=running" \
--query 'Reservations[].Instances[].InstanceId' \
--output text | xargs aws ec2 stop-instances --instance-ids
Example 2: S3 Migration with Encryption
"Migrate data between buckets with SSE"
# 1. Dry-run migration
aws s3 sync s3://source-bucket/ s3://dest-bucket/ \
--sse AES256 \
--storage-class GLACIER \
--exclude "*.tmp" \
--dryrun
# 2. Enable versioning on destination
aws s3api put-bucket-versioning \
--bucket dest-bucket \
--versioning-configuration Status=Enabled
# 3. Execute after review
aws s3 sync s3://source-bucket/ s3://dest-bucket/ \
--sse AES256 \
--storage-class GLACIER \
--exclude "*.tmp"
Example 3: IAM Security Audit
"Find overprivileged IAM users"
aws iam list-users --query 'Users[].UserName' --output text | \
while read user; do
echo "Checking $user..."
aws iam simulate-principal-policy \
--policy-source-arn "arn:aws:iam::123456789012:user/$user" \
--action-names DeleteItem,DeleteTable,DeleteFunction \
--resource-arns "*" \
--query 'EvaluationResults[?EvalDecision==`allowed`]'
done
Example 4: Multi-Region Lambda Deployment
"Deploy Lambda to all regions"
for region in us-east-1 us-west-2 eu-west-1; do
echo "Deploying to $region..."
aws lambda update-function-code \
--function-name my-function \
--zip-file fileb://function.zip \
--region $region \
--publish
aws lambda wait function-active \
--function-name my-function \
--region $region
done
Example 5: JMESPath Advanced Filtering
"Get running instances with specific tags as table"
aws ec2 describe-instances \
--query 'Reservations[].Instances[?State.Name==`running`].[InstanceId,Tags[?Key==`Name`].Value[0]|[0],PrivateIpAddress]' \
--output table
Best Practices
- Use
--output json for programmatic processing
- Filter with JMESPath server-side before transfer
- Implement retry logic with exponential backoff
- Use waiters instead of manual polling loops
- Tag all resources for cost allocation and automation
- Separate dev/staging/prod with AWS profiles
- Enable CloudTrail for audit compliance
- Validate IAM policies with simulate-principal-policy before attachment
- Use --dry-run on every state-modifying operation
- Enable MFA for security-sensitive operations
Constraints and Warnings
Rate Limiting
- AWS API throttling applies; use
--max-throttle and exponential backoff
- Check
aws service-quotas for current limits
Pagination
- Default page size is variable; use
--max-results for consistency
- Use
--no-paginate with jq for full dataset processing
Destructive Operations
- S3 sync --delete: Irreversibly removes files not in source
- EC2 terminate-instances: Cannot be undone; validate instance IDs first
- IAM detach/policy: May break existing access; simulate before applying
- RDS delete-db-instance: Snapshots do not protect all scenarios; verify retention
Security
- Never commit AWS credentials; use
aws configure or environment variables
- Rotate access keys regularly with
aws iam create-access-key
- Use least-privilege: simulate before granting permissions
1---2name: aws-cli-beast3description: Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch. Generates bulk operation scripts, automates cross-service workflows, validates security configurations, and executes JMESPath queries for complex filtering. Triggers on "aws cli help", "aws command line", "aws scripting", "aws automation", "aws batch operations", "aws bulk operations", "aws cli pagination", "aws multi-region", "aws profiles", "aws cli troubleshooting".4---5
6# AWS CLI Beast Mode
7
8## Overview
9
10Advanced AWS CLI patterns for speed, precision, and security-first automation. Covers JMESPath queries, bulk operations, waiters, cross-account access, and destructive operation safety.
11
12## When to Use
13
14- Bulk operations across thousands of AWS resources
15- Advanced JMESPath filtering and output transformation
16- Automated scripts for AWS routines
17- Multi-profile and multi-region management
18- Security auditing and compliance checks
19- CLI-driven infrastructure-as-code workflows
20
21## Instructions
22
23### Step 1: Categorize the Request
24
25| Category | Services | Commands |
26|----------|----------|----------|
27| Compute | EC2, Lambda | describe-instances, invoke, publish-version |
28| Storage | S3 | sync, cp, mb, rb, presign |
29| Database | DynamoDB, RDS | query, scan, batch-write-item |
30| Networking | VPC, Route53 | describe-vpcs, describe-security-groups |
31| Security | IAM | simulate-principal-policy, get-policy-version |
32| Observability | CloudWatch | get-metric-statistics, filter-log-events |
33
34### Step 2: Apply Beast Mode Principles
35
361. **Dry-run first**: Always validate with `--dryrun` or `--dry-run`
372. **Query server-side**: Use `--query` with JMESPath to filter before transfer
383. **Batch intelligently**: Paginate with `--max-results` and parallelize with xargs
394. **Wait properly**: Use built-in waiters or exponential backoff polling
405. **Switch contexts**: Use `--profile` and `--region` for multi-account operations
41
42### Step 3: Validate Destructive Operations
43
44**MANDATORY** for any destructive operation:
45
46```bash
47# S3 sync with delete - MUST dry-run first
48aws s3 sync s3://source/ s3://dest/ --delete --dryrun
49# Review output, then remove --dryrun only if satisfied
50
51# Bulk EC2 stop - validate targets first
52aws ec2 describe-instances \
53 --filters "Name=tag:Environment,Values=development" \
54 --query 'Reservations[].Instances[?State.Name==`running`].InstanceId' \
55 --output text
56# Confirm list, then pipe to stop command
57
58# IAM policy attachment - simulate first
59aws iam simulate-principal-policy \
60 --policy-source-arn arn:aws:iam::123456789012:user/myuser \
61 --action-names s3:DeleteObject \
62 --resource-arns arn:aws:s3:::my-bucket/*
63```
64
65### Step 4: Reference Detailed Guides
66
67- `compute-mastery.md` - EC2, Lambda, Spot Fleets, ASG
68- `data-ops-beast.md` - S3 multipart, DynamoDB batch, RDS snapshots
69- `networking-security-hardened.md` - VPC Flow Logs, IAM policies, security groups
70- `automation-patterns.md` - Shell aliases, JMESPath templates, CI/CD integration
71
72## Examples
73
74### Example 1: Bulk EC2 Stop
75
76**"Stop all development instances"**
77
78```bash
79# 1. Dry-run: identify targets
80aws ec2 describe-instances \
81 --filters "Name=tag:Environment,Values=development" \
82 "Name=instance-state-name,Values=running" \
83 --query 'Reservations[].Instances[].InstanceId' \
84 --output text
85
86# 2. Confirm IDs, then execute
87aws ec2 describe-instances \
88 --filters "Name=tag:Environment,Values=development" \
89 "Name=instance-state-name,Values=running" \
90 --query 'Reservations[].Instances[].InstanceId' \
91 --output text | xargs aws ec2 stop-instances --instance-ids
92```
93
94### Example 2: S3 Migration with Encryption
95
96**"Migrate data between buckets with SSE"**
97
98```bash
99# 1. Dry-run migration
100aws s3 sync s3://source-bucket/ s3://dest-bucket/ \
101 --sse AES256 \
102 --storage-class GLACIER \
103 --exclude "*.tmp" \
104 --dryrun
105
106# 2. Enable versioning on destination
107aws s3api put-bucket-versioning \
108 --bucket dest-bucket \
109 --versioning-configuration Status=Enabled
110
111# 3. Execute after review
112aws s3 sync s3://source-bucket/ s3://dest-bucket/ \
113 --sse AES256 \
114 --storage-class GLACIER \
115 --exclude "*.tmp"
116```
117
118### Example 3: IAM Security Audit
119
120**"Find overprivileged IAM users"**
121
122```bash
123aws iam list-users --query 'Users[].UserName' --output text | \
124while read user; do
125 echo "Checking $user..."
126 aws iam simulate-principal-policy \
127 --policy-source-arn "arn:aws:iam::123456789012:user/$user" \
128 --action-names DeleteItem,DeleteTable,DeleteFunction \
129 --resource-arns "*" \
130 --query 'EvaluationResults[?EvalDecision==`allowed`]'
131done
132```
133
134### Example 4: Multi-Region Lambda Deployment
135
136**"Deploy Lambda to all regions"**
137
138```bash
139for region in us-east-1 us-west-2 eu-west-1; do
140 echo "Deploying to $region..."
141 aws lambda update-function-code \
142 --function-name my-function \
143 --zip-file fileb://function.zip \
144 --region $region \
145 --publish
146 aws lambda wait function-active \
147 --function-name my-function \
148 --region $region
149done
150```
151
152### Example 5: JMESPath Advanced Filtering
153
154**"Get running instances with specific tags as table"**
155
156```bash
157aws ec2 describe-instances \
158 --query 'Reservations[].Instances[?State.Name==`running`].[InstanceId,Tags[?Key==`Name`].Value[0]|[0],PrivateIpAddress]' \
159 --output table
160```
161
162## Best Practices
163
1641. Use `--output json` for programmatic processing
1652. Filter with JMESPath server-side before transfer
1663. Implement retry logic with exponential backoff
1674. Use waiters instead of manual polling loops
1685. Tag all resources for cost allocation and automation
1696. Separate dev/staging/prod with AWS profiles
1707. Enable CloudTrail for audit compliance
1718. Validate IAM policies with simulate-principal-policy before attachment
1729. Use --dry-run on every state-modifying operation
17310. Enable MFA for security-sensitive operations
174
175## Constraints and Warnings
176
177### Rate Limiting
178- AWS API throttling applies; use `--max-throttle` and exponential backoff
179- Check `aws service-quotas` for current limits
180
181### Pagination
182- Default page size is variable; use `--max-results` for consistency
183- Use `--no-paginate` with jq for full dataset processing
184
185### Destructive Operations
186- **S3 sync --delete**: Irreversibly removes files not in source
187- **EC2 terminate-instances**: Cannot be undone; validate instance IDs first
188- **IAM detach/policy**: May break existing access; simulate before applying
189- **RDS delete-db-instance**: Snapshots do not protect all scenarios; verify retention
190
191### Security
192- Never commit AWS credentials; use `aws configure` or environment variables
193- Rotate access keys regularly with `aws iam create-access-key`
194- Use least-privilege: simulate before granting permissions