AWS 021: JSON, YAML, shell exit codes, environment variables, and safe copy-paste
The problem
Cloud instructions often mix shell commands, JSON, YAML, placeholders, and environment variables. A learner copies the prompt character, leaves an example Region unchanged, exposes a credential, or assumes that visible output means success.
This lesson builds the reading skills required before AWS CloudShell and the AWS CLI are introduced.
Final outcome
You will create a local evidence folder containing valid JSON and YAML, a shell transcript that proves success and failure exit codes, and a copy-paste safety checklist. No AWS account or AWS tool is required.
Recognize the layers
human instruction
|
v
shell parses command and expands variables
|
v
program receives arguments
|
v
program returns output plus an exit code
The shell and the program are different. Quoting, variables, pipes, and redirection are interpreted by the shell before the target program receives its arguments.
JSON
JSON uses objects, arrays, strings, numbers, Boolean values, and null.
{
"application": "training-portal",
"region": "ap-south-1",
"highAvailability": true,
"tiers": ["web", "application", "data"]
}
Rules that often surprise beginners:
- object keys and strings use double quotes;
- commas separate entries, but a trailing comma is invalid;
true,false, andnullare lowercase and are not strings;- duplicate keys should be avoided even if a parser accepts them;
- comments are not part of standard JSON.
JSON is common in AWS API responses, policies, and command input. Indentation improves reading but does not define the structure.
YAML
YAML represents mappings, sequences, and scalar values with indentation.
application: training-portal
region: ap-south-1
highAvailability: true
tiers:
- web
- application
- data
Spaces and indentation are meaningful. Do not use tabs for indentation. Quote values when automatic type interpretation could change the meaning. For example, identifiers with leading zeros and values resembling dates or Boolean words deserve explicit review.
YAML is not automatically safer or simpler than JSON. CloudFormation accepts JSON or YAML templates, but both describe the same underlying data model.
Shell exit codes
A process returns an integer exit status. By convention, 0 means success and a nonzero value means failure. The exact nonzero meaning belongs to the program.
Run locally:
mkdir -p "$HOME/nitwings-aws/evidence/aws-021"
cd "$HOME/nitwings-aws/evidence/aws-021"
command -v sh
printf '%s\n' "foundation check"
printf 'exit=%s\n' "$?"
test -f missing-file.txt
printf 'exit=%s\n' "$?"
Read each command:
mkdir -pcreates the folder and does not complain if it already exists.cdchanges the current directory.command -v shchecks whether the shell command is available.printfwrites controlled text.$?expands to the immediately preceding command's exit code.test -fsucceeds only when the path is a regular file.
The first recorded exit should be 0. The missing-file test should be nonzero. Always inspect $? immediately because the next command replaces it.
Environment variables
An environment variable passes a named value to the current process and its child processes.
COURSE_REGION="ap-south-1"
export COURSE_REGION
printf 'region=%s\n' "$COURSE_REGION"
env | grep '^COURSE_REGION='
unset COURSE_REGION
The variable name is COURSE_REGION. Quotes keep the value as one shell word. export makes it available to child processes. unset removes it from the current shell.
Do not store passwords, access keys, session tokens, or private keys in screenshots, shell history, notes, or source control. Environment variables are useful, but they are not a secret vault.
Safe copy-paste method
Before pressing Enter:
- Read the complete command and the explanation.
- Remove prompt characters such as
$or#. - Identify placeholders such as
<course-region>and replace each one. - Check quotes, paths, variables, pipes, redirections, and line-continuation backslashes.
- Look up every unfamiliar option with
command --helpor its manual. - Separate download, inspection, installation, execution, and deletion steps.
- Prefer read-only inspection before mutation.
- Never paste secrets into a command shared by another person.
- Run one logical step at a time.
- capture both output and exit status before continuing.
Treat curl ... | sh as high risk because downloaded content is executed without a review boundary. Download to a temporary location, validate the origin and integrity, inspect it, and only then decide whether to run it.
Practical evidence
Create portal.json and portal.yaml using a text editor. Represent the same application, Region, three tiers, and high-availability Boolean in both formats.
Validate JSON with any locally available parser. One common option is:
python3 -m json.tool portal.json
printf 'json_exit=%s\n' "$?"
If Python is unavailable, record that fact rather than installing software silently. For YAML, visual inspection is not proof of valid syntax. Use an existing trusted parser if available, or record validation as pending until a later lesson provides one.
Create evidence.txt containing:
- the shell used;
- one command that returned
0; - one intentional failure and its nonzero status;
- the variable before and after
unset; - the JSON validation result;
- three risks found by reviewing a sample internet command.
Redact usernames and local paths if the file will be shared.
Troubleshooting
| Symptom | Likely cause | Safe check |
|---|---|---|
command not found | copied prompt, missing program, or wrong PATH | command -v program |
| variable prints literally | single quotes or escaped dollar sign | compare quoting rules |
| variable is empty | not set in this shell | printf '<%s>\n' "$NAME" |
| JSON parser reports an error | quote, comma, or structure problem | use reported line and column |
| YAML meaning changes | indentation or implicit type | quote ambiguous values |
| expected exit code disappears | another command ran first | rerun and inspect immediately |
Knowledge check
- Does visible output prove a command succeeded?
- What does exit status
0conventionally mean? - Does JSON use indentation to define structure?
- Why quote shell variable expansions?
- Why is piping a download directly to a shell risky?
Expected answers: no, inspect the exit status and result; success; no; to preserve one argument and avoid unwanted splitting; it removes the inspection boundary.
Completion gate
Pass when both data files represent the same values, JSON validates, the transcript proves one success and one intentional failure, the variable lifecycle is explained, and the safety checklist identifies placeholders, secrets, mutation, and cleanup.
No AWS resources were created.