AWS 029: Install and verify AWS CLI v2 on Linux
The problem
A beginner receives AWS CLI commands without first installing the tool, checking CPU architecture, understanding sudo, validating the download source, or separating installation from authentication.
This lesson installs the executable only. Authentication is taught in AWS 030.
Final outcome
You will identify the Linux architecture, download the official AWS CLI v2 installer, inspect and optionally verify its signature, install or update it, prove which executable runs, and remove temporary installer files.
Before changing the system
AWS CLI v2 supports 64-bit recent Linux distributions listed in the official guide. The installer requires glibc, and extraction normally requires unzip.
Run:
uname -m
getconf LONG_BIT
command -v curl
command -v unzip
command -v gpg
command -v aws
Interpret common architectures:
x86_64uses the x86 64-bit installer.aarch64orarm64uses the ARM 64-bit installer.- another result requires checking current AWS support rather than guessing.
command -v returning no output and a nonzero exit means the command was not found through the current PATH.
Check for an existing installation
If aws exists:
aws --version
command -v aws
type -a aws
Record the version and every discovered path. Linux can have an old distribution package and a separate AWS installer. Updating the wrong installation leaves the old executable first in PATH.
Do not remove an existing package until you know how it was installed and whether other automation depends on its path.
Prepare a temporary directory
AWSCLI_TMP="$(mktemp -d)"
printf 'temporary_directory=%s\n' "$AWSCLI_TMP"
cd "$AWSCLI_TMP"
mktemp -d creates a unique temporary directory. The task-specific variable prevents accidental use of a broad deletion target.
Choose exactly one download URL after checking uname -m.
For x86 64-bit:
curl -fL "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" \
-o "awscliv2.zip"
For ARM 64-bit:
curl -fL "https://awscli.amazonaws.com/awscli-exe-linux-aarch64.zip" \
-o "awscliv2.zip"
Options:
-ffails for HTTP error responses;-Lfollows redirects;-owrites the named local file.
Check:
ls -lh awscliv2.zip
unzip -t awscliv2.zip
The archive test must finish successfully before extraction.
Signature verification
The official installer archives have detached PGP signatures. For a stronger supply-chain check:
- install or obtain GnuPG through your trusted operating-system method;
- copy the current AWS CLI public key from the official installation guide;
- compare its fingerprint with the value documented there;
- download the matching
.sigfile; - run
gpg --verify awscliv2.sig awscliv2.zip; - stop if the signature is bad, missing, or from an unexpected key.
Do not copy a public key from an unrelated blog. This lesson does not reproduce the key because keys and instructions must be verified from the current official page.
Extract and inspect
unzip -q awscliv2.zip
find aws -maxdepth 2 -type f | head
The extracted aws/install program performs installation. You are about to use elevated privileges, so confirm:
- current directory is the unique temporary directory;
- archive came from
awscli.amazonaws.com; - signature or provenance review succeeded;
aws/installexists;- no unrelated command was substituted.
Install or update
For a first official installation:
sudo ./aws/install
sudo runs the installer with elevated system privileges. Read the password prompt and final path. Do not paste an AWS password or MFA code into sudo; it expects the local Linux account password.
For an existing official install, first identify its paths:
ls -l "$(command -v aws)"
Then follow the official update syntax using the existing install and binary directories. A common installation uses:
sudo ./aws/install \
--bin-dir /usr/local/bin \
--install-dir /usr/local/aws-cli \
--update
Do not assume those paths if inspection shows different ones.
Verify the result
Open a new terminal if the shell cached an old path, or run:
hash -r
command -v aws
type -a aws
aws --version
aws help
printf 'exit=%s\n' "$?"
Success requires:
- the expected executable path;
- version output beginning with
aws-cli/2; - help command exit code
0.
This proves local installation. It does not prove authentication, authorization, connectivity, or Region configuration.
Cleanup
Return outside the temporary directory before removal:
cd /
printf 'cleanup_target=%s\n' "$AWSCLI_TMP"
Confirm the printed path is the unique directory created by mktemp. Remove only that exact temporary directory using your approved local cleanup method, then:
unset AWSCLI_TMP
Never place installer archives in the course evidence folder. Evidence should contain version, architecture, source URL, verification result, executable path, and install date.
Troubleshooting
| Symptom | Likely cause | Check |
|---|---|---|
Exec format error | wrong CPU installer | uname -m |
unzip: command not found | prerequisite missing | trusted distribution package method |
aws still old | PATH or shell cache | type -a aws, hash -r |
| permission denied | installer or target permissions | file mode and correct use of sudo |
| signature failure | altered file, wrong signature, or wrong key | delete download and restart from official guide |
| installer says existing install | update path required | inspect symlink and install directory |
Knowledge check
- Why check
uname -m? - What does
unzip -tprove? - Why inspect
type -a aws? - Does
aws --versionprove AWS access? - Why use a unique temporary directory?
Expected answers: select the correct architecture; archive structure and integrity can be read; multiple installations may exist; no; cleanup remains narrow and predictable.
Completion gate
Pass when AWS CLI v2 runs from the expected path, architecture and provenance checks are recorded, help returns 0, temporary files are removed safely, and the learner states that authentication is still not configured.
No AWS resources were created.