Lesson 029 · AWS Learning Path

AWS 029: Install and verify AWS CLI v2 on Linux

· Published · 5 min read

A graphical console, terminal, and application code all manage the same cloud control plane

The problem

A beginner receives AWS CLI commands without first installing the tool, checking CPU architecture, understanding sudo, validating the download source, or separating installation from authentication.

This lesson installs the executable only. Authentication is taught in AWS 030.

Final outcome

You will identify the Linux architecture, download the official AWS CLI v2 installer, inspect and optionally verify its signature, install or update it, prove which executable runs, and remove temporary installer files.

Before changing the system

AWS CLI v2 supports 64-bit recent Linux distributions listed in the official guide. The installer requires glibc, and extraction normally requires unzip.

Run:

uname -m
getconf LONG_BIT
command -v curl
command -v unzip
command -v gpg
command -v aws

Interpret common architectures:

  • x86_64 uses the x86 64-bit installer.
  • aarch64 or arm64 uses the ARM 64-bit installer.
  • another result requires checking current AWS support rather than guessing.

command -v returning no output and a nonzero exit means the command was not found through the current PATH.

Check for an existing installation

If aws exists:

aws --version
command -v aws
type -a aws

Record the version and every discovered path. Linux can have an old distribution package and a separate AWS installer. Updating the wrong installation leaves the old executable first in PATH.

Do not remove an existing package until you know how it was installed and whether other automation depends on its path.

Prepare a temporary directory

AWSCLI_TMP="$(mktemp -d)"
printf 'temporary_directory=%s\n' "$AWSCLI_TMP"
cd "$AWSCLI_TMP"

mktemp -d creates a unique temporary directory. The task-specific variable prevents accidental use of a broad deletion target.

Choose exactly one download URL after checking uname -m.

For x86 64-bit:

curl -fL "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" \
  -o "awscliv2.zip"

For ARM 64-bit:

curl -fL "https://awscli.amazonaws.com/awscli-exe-linux-aarch64.zip" \
  -o "awscliv2.zip"

Options:

  • -f fails for HTTP error responses;
  • -L follows redirects;
  • -o writes the named local file.

Check:

ls -lh awscliv2.zip
unzip -t awscliv2.zip

The archive test must finish successfully before extraction.

Signature verification

The official installer archives have detached PGP signatures. For a stronger supply-chain check:

  1. install or obtain GnuPG through your trusted operating-system method;
  2. copy the current AWS CLI public key from the official installation guide;
  3. compare its fingerprint with the value documented there;
  4. download the matching .sig file;
  5. run gpg --verify awscliv2.sig awscliv2.zip;
  6. stop if the signature is bad, missing, or from an unexpected key.

Do not copy a public key from an unrelated blog. This lesson does not reproduce the key because keys and instructions must be verified from the current official page.

Extract and inspect

unzip -q awscliv2.zip
find aws -maxdepth 2 -type f | head

The extracted aws/install program performs installation. You are about to use elevated privileges, so confirm:

  • current directory is the unique temporary directory;
  • archive came from awscli.amazonaws.com;
  • signature or provenance review succeeded;
  • aws/install exists;
  • no unrelated command was substituted.

Install or update

For a first official installation:

sudo ./aws/install

sudo runs the installer with elevated system privileges. Read the password prompt and final path. Do not paste an AWS password or MFA code into sudo; it expects the local Linux account password.

For an existing official install, first identify its paths:

ls -l "$(command -v aws)"

Then follow the official update syntax using the existing install and binary directories. A common installation uses:

sudo ./aws/install \
  --bin-dir /usr/local/bin \
  --install-dir /usr/local/aws-cli \
  --update

Do not assume those paths if inspection shows different ones.

Verify the result

Open a new terminal if the shell cached an old path, or run:

hash -r
command -v aws
type -a aws
aws --version
aws help
printf 'exit=%s\n' "$?"

Success requires:

  • the expected executable path;
  • version output beginning with aws-cli/2;
  • help command exit code 0.

This proves local installation. It does not prove authentication, authorization, connectivity, or Region configuration.

Cleanup

Return outside the temporary directory before removal:

cd /
printf 'cleanup_target=%s\n' "$AWSCLI_TMP"

Confirm the printed path is the unique directory created by mktemp. Remove only that exact temporary directory using your approved local cleanup method, then:

unset AWSCLI_TMP

Never place installer archives in the course evidence folder. Evidence should contain version, architecture, source URL, verification result, executable path, and install date.

Troubleshooting

SymptomLikely causeCheck
Exec format errorwrong CPU installeruname -m
unzip: command not foundprerequisite missingtrusted distribution package method
aws still oldPATH or shell cachetype -a aws, hash -r
permission deniedinstaller or target permissionsfile mode and correct use of sudo
signature failurealtered file, wrong signature, or wrong keydelete download and restart from official guide
installer says existing installupdate path requiredinspect symlink and install directory

Knowledge check

  1. Why check uname -m?
  2. What does unzip -t prove?
  3. Why inspect type -a aws?
  4. Does aws --version prove AWS access?
  5. Why use a unique temporary directory?

Expected answers: select the correct architecture; archive structure and integrity can be read; multiple installations may exist; no; cleanup remains narrow and predictable.

Completion gate

Pass when AWS CLI v2 runs from the expected path, architecture and provenance checks are recorded, help returns 0, temporary files are removed safely, and the learner states that authentication is still not configured.

No AWS resources were created.

Official sources

Advertisement