← ClaudeAtlas

awslisted

Operate AWS accounts, resources, and SSO profiles with aws and aws-sso-util.
fmind/dot · ★ 9 · AI & Automation · score 79
Install: claude install-skill fmind/dot
# Amazon Web Services CLI Use `aws` and `aws-sso-util` for AWS account, IAM, S3, ECS, and CloudWatch operations. [infra-as-code](../infra-as-code/SKILL.md) owns provisioned infrastructure, and [incident-response](../incident-response/SKILL.md) owns a live outage. ## Workflow 1. **Resolve identity and profile context**: inspect the active AWS profile, SSO session, and caller identity; never assume role or run commands under ambiguous profiles. ```bash aws sts get-caller-identity --profile <profile> --output json aws configure list-profiles ``` 1. **Authenticate via SSO**: when credentials expire, refresh the session using AWS IAM Identity Center (SSO); avoid long-lived access keys. ```bash aws sso login --profile <profile> # Or using aws-sso-util: aws-sso-util login --profile <profile> ``` 1. **Pin every consequential call**: pass `--profile <name>` and `--region <region>` explicitly so environment variables or shell defaults cannot redirect operations to the wrong account or region. 1. **Start read-only with bounded queries**: use `--query` (JMESPath) and `--max-items` to constrain results; describe resources, IAM policies, and CloudWatch metrics before changing anything. ```bash aws s3 ls --profile <profile> aws ecs list-clusters --profile <profile> --region <region> --max-items 20 --output json ``` 1. **Plan mutations and confirm**: state the target ARN, expected before and after states, and rollback steps; resource creation,