The AWS CLI 24 (AWS CLI v2) talks to real AWS 24 unless told otherwise. AWS CLI v2 reads AWS_ENDPOINT_URL for every service (or endpoint_url in a profile), so this chapter simply exports it with dummy credentials, which LocalStack 63,725 accepts:
export AWS_ENDPOINT_URL=http://localhost:31566 AWS_DEFAULT_REGION=us-east-1
export AWS_ACCESS_KEY_ID=test AWS_SECRET_ACCESS_KEY=test
aws sts get-caller-identity --output text
env -u AWS_ENDPOINT_URL aws sts get-caller-identity --output text 2>&1 \
| sed 's/ when calling.*//'000000000000 arn:aws:iam::000000000000:root AKIAIOSFODNN7EXAMPLE aws: [ERROR]: An error occurred (InvalidClientTokenId)
LocalStack answers as account 000000000000. Without the endpoint, the same call went to real AWS, which rejected the dummy key; in a shell holding real keys, it would have run against your account. Keep the variables in one sourced file, or make the choice explicit per command with a named profile: a [profile localstack] block in ~/.aws/config with endpoint_url = http://localhost:31566, test keys under [localstack] in ~/.aws/credentials, and aws --profile localstack ... reaches LocalStack too.
LocalStack's own wrapper, awslocal 1,301 (awscli-local 0.22.2, github.com/localstack/awscli-local (https://github.com/localstack/awscli-local 1,301 ), pipx 21,050 install awscli-local), predates endpoint variables: it runs aws with --endpoint-url filled in from AWS_ENDPOINT_URL or LOCALSTACK_HOST (default localhost:4566), and sets test credentials. With the exports above, both behave identically, so the book prints plain aws commands, which also work against real AWS.