• /
  • EnglishEspañolFrançais日本語한국어Português
  • ログイン今すぐ開始

この機械翻訳は、参考として提供されています。

英語版と翻訳版に矛盾がある場合は、英語版が優先されます。詳細については、このページを参照してください。

問題を作成する

AWS EC2 アクション

|View as Markdown (English)

This page provides a reference for AWS EC2 actions available in the workflow automation actions catalog. Use these actions to manage EC2 instances, EBS volumes and snapshots, Elastic IP addresses, Amazon Machine Images (AMIs), security groups, key pairs, and EC2 resource tags.

前提条件

ワークフロー自動化で AWS アクションを使用する前に、次の点を確認してください。

  • 適切な権限を持つ AWS アカウント。
  • 設定された AWS 認証情報 (IAM ユーザー認証情報、IAM ロール ARN、またはセッション認証情報)。
  • 使用する予定の特定のAWSサービスに必要な IAM 権限。

IAM ユーザーおよび IAM ロールを作成する方法、およびワークフロー オートメーションAWSアクションと統合するための静的 AWS 認証情報とセッションAWS認証情報を設定する方法については、 AWS認証情報のセットアップ」を参照してください。

インスタンスを実行する

アクション識別子はaws.ec2.runInstancesです。

権限を持つAMIを使用して、指定された数のインスタンスをリリースします。サブネットIDを指定しない場合、デフォルトのVPCサブネットが使用されます。ユーザーがサブスクライブしていない製品コードを持つAMIがある場合、リクエストは失敗します。

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

必須。インスタンスがリリースされるAWSリージョン。

us-east-2

imageId

弦

必須。インスタンスに使用するAMIのIDです。

ami-0ca4d5db4872d0c28

instanceType

弦

必須。インスタンスに使用するインスタンスタイプ。

t2.micro

minCount

Int

必須。リリースするインスタンスの最小数。

1

maxCount

Int

必須。リリースするインスタンスの最大数。

10

parameters

地図

オプション。run_instances呼び出しの追加のboto3 APIパラメーター。

{"EbsOptimized": false, "TagSpecifications": [{"ResourceType": "instance", "Tags": [{"Key": "Name", "Value": "My-Web-Server"}]}]}

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

ヒント

parameters マップは、boto3 API で利用可能な任意のオプション引数を受け入れるため、requests を動的に構築できます。

次の表は、このアクションの出力フィールドについて説明しています。

インスタンスを説明する

アクション識別子はaws.ec2.describeInstancesです。

指定されたインスタンスまたはすべてのインスタンスについて説明します。

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

必須。インスタンスが配置されているAWSリージョン。

us-east-2

instanceIds

リスト

オプション。記述するインスタンスIDの一覧。

["i-0123456789abcdef0", "i-0fedcba9876543210"]

filters

リスト

オプション。describeリクエストに適用するフィルター。

[{"Name": "instance-state-name", "Values": ["running"]}]

nextToken

弦

オプション。以前のレスポンスからのページネーショントークン。

abcdefgh

maxResults

Int

オプション。返す結果の最大数です。

100

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

describe_instances boto3リファレンス

を参照してください。

success

ブール値

true

または

false

errorMessage

弦

"The parameter instancesSet cannot be used with the parameter maxResults"

重要

インスタンスIDを指定した場合、出力には指定されたインスタンスの情報のみが含まれます。フィルターを指定した場合、出力にはフィルター条件を満たすインスタンスの情報のみが含まれます。どちらも指定しない場合、出力にはすべてのインスタンスの情報が含まれます。instanceIdsパラメーターはmaxResultsと一緒に使用できません。

インスタンスを再起動する

アクション識別子はaws.ec2.startInstancesです。

以前に停止した Amazon EBS ベースのインスタンスを起動します。

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

必須。インスタンスが配置されているAWSリージョン。

us-east-2

instanceIds

リスト

必須。開始するインスタンスIDの一覧。

["i-0123456789abcdef0", "i-0fedcba9876543210"]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

start_instances boto3リファレンス

を参照してください。

success

ブール値

true

または

false

errorMessage

弦

"The parameter instancesSet cannot be used with the parameter maxResults"

インスタンスを停止する

アクション識別子はaws.ec2.stopInstancesです。

Amazon EBS-backed インスタンスを停止します。

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

必須。インスタンスが配置されているAWSリージョン。

us-east-2

instanceIds

リスト

必須。停止するインスタンスIDの一覧。

["i-0123456789abcdef0", "i-0fedcba9876543210"]

hibernate

ブール値

オプション。インスタンスを停止する代わりにHibernateします。デフォルト:

false

。

false

force

ブール値

オプション。インスタンスの停止を強制します。デフォルト:

false

。

false

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

stop_instances boto3 リファレンス

を参照してください。

success

ブール値

true

または

false

errorMessage

弦

"An error occurred (InvalidInstanceID.Malformed) when calling the StopInstances operation: The instance ID 'i-123456789' is malformed"

インスタンスの再起動をリクエストします

アクション識別子はaws.ec2.rebootInstancesです。

指定されたインスタンスの再起動をリクエストします。この操作は非同期です — 指定されたインスタンスを再起動するリクエストをキューに入れるだけです。インスタンスが有効であり、お客様の所有である場合、操作は成功します。終了したインスタンスを再起動するリクエストは無視されます。インスタンスが数分以内に正常にシャットダウンしない場合、Amazon EC2はハードリブートを実行します。

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

必須。インスタンスが配置されているAWSリージョン。

us-east-2

instanceIds

リスト

必須。再起動するインスタンスIDの一覧。

["i-0123456789abcdef0", "i-0fedcba9876543210"]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

reboot_instances boto3リファレンス

を参照してください。

success

ブール値

true

または

false

errorMessage

弦

""

インスタンスをシャットダウンする

アクション識別子はaws.ec2.terminateInstancesです。

指定されたインスタンスをシャットダウンします。この操作はべき等です — インスタンスを複数回終了しても、各呼び出しは成功します。複数のインスタンスを指定してリクエストが失敗した場合(たとえば、1つの誤ったインスタンスIDが原因の場合)、どのインスタンスも終了しません。

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

必須。インスタンスが配置されているAWSリージョン。

us-east-2

instanceIds

リスト

必須。終了するインスタンスのID。

["i-0123456789abcdef0", "i-0fedcba9876543210"]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

terminate_instances boto3リファレンス

を参照してください。

success

ブール値

true

または

false

errorMessage

弦

"An error occurred (InvalidInstanceID.Malformed) when calling the TerminateInstances operation: The instance ID 'i-012345678' is malformed"

EBSスナップショットを作成する

アクション識別子はaws.ec2.createSnapshotです。

EBSボリュームのスナップショットを作成し、Amazon S3に保存します。スナップショットは、バックアップ、EBSボリュームのコピーの作成、およびインスタンスをシャットダウンする前のデータの保存に使用できます。ソースEBSボリュームの場所によって、スナップショットを作成できる場所が決まります。

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

必須。EBSボリュームが配置されているAWSリージョン。

us-east-2

volumeId

弦

必須。スナップショットを作成するEBSボリュームのID。

vol-0123456789abcdef0

description

弦

オプション。スナップショットの説明。

This is a test snapshot

outpostArn

弦

オプション。スナップショットを作成するOutpostのAmazonリソースネーム(ARN)。

arn:aws:ec2:us-east-1:123456789012:outpost/op-1a2b3c4d5e6f7g8h9

tagSpecifications

リスト

オプション。作成時にスナップショットに適用するタグ。

[{"ResourceType":"snapshot","Tags":[{"Key":"testKey","Value":"testValue"}]}]

location

弦

オプション。スナップショットの場所。有効な値:

regional

、

local

。

regional

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

create_snapshot boto3リファレンス

をご覧ください。

success

ブール値

true

または

false

errorMessage

弦

""

スナップショットを削除する

アクション識別子はaws.ec2.deleteSnapshotです。

指定されたスナップショットを削除します。登録済みのAMIで使用されているEBSボリュームのルートデバイスのスナップショットは削除できません — スナップショットを削除する前に、まずAMIの登録を解除する必要があります。

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

必須。スナップショットが配置されている AWS リージョン。

us-east-2

snapshotId

弦

必須。削除するスナップショットのID。

snapshot-id-1

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

成功時にレスポンスボディはありません。

delete_snapshot boto3リファレンス

を参照してください。

success

ブール値

true

または

false

errorMessage

弦

"Failed to delete snapshot"

Allocate an Elastic IP address

アクション識別子はaws.ec2.allocateAddressです。

Allocates a new Elastic IP address for use with EC2 instances in a VPC.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the address is allocated.

us-east-2

domain

弦

Optional. Scope of the address. Use

vpc

for VPC instances.

vpc

address

弦

Optional. A specific Elastic IP address to recover that you previously released.

203.0.113.25

networkBorderGroup

弦

Optional. Limits the group from which the IP address is advertised.

us-east-2

tagSpecifications

リスト

Optional. Tags applied to the address at allocation time.

[{"ResourceType": "elastic-ip", "Tags": [{"Key": "Name", "Value": "nat-eip"}]}]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "allocationId", "expression": ".response.AllocationId"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

allocate_address boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Associate an Elastic IP address

アクション識別子はaws.ec2.associateAddressです。

Associates an Elastic IP address with an EC2 instance or network interface.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the association is made.

us-east-2

allocationId

弦

Optional. The Elastic IP allocation ID to associate. Use with

instanceId

or

networkInterfaceId

for VPC instances.

eipalloc-0123456789abcdef0

instanceId

弦

Optional. The instance to associate the address with.

i-0123456789abcdef0

publicIp

弦

Optional. Alternative to

allocationId

for EC2-Classic addresses.

203.0.113.25

networkInterfaceId

弦

Optional. Target network interface instead of an instance.

eni-0123456789abcdef0

privateIpAddress

弦

Optional. A specific private IP on the network interface to associate with.

10.0.1.25

allowReassociation

ブール値

Optional. Allow the address to move off an existing association. Default:

false

.

false

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "associationId", "expression": ".response.AssociationId"}]

重要

Only certain combinations of identifiers are valid. For VPC instances, use allocationId with instanceId or networkInterfaceId. For EC2-Classic instances, use publicIp with instanceId. Do not mix the two forms.

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

associate_address boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Disassociate an Elastic IP address

アクション識別子はaws.ec2.disassociateAddressです。

Disassociates an Elastic IP address from its current instance or network interface.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the association exists.

us-east-2

associationId

弦

Optional. The association ID returned by

aws.ec2.associateAddress

. Use for VPC addresses.

eipassoc-0123456789abcdef0

publicIp

弦

Optional. Alternative to

associationId

for EC2-Classic addresses.

203.0.113.25

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

重要

Use exactly one identifier matching the domain the address was associated in. For VPC addresses, use associationId. For EC2-Classic addresses, use publicIp.

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

No response body on success. See the

disassociate_address boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Release an Elastic IP address

アクション識別子はaws.ec2.releaseAddressです。

Releases an Elastic IP address back to the AWS pool. The address must already be disassociated before it can be released.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the address is allocated.

us-east-2

allocationId

弦

Optional. The allocation ID of the VPC address to release.

eipalloc-0123456789abcdef0

publicIp

弦

Optional. Alternative to

allocationId

for EC2-Classic addresses.

203.0.113.25

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

No response body on success. See the

release_address boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Describe Elastic IP addresses

アクション識別子はaws.ec2.describeAddressesです。

Describes Elastic IP addresses and their current associations.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region to query.

us-east-2

publicIps

リスト

Optional. Restrict results to these public IP addresses.

["203.0.113.25"]

allocationIds

リスト

Optional. Restrict results to these allocation IDs.

["eipalloc-0123456789abcdef0"]

filters

リスト

Optional. AWS filters to apply to the query.

[{"Name": "domain", "Values": ["vpc"]}]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "addresses", "expression": ".response.Addresses"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

describe_addresses boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Create tags

アクション識別子はaws.ec2.createTagsです。

Adds or overwrites tags on any EC2 resource — instances, volumes, snapshots, security groups, AMIs, and so on. An existing tag with the same key is overwritten.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the resources are located.

us-east-2

resources

リスト

Required. IDs of the EC2 resources to tag.

["i-0123456789abcdef0"]

tags

リスト

Required. Tag key/value pairs to apply.

[{"Key": "Name", "Value": "app-server"}]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

No response body on success. See the

create_tags boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

タグを削除

アクション識別子はaws.ec2.deleteTagsです。

Removes tags from any EC2 resource. Omit the tags field to remove all tags from the specified resources.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the resources are located.

us-east-2

resources

リスト

Required. IDs of the EC2 resources to remove tags from.

["i-0123456789abcdef0"]

tags

リスト

Optional. Tags to remove. Omit

Value

to delete the key regardless of its value. Omit the field entirely to remove all tags.

[{"Key": "Name"}]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

No response body on success. See the

delete_tags boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Describe tags

アクション識別子はaws.ec2.describeTagsです。

Describes tags across any EC2 resource type, with optional filtering by resource ID, resource type, key, or value.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region to query.

us-east-2

filters

リスト

Optional. AWS filters applied to the query. Filter by

resource-id

,

resource-type

,

key

, or

value

.

[{"Name": "resource-id", "Values": ["i-0123456789abcdef0"]}]

nextToken

弦

オプション。以前のレスポンスからのページネーショントークン。

nextToken

maxResults

Int

Optional. Maximum number of tags to return per page.

10

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "tags", "expression": ".response.Tags"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

describe_tags boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Create a volume

アクション識別子はaws.ec2.createVolumeです。

Creates a new EBS volume in a given availability zone. A volume can only be attached to an instance in the same availability zone.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the volume is created.

us-east-2

availabilityZone

弦

Required. The availability zone in which to create the volume.

us-east-2a

size

Int

Optional. Volume size in GiB. Required if

snapshotId

is not supplied.

100

volumeType

弦

Optional. EBS volume type. Valid values:

gp2

,

gp3

,

io1

,

io2

,

st1

,

sc1

,

standard

. Default:

gp2

.

gp3

snapshotId

弦

Optional. Snapshot to restore the volume from.

snap-0123456789abcdef0

iops

Int

Optional. Provisioned IOPS. Only valid for

gp3

,

io1

, and

io2

volumes.

3000

throughput

Int

Optional. Throughput in MiB/s. Only valid for

gp3

volumes.

125

tagSpecifications

リスト

Optional. Tags applied to the volume at creation time.

[{"ResourceType": "volume", "Tags": [{"Key": "Name", "Value": "app-data"}]}]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "volumeId", "expression": ".response.VolumeId"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

create_volume boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Delete a volume

アクション識別子はaws.ec2.deleteVolumeです。

Deletes an EBS volume. The volume must be in the available state (fully detached) before it can be deleted.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the volume is located.

us-east-2

volumeId

弦

Required. The ID of the volume to delete.

vol-0123456789abcdef0

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

No response body on success. See the

delete_volume boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Attach a volume

アクション識別子はaws.ec2.attachVolumeです。

Attaches an EBS volume to a running or stopped EC2 instance. The volume and instance must be in the same availability zone.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the volume and instance are located.

us-east-2

volumeId

弦

Required. The ID of the volume to attach. Must be in the

available

state.

vol-0123456789abcdef0

instanceId

弦

Required. The instance to attach to. Must be

running

or

stopped

.

i-0123456789abcdef0

device

弦

Required. The device name the volume is exposed as on the instance.

/dev/sdf

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "attachmentState", "expression": ".response.State"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

attach_volume boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Detach a volume

アクション識別子はaws.ec2.detachVolumeです。

Detaches an EBS volume from an EC2 instance.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the volume is located.

us-east-2

volumeId

弦

Required. The ID of the volume to detach.

vol-0123456789abcdef0

instanceId

弦

Optional. Narrows the detach to a specific instance. Useful when the volume is multi-attached.

i-0123456789abcdef0

device

弦

Optional. Narrows the detach to a specific device name on the instance.

/dev/sdf

force

ブール値

Optional. Forces detachment without unmounting from the guest OS. Can cause data loss or filesystem corruption. Default:

false

.

false

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "detachmentState", "expression": ".response.State"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

detach_volume boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Modify a volume

アクション識別子はaws.ec2.modifyVolumeです。

Resizes an EBS volume or changes its volume type, IOPS, or throughput. EBS volumes can only be grown, never shrunk.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the volume is located.

us-east-2

volumeId

弦

Required. The ID of the volume to modify.

vol-0123456789abcdef0

size

Int

Optional. New size in GiB.

200

volumeType

弦

Optional. New volume type.

gp3

iops

Int

Optional. New provisioned IOPS. Only valid for

gp3

,

io1

, and

io2

volumes.

4000

throughput

Int

Optional. New throughput in MiB/s. Only valid for

gp3

volumes.

250

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "modificationState", "expression": ".response.VolumeModification.ModificationState"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

modify_volume boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Describe volumes

アクション識別子はaws.ec2.describeVolumesです。

Describes EBS volumes and their attachment state.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region to query.

us-east-2

volumeIds

リスト

Optional. Restrict results to specific volume IDs. Omit to describe all volumes in the region.

["vol-0123456789abcdef0"]

filters

リスト

Optional. Server-side filters, for example by

status

,

availability-zone

, or

volume-type

.

[{"Name": "status", "Values": ["available"]}]

nextToken

弦

オプション。以前のレスポンスからのページネーショントークン。

nextToken

maxResults

Int

Optional. Maximum number of volumes to return per page.

10

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "volumes", "expression": ".response.Volumes"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

describe_volumes boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Copy a snapshot

アクション識別子はaws.ec2.copySnapshotです。

Copies an EBS snapshot to another region for backup and disaster recovery. The region field specifies the destination region.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. The destination region the snapshot is copied into.

us-west-2

sourceSnapshotId

弦

Required. The ID of the snapshot to copy.

snap-0123456789abcdef0

sourceRegion

弦

Required. The region the source snapshot currently lives in.

us-east-1

description

弦

Optional. Description applied to the new snapshot.

Cross-region DR copy

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "snapshotId", "expression": ".response.SnapshotId"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

copy_snapshot boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Describe snapshots

アクション識別子はaws.ec2.describeSnapshotsです。

Describes EBS snapshots by owner, volume, or filter criteria.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region to query.

us-east-2

snapshotIds

リスト

Optional. Restrict results to specific snapshot IDs.

["snap-0123456789abcdef0"]

ownerIds

リスト

Optional. Filter by snapshot owner. Use

self

to return only snapshots owned by the calling account.

["self"]

filters

リスト

Optional. AWS filters, for example by volume, status, or tag.

[{"Name": "volume-id", "Values": ["vol-0123456789abcdef0"]}]

nextToken

弦

オプション。以前のレスポンスからのページネーショントークン。

nextToken

maxResults

Int

Optional. Maximum number of snapshots to return per page.

10

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "snapshots", "expression": ".response.Snapshots"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

describe_snapshots boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

画像を作成する

アクション識別子はaws.ec2.createImageです。

Creates an Amazon Machine Image (AMI) from a running or stopped EC2 instance.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the instance is located.

us-east-2

instanceId

弦

Required. The EC2 instance to capture the image from.

i-0123456789abcdef0

name

弦

Required. Name for the new AMI. Must be unique within the region.

my-server-ami-2026-09-21

description

弦

Optional. Free-form description for the AMI.

Nightly backup AMI

noReboot

ブール値

Optional. When

false

, AWS shuts down and reboots the instance to guarantee a filesystem-consistent image. Set

true

to skip the reboot at the cost of image consistency. Default:

false

.

false

tagSpecifications

リスト

Optional. Tags applied to the new AMI and its snapshots at creation time.

[{"ResourceType": "image", "Tags": [{"Key": "Name", "Value": "nightly-backup"}]}]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "imageId", "expression": ".response.ImageId"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

create_image boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Copy an image

アクション識別子はaws.ec2.copyImageです。

Copies an Amazon Machine Image (AMI) to another region for disaster recovery or multi-region deployments. The region field specifies the destination region.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. The destination region the copy is created in.

us-west-2

sourceImageId

弦

Required. The AMI to copy.

ami-0123456789abcdef0

sourceRegion

弦

Required. The region that currently holds the source AMI.

us-east-1

name

弦

Optional. Name for the new AMI in the destination region.

my-server-ami-copy

description

弦

Optional. Free-form description for the copied AMI.

Cross-region DR copy

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "imageId", "expression": ".response.ImageId"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

copy_image boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Deregister an image

アクション識別子はaws.ec2.deregisterImageです。

Deregisters an Amazon Machine Image (AMI) that you own. Deregistering an AMI does not delete its backing EBS snapshots — delete those separately to stop incurring storage costs.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the AMI is registered.

us-east-2

imageId

弦

Required. The AMI to deregister. Must be an AMI owned by the calling account.

ami-0123456789abcdef0

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

deregister_image boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Describe images

アクション識別子はaws.ec2.describeImagesです。

Describes Amazon Machine Images owned by, shared with, or public to your account.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region to query.

us-east-2

imageIds

リスト

Optional. Restrict results to specific AMI IDs.

["ami-0123456789abcdef0"]

owners

リスト

Optional. Scope results by owner. Accepts an AWS account ID,

self

,

amazon

, or

aws-marketplace

.

["self"]

filters

リスト

Optional. Server-side filters, for example by

name

,

state

, or

tag:<key>

.

[{"Name": "name", "Values": ["my-server-ami-*"]}]

nextToken

弦

オプション。以前のレスポンスからのページネーショントークン。

nextToken

maxResults

Int

Optional. Maximum number of AMIs to return per page.

10

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "images", "expression": ".response.Images"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

describe_images boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Describe instance status

アクション識別子はaws.ec2.describeInstanceStatusです。

Describes the status of one or more EC2 instances, including system and instance status checks and scheduled events.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region to query.

us-east-2

instanceIds

リスト

Optional. Instance IDs to check. If omitted, all instances are returned.

["i-0123456789abcdef0"]

includeAllInstances

ブール値

Optional. When

true

, includes instances in states other than running. Default:

false

.

false

filters

リスト

Optional. AWS filters to apply to the query.

[{"Name": "instance-status.status", "Values": ["impaired"]}]

nextToken

弦

オプション。以前のレスポンスからのページネーショントークン。

nextToken

maxResults

Int

Optional. Maximum number of results to return per page.

10

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "instanceStatuses", "expression": ".response.InstanceStatuses"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

describe_instance_status boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Describe instance types

アクション識別子はaws.ec2.describeInstanceTypesです。

Describes the specifications (vCPU, memory, network, storage) of EC2 instance types.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region to query.

us-east-2

instanceTypes

リスト

Optional. Specific instance types to describe.

["t3.micro", "m5.large"]

filters

リスト

Optional. AWS filters to apply to the query.

[{"Name": "instance-type", "Values": ["t3.*"]}]

nextToken

弦

オプション。以前のレスポンスからのページネーショントークン。

nextToken

maxResults

Int

Optional. Maximum number of results to return per page.

10

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "instanceTypes", "expression": ".response.InstanceTypes"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

describe_instance_types boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Modify an instance attribute

アクション識別子はaws.ec2.modifyInstanceAttributeです。

Modifies a single attribute of an EC2 instance such as instance type, termination protection, user data, or source/dest check.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the instance is located.

us-east-2

instanceId

弦

Required. The instance whose attribute is being modified.

i-0123456789abcdef0

parameters

地図

Required. The attribute to modify in the shape the AWS API expects. Only one attribute can be modified per call.

{"DisableApiTermination": {"Value": true}}

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

重要

Only one attribute can be modified per call. Each attribute has a different shape in the parameters map — for example, {"InstanceType": {"Value": "t3.large"}} to change the instance type, or {"DisableApiTermination": {"Value": true}} to enable termination protection. Most attributes require the instance to be stopped first.

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

No response body on success. See the

modify_instance_attribute boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Enable detailed monitoring

アクション識別子はaws.ec2.monitorInstancesです。

Enables detailed CloudWatch monitoring (1-minute metrics) for one or more EC2 instances.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

必須。インスタンスが配置されているAWSリージョン。

us-east-2

instanceIds

リスト

Required. IDs of the instances to enable detailed monitoring on.

["i-0123456789abcdef0"]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "instanceMonitorings", "expression": ".response.InstanceMonitorings"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

monitor_instances boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Disable detailed monitoring

アクション識別子はaws.ec2.unmonitorInstancesです。

Disables detailed CloudWatch monitoring for one or more EC2 instances, reverting to standard 5-minute metrics.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

必須。インスタンスが配置されているAWSリージョン。

us-east-2

instanceIds

リスト

Required. IDs of the instances to disable detailed monitoring on.

["i-0123456789abcdef0"]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "instanceMonitorings", "expression": ".response.InstanceMonitorings"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

unmonitor_instances boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Get console output

アクション識別子はaws.ec2.getConsoleOutputです。

Retrieves the console output of an EC2 instance for boot and troubleshooting diagnostics. The output is base64-encoded.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the instance is located.

us-east-2

instanceId

弦

Required. The instance to retrieve console output from.

i-0123456789abcdef0

latest

ブール値

Optional. When

true

, returns the latest output even if it is still being processed. Default:

false

.

true

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "output", "expression": ".response.Output"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

get_console_output boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Get Windows password data

アクション識別子はaws.ec2.getPasswordDataです。

Retrieves the encrypted administrator password for a Windows EC2 instance. Returns an empty PasswordData field for non-Windows instances.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the instance is located.

us-east-2

instanceId

弦

Required. The Windows instance to retrieve password data from.

i-0123456789abcdef0

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "passwordData", "expression": ".response.PasswordData"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

get_password_data boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Import a key pair

アクション識別子はaws.ec2.importKeyPairです。

Imports an existing public key into EC2 as a key pair. AWS stores only the public key — the private key never leaves your control.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the key pair is registered.

us-east-2

keyName

弦

Required. Unique name to register the imported key pair under.

my-imported-key

publicKeyMaterial

弦

Required. The public key to import. Pass as a secret.

${{ :secrets:opsPublicKeyMaterial }}

tagSpecifications

リスト

Optional. Tags applied to the key pair at import time.

[{"ResourceType": "key-pair", "Tags": [{"Key": "Name", "Value": "my-imported-key"}]}]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "keyPairId", "expression": ".response.KeyPairId"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

import_key_pair boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Delete a key pair

アクション識別子はaws.ec2.deleteKeyPairです。

Deletes an EC2 key pair. Supply either keyName or keyPairId.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the key pair exists.

us-east-2

keyName

弦

Optional. Name of the key pair to delete. Supply either

keyName

or

keyPairId

.

my-key-pair

keyPairId

弦

Optional. ID of the key pair to delete. Supply either

keyName

or

keyPairId

.

key-0123456789abcdef0

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

No response body on success. See the

delete_key_pair boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Describe key pairs

アクション識別子はaws.ec2.describeKeyPairsです。

Describes the EC2 key pairs in an account and region.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region to query.

us-east-2

keyNames

リスト

Optional. Restrict results to these key pair names.

["my-key-pair"]

keyPairIds

リスト

Optional. Restrict results to these key pair IDs.

["key-0123456789abcdef0"]

filters

リスト

Optional. AWS filters, for example by

key-name

or tag.

[{"Name": "key-name", "Values": ["my-key-*"]}]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "keyPairs", "expression": ".response.KeyPairs"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

describe_key_pairs boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Create a security group

アクション識別子はaws.ec2.createSecurityGroupです。

Creates a new EC2 security group in a VPC.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the security group is created.

us-east-2

groupName

弦

Required. Name for the new security group. Must be unique within the VPC.

web-servers-sg

description

弦

Required. Description for the security group.

Security group for web servers

vpcId

弦

Optional. VPC in which to create the group. Defaults to the region's default VPC.

vpc-0123456789abcdef0

tagSpecifications

リスト

Optional. Tags applied to the group at creation time.

[{"ResourceType": "security-group", "Tags": [{"Key": "Name", "Value": "web-servers-sg"}]}]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "groupId", "expression": ".response.GroupId"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

create_security_group boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Delete a security group

アクション識別子はaws.ec2.deleteSecurityGroupです。

Deletes an EC2 security group. Supply either groupId (preferred) or groupName.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the security group exists.

us-east-2

groupId

弦

Optional. The security group to delete. Works for any VPC. Preferred over

groupName

.

sg-0123456789abcdef0

groupName

弦

Optional. Alternative to

groupId

. Only valid for groups in the default VPC.

web-servers-sg

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

No response body on success. See the

delete_security_group boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Describe security groups

アクション識別子はaws.ec2.describeSecurityGroupsです。

Describes EC2 security groups and their inbound and outbound rules.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region to query.

us-east-2

groupIds

リスト

Optional. Restrict results to specific security group IDs.

["sg-0123456789abcdef0"]

groupNames

リスト

Optional. Restrict results by group name. Only valid for groups in the default VPC.

["web-servers-sg"]

filters

リスト

Optional. AWS filters, for example by

vpc-id

,

group-name

, or

tag:<key>

.

[{"Name": "vpc-id", "Values": ["vpc-0123456789abcdef0"]}]

nextToken

弦

オプション。以前のレスポンスからのページネーショントークン。

nextToken

maxResults

Int

Optional. Maximum number of groups to return per page.

10

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "securityGroups", "expression": ".response.SecurityGroups"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

See the

describe_security_groups boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Add an inbound rule

アクション識別子はaws.ec2.authorizeSecurityGroupIngressです。

Adds an inbound rule to an EC2 security group.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the security group exists.

us-east-2

groupId

弦

Required. The security group to add the inbound rule to.

sg-0123456789abcdef0

ipProtocol

弦

Optional. Flat form. Use with

fromPort

,

toPort

, and

cidrIp

for a single IPv4 rule.

tcp

fromPort

Int

Optional. Flat form. Start of the port range.

443

toPort

Int

Optional. Flat form. End of the port range.

443

cidrIp

弦

Optional. Flat form. Source CIDR block allowed by the rule.

0.0.0.0/0

ipPermissions

リスト

Optional. Structured form. Required for multiple rules in one call, rule descriptions, IPv6 ranges, prefix lists, or source security groups.

[{"IpProtocol": "tcp", "FromPort": 443, "ToPort": 443, "IpRanges": [{"CidrIp": "0.0.0.0/0", "Description": "HTTPS from anywhere"}]}]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

ヒント

This action supports two rule forms — pick one per call. The flat form (ipProtocol, fromPort, toPort, cidrIp) is a shorthand for a single IPv4 rule. Use ipPermissions for multiple rules, descriptions, IPv6 ranges, prefix lists, or source security groups.

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

No response body on success. See the

authorize_security_group_ingress boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Remove an inbound rule

アクション識別子はaws.ec2.revokeSecurityGroupIngressです。

Removes an inbound rule from an EC2 security group. The rule specification must exactly match an existing rule.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the security group exists.

us-east-2

groupId

弦

Required. The security group to remove the inbound rule from.

sg-0123456789abcdef0

ipProtocol

弦

Optional. Flat form. Use with

fromPort

,

toPort

, and

cidrIp

.

tcp

fromPort

Int

Optional. Flat form. Start of the port range.

443

toPort

Int

Optional. Flat form. End of the port range.

443

cidrIp

弦

Optional. Flat form. Source CIDR block of the rule being removed.

0.0.0.0/0

ipPermissions

リスト

Optional. Structured form. Required to revoke multiple rules in one call, or rules on IPv6 ranges, prefix lists, or source security groups.

[{"IpProtocol": "tcp", "FromPort": 443, "ToPort": 443, "IpRanges": [{"CidrIp": "0.0.0.0/0"}]}]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

No response body on success. See the

revoke_security_group_ingress boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Add an outbound rule

アクション識別子はaws.ec2.authorizeSecurityGroupEgressです。

Adds an outbound rule to an EC2 security group using the structured ipPermissions form.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the security group exists.

us-east-2

groupId

弦

Required. The security group to add the outbound rule to.

sg-0123456789abcdef0

ipPermissions

リスト

Required. The outbound rules to add in the structured form.

[{"IpProtocol": "tcp", "FromPort": 443, "ToPort": 443, "IpRanges": [{"CidrIp": "0.0.0.0/0"}]}]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

重要

Unlike the inbound rule actions, this action does not support the flat parameter form (cidrIp, ipProtocol, fromPort, toPort). The AWS AuthorizeSecurityGroupEgress API rejects those parameters outright. All outbound rules must use the structured ipPermissions list.

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

No response body on success. See the

authorize_security_group_egress boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Remove an outbound rule

アクション識別子はaws.ec2.revokeSecurityGroupEgressです。

Removes an outbound rule from an EC2 security group. The rule specification must exactly match an existing rule. A common use is removing the default allow-all egress rule that AWS attaches to every new security group.

次の表に、このアクションの入力フィールドについて説明します。

入力

タイプ

説明

例

awsRoleArn

弦

オプション。AWS APIコールのために引き受けるIAMロールARN。

arn:aws:iam::123456789012:role/my-workflow-role

awsAccessKeyId

弦

オプション。AWSアクセスキーID。シークレットとして渡します。

${{ :secrets:awsAccessKeyId }}

awsSecretAccessKey

弦

オプション。AWSシークレットアクセスキー。シークレットとして渡します。

${{ :secrets:awsSecretAccessKey }}

awsSessionToken

弦

オプション。STS認証用の一時的なセッショントークン。シークレットとして渡します。

${{ :secrets:awsSessionToken }}

region

弦

Required. AWS region where the security group exists.

us-east-2

groupId

弦

Required. The security group to remove the outbound rule from.

sg-0123456789abcdef0

ipPermissions

リスト

Required. The outbound rules to remove in the structured form. Must exactly match existing rules.

[{"IpProtocol": "-1", "IpRanges": [{"CidrIp": "0.0.0.0/0"}]}]

selectors

リスト

オプション。アクションの出力から特定のフィールドを抽出するためのJQセレクター。

[{"name": "response", "expression": ".response"}]

重要

Unlike the inbound rule actions, this action does not support the flat parameter form (cidrIp, ipProtocol, fromPort, toPort). All outbound rules must use the structured ipPermissions list.

次の表は、このアクションの出力フィールドについて説明しています。

出力

タイプ

例

response

オブジェクト

No response body on success. See the

revoke_security_group_egress boto3 reference

.

success

ブール値

true

または

false

errorMessage

弦

""

Copyright © 2026 New Relic株式会社。

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.