Skip to content
Proud to collaborate with Microsoft for Startups

aws.acm.request_certificate ​

Call AWS ACM RequestCertificate using a CloudConnection UUID.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryBase-aws
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Authenticated organization UUID used for field resolution and connection scoping.
connection_uuiduuidYes—AWS CloudConnection UUID for the target ACM account, scoped to the caller organization.
workflow_run_idstringNo—Engine DAG run ID stamped onto child steps.
regionstringNo—AWS API endpoint region override; omit to use the connection or SDK default.
domain_namestringYes—Fully qualified domain name (FQDN), such as www.example.com, that you want to secure with an ACM certificate. Use an asterisk (*) to create a wildcard certificate that protects several sites in the...
validation_methodstringNo—The method you want to use if you are requesting a public certificate to validate that you own or control domain. You can validate with DNS or validate with email. We recommend that you use DNS val...
subject_alternative_nameslistNo—Additional FQDNs to be included in the Subject Alternative Name extension of the ACM certificate. For example, add the name www.example.net to a certificate for which the DomainName field is www.ex...
idempotency_tokenstringNo—Customer chosen string that can be used to distinguish between calls to RequestCertificate. Idempotency tokens time out after one hour. Therefore, if you call RequestCertificate multiple times with...
domain_validation_optionslistNo—The domain name that you want ACM to use to send you emails so that you can validate domain ownership.
optionsjsonNo—You can use this parameter to specify whether to add the certificate to a certificate transparency log and export your certificate. Certificate transparency makes it possible to detect SSL/TLS cert...
certificate_authority_arnstringNo—The Amazon Resource Name (ARN) of the private certificate authority (CA) that will be used to issue the certificate. If you do not provide an ARN and you are trying to request a private certificate...
tagslistNo—One or more resource tags to associate with the certificate.
key_algorithmstringNo—Specifies the algorithm of the public and private key pair that your certificate uses to encrypt data. RSA is the default key algorithm for ACM certificates. Elliptic Curve Digital Signature Algori...
managed_bystringNo—Identifies the Amazon Web Services service that manages the certificate issued by ACM.
provider_native_requestjsonNo—Optional provider-native request overrides for AWS parameters not yet promoted to first-class fields.

Output Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidNo—Organization UUID echoed from input.
connection_uuiduuidNo—AWS CloudConnection UUID echoed from input.
regionstringNo—AWS API endpoint region used.
servicestringNo—AWS boto3 service/client name.
operationstringNo—AWS API operation invoked.
request_idstringNo—AWS request ID when available.
responsejsonNo—Sanitized provider response object.
itemslistNo—Primary response item list when the API returns a collection.
result_countintegerNo—Count of primary response items.
next_page_tokenstringNo—Pagination token for the next page.
failure_reasonstringNo—Human-readable failure reason.
failed_stepstringNo—Failed logical step.
failed_layerjsonNo—Failed DAG layer if engine supplies one.
failed_at_statestringNo—State where failure occurred.
errorstringNo—Error message.
error_typestringNo—Error class.
failed_atstringNo—ISO failure timestamp.

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "aws.acm.request_certificate",
  "initial_data": {
    "organization_uuid": "value",
    "connection_uuid": "value",
    "domain_name": "value"
  }
}