Skip to content
Proud to collaborate with Microsoft for Startups

aws.iam.ensure_instance_profile ​

Create or validate an IAM role and matching instance profile

Idempotently provisions an IAM role + instance profile suitable for binding to EC2 instances (e.g. ECS container instances).

Inputs:

  • connection_uuid: Cloud connection UUID for AWS credentials (required)
  • role_name: IAM role name (required)
  • profile_name: Instance profile name. Defaults to role_name (optional)
  • assume_role_policy: Trust policy document as dict. Defaults to EC2 service trust (optional)
  • managed_policy_arns: List of managed policy ARNs to attach to the role (optional)
  • role_description: Human-readable description (optional)
  • tags: Dict of tags applied to role + profile (optional)

Outputs:

  • role_name
  • role_arn
  • profile_name
  • profile_arn
  • existed: bool — true if both role and profile already existed

Overview ​

PropertyValue
Workflow typeAtomic
LibraryBase-aws
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidYes—Cloud connection UUID
role_namestringYes—IAM role name
profile_namestringNo—Instance profile name (defaults to role_name)
assume_role_policyjsonNo—Trust policy document
managed_policy_arnsjsonNo—List of managed policy ARNs to attach
role_descriptionstringNo—Human-readable role description
tagsjsonNo—Tags applied to role + profile

Output Schema ​

FieldTypeRequiredDefaultDescription
existedbooleanNo——
profile_arnstringNo——
profile_namestringNo——
role_arnstringNo——
role_namestringNo——
assume_role_policyjsonNo——
connection_uuiduuidNo——
managed_policy_arnsjsonNo——
role_descriptionstringNo——
tagsjsonNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
failed_layerstringNo——
errorstringNo——
error_typestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "aws.iam.ensure_instance_profile",
  "initial_data": {
    "connection_uuid": "value",
    "role_name": "value"
  }
}