aws.lambda.add_permission ​
Call AWS Lambda AddPermission using a CloudConnection UUID.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | Base-aws |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | Authenticated organization UUID used for field resolution and connection scoping. |
connection_uuid | uuid | Yes | — | AWS CloudConnection UUID for the target IAM account, scoped to the caller organization. |
workflow_run_id | string | No | — | Engine DAG run ID stamped onto child steps. |
region | string | No | — | AWS API endpoint region override; omit to use the connection or SDK default. |
function_name | string | Yes | — | The name or ARN of the Lambda function, version, or alias. Name formats Function name – my-function (name-only), my-function:v1 (with alias). Function ARN – arn:aws:lambda:us-west-2:123456789012:fu... |
statement_id | string | Yes | — | A statement identifier that differentiates the statement from others in the same policy. |
action | string | Yes | — | The action that the principal can use on the function. For example, lambda:InvokeFunction or lambda:GetFunction. |
principal | string | Yes | — | The Amazon Web Services service, Amazon Web Services account, IAM user, or IAM role that invokes the function. If you specify a service, use SourceArn or SourceAccount to limit who can invoke the f... |
source_arn | string | No | — | For Amazon Web Services services, the ARN of the Amazon Web Services resource that invokes the function. For example, an Amazon S3 bucket or Amazon SNS topic. Note that Lambda configures the compar... |
source_account | string | No | — | For Amazon Web Services service, the ID of the Amazon Web Services account that owns the resource. Use this together with SourceArn to ensure that the specified account owns the resource. It is pos... |
event_source_token | string | No | — | For Alexa Smart Home functions, a token that the invoker must supply. |
qualifier | string | No | — | Specify a version or alias to add permissions to a published version of the function. |
revision_id | string | No | — | Update the policy only if the revision ID matches the ID that's specified. Use this option to avoid modifying a policy that has changed since you last read it. |
principal_org_id | string | No | — | The identifier for your organization in Organizations. Use this to grant permissions to all the Amazon Web Services accounts under this organization. |
function_url_auth_type | string | No | — | The type of authentication that your function URL uses. Set to AWS_IAM if you want to restrict access to authenticated users only. Set to NONE if you want to bypass IAM authentication to create a p... |
invoked_via_function_url | boolean | No | — | Indicates whether the permission applies when the function is invoked through a function URL. |
provider_native_request | json | No | — | Optional provider-native request overrides for AWS parameters not yet promoted to first-class fields. |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | No | — | Organization UUID echoed from input. |
connection_uuid | uuid | No | — | AWS CloudConnection UUID echoed from input. |
region | string | No | — | AWS API endpoint region used. |
service | string | No | — | AWS boto3 service/client name. |
operation | string | No | — | AWS API operation invoked. |
request_id | string | No | — | AWS request ID when available. |
response | json | No | — | Sanitized provider response object. |
items | list | No | — | Primary response item list when the API returns a collection. |
result_count | integer | No | — | Count of primary response items. |
next_page_token | string | No | — | Pagination token for the next page. |
failure_reason | string | No | — | Human-readable failure reason. |
failed_step | string | No | — | Failed logical step. |
failed_layer | json | No | — | Failed DAG layer if engine supplies one. |
failed_at_state | string | No | — | State where failure occurred. |
error | string | No | — | Error message. |
error_type | string | No | — | Error class. |
failed_at | string | No | — | ISO failure timestamp. |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "aws.lambda.add_permission",
"initial_data": {
"organization_uuid": "value",
"connection_uuid": "value",
"function_name": "value",
"statement_id": "value"
}
}