Skip to content
Proud to collaborate with Microsoft for Startups

aws.s3.put_bucket_policy ​

Call AWS S3 PutBucketPolicy using a CloudConnection UUID.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryBase-aws
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Authenticated organization UUID used for field resolution and connection scoping.
connection_uuiduuidYes—AWS CloudConnection UUID for the target S3 account, scoped to the caller organization.
workflow_run_idstringNo—Engine DAG run ID stamped onto child steps.
regionstringNo—AWS API endpoint region override; omit to use the connection or SDK default.
bucketstringYes—The name of the bucket. Directory buckets - When you use this operation with a directory bucket, you must use path-style requests in the format https://s3express-control.region-code.amazonaws.com/b...
content_md5stringNo—The MD5 hash of the request body. For requests made using the Amazon Web Services Command Line Interface (CLI) or Amazon Web Services SDKs, this field is calculated automatically. This functionalit...
checksum_algorithmstringNo—Indicates the algorithm used to create the checksum for the request when you use the SDK. This header will not provide any additional functionality if you don't use the SDK. When you send this head...
confirm_remove_self_bucket_accessbooleanNo—Set this parameter to true to confirm that you want to remove your permissions to change this bucket policy in the future. This functionality is not supported for directory buckets.
policystringYes—The bucket policy as a JSON document. For directory buckets, the only IAM action supported in the bucket policy is s3express:CreateSession.
expected_bucket_ownerstringNo—The account ID of the expected bucket owner. If the account ID that you provide does not match the actual owner of the bucket, the request fails with the HTTP status code 403 Forbidden (access deni...
provider_native_requestjsonNo—Optional provider-native request overrides for AWS parameters not yet promoted to first-class fields.

Output Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidNo—Organization UUID echoed from input.
connection_uuiduuidNo—AWS CloudConnection UUID echoed from input.
regionstringNo—AWS API endpoint region used.
servicestringNo—AWS boto3 service/client name.
operationstringNo—AWS API operation invoked.
request_idstringNo—AWS request ID when available.
responsejsonNo—Sanitized provider response object.
itemslistNo—Primary response item list when the API returns a collection.
result_countintegerNo—Count of primary response items.
next_page_tokenstringNo—Pagination token for the next page.
failure_reasonstringNo—Human-readable failure reason.
failed_stepstringNo—Failed logical step.
failed_layerjsonNo—Failed DAG layer if engine supplies one.
failed_at_statestringNo—State where failure occurred.
errorstringNo—Error message.
error_typestringNo—Error class.
failed_atstringNo—ISO failure timestamp.

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "aws.s3.put_bucket_policy",
  "initial_data": {
    "organization_uuid": "value",
    "connection_uuid": "value",
    "bucket": "value",
    "policy": "value"
  }
}