aws.ssm.send_command ​
Call AWS SSM SendCommand using a CloudConnection UUID.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | Base-aws |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | Authenticated organization UUID used for field resolution and connection scoping. |
connection_uuid | uuid | Yes | — | AWS CloudConnection UUID for the target SSM account, scoped to the caller organization. |
workflow_run_id | string | No | — | Engine DAG run ID stamped onto child steps. |
region | string | No | — | AWS API endpoint region override; omit to use the connection or SDK default. |
instance_ids | list | No | — | The IDs of the managed nodes where the command should run. Specifying managed node IDs is most useful when you are targeting a limited number of managed nodes, though you can specify up to 50 IDs.... |
targets | list | No | — | An array of search criteria that targets managed nodes using a Key,Value combination that you specify. Specifying targets is most useful when you want to send a command to a large number of managed... |
document_name | string | Yes | — | The name of the Amazon Web Services Systems Manager document (SSM document) to run. This can be a public document or a custom document. To run a shared document belonging to another account, specif... |
document_version | string | No | — | The SSM document version to use in the request. You can specify $DEFAULT, $LATEST, or a specific version number. If you run commands by using the Command Line Interface (Amazon Web Services CLI), t... |
document_hash | string | No | — | The Sha256 or Sha1 hash created by the system when the document was created. Sha1 hashes have been deprecated. |
document_hash_type | string | No | — | Sha256 or Sha1. Sha1 hashes have been deprecated. |
timeout_seconds | integer | No | — | If this time is reached and the command hasn't already started running, it won't run. |
comment | string | No | — | User-specified information about the command, such as a brief description of what the command should do. |
parameters | json | No | — | The required and optional parameters specified in the document being run. |
output_s3_region | string | No | — | (Deprecated) You can no longer specify this parameter. The system ignores it. Instead, Systems Manager automatically determines the Amazon Web Services Region of the S3 bucket. |
output_s3_bucket_name | string | No | — | The name of the S3 bucket where command execution responses should be stored. |
output_s3_key_prefix | string | No | — | The directory structure within the S3 bucket where the responses should be stored. |
max_concurrency | string | No | — | (Optional) The maximum number of managed nodes that are allowed to run the command at the same time. You can specify a number such as 10 or a percentage such as 10%. The default value is 50. For mo... |
max_errors | string | No | — | The maximum number of errors allowed without the command failing. When the command fails one more time beyond the value of MaxErrors, the systems stops sending the command to additional targets. Yo... |
service_role_arn | string | No | — | The ARN of the Identity and Access Management (IAM) service role to use to publish Amazon Simple Notification Service (Amazon SNS) notifications for Run Command commands. This role must provide the... |
notification_config | json | No | — | Configurations for sending notifications. |
cloud_watch_output_config | json | No | — | Enables Amazon Web Services Systems Manager to send Run Command output to Amazon CloudWatch Logs. Run Command is a tool in Amazon Web Services Systems Manager. |
alarm_configuration | json | No | — | The CloudWatch alarm you want to apply to your command. |
provider_native_request | json | No | — | Optional provider-native request overrides for AWS parameters not yet promoted to first-class fields. |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | No | — | Organization UUID echoed from input. |
connection_uuid | uuid | No | — | AWS CloudConnection UUID echoed from input. |
region | string | No | — | AWS API endpoint region used. |
service | string | No | — | AWS boto3 service/client name. |
operation | string | No | — | AWS API operation invoked. |
request_id | string | No | — | AWS request ID when available. |
response | json | No | — | Sanitized provider response object. |
items | list | No | — | Primary response item list when the API returns a collection. |
result_count | integer | No | — | Count of primary response items. |
next_page_token | string | No | — | Pagination token for the next page. |
failure_reason | string | No | — | Human-readable failure reason. |
failed_step | string | No | — | Failed logical step. |
failed_layer | json | No | — | Failed DAG layer if engine supplies one. |
failed_at_state | string | No | — | State where failure occurred. |
error | string | No | — | Error message. |
error_type | string | No | — | Error class. |
failed_at | string | No | — | ISO failure timestamp. |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "aws.ssm.send_command",
"initial_data": {
"organization_uuid": "value",
"connection_uuid": "value",
"document_name": "value"
}
}