aws.sso_admin.create_permission_set ​
Call AWS SSO Admin CreatePermissionSet using a CloudConnection UUID.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | Base-aws |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | Authenticated organization UUID used for field resolution and connection scoping. |
connection_uuid | uuid | Yes | — | AWS CloudConnection UUID for the target IAM account, scoped to the caller organization. |
workflow_run_id | string | No | — | Engine DAG run ID stamped onto child steps. |
region | string | No | — | AWS API endpoint region override; omit to use the connection or SDK default. |
name | string | Yes | — | The name of the PermissionSet. |
description | string | No | — | The description of the PermissionSet. |
instance_arn | string | Yes | — | The ARN of the IAM Identity Center instance under which the operation will be executed. For more information about ARNs, see Amazon Resource Names (ARNs) and Amazon Web Services Service Namespaces... |
session_duration | string | No | — | The length of time that the application user sessions are valid in the ISO-8601 standard. |
relay_state | string | No | — | Used to redirect users within the application during the federation authentication process. |
tags | list | No | — | The tags to attach to the new PermissionSet. |
provider_native_request | json | No | — | Optional provider-native request overrides for AWS parameters not yet promoted to first-class fields. |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | No | — | Organization UUID echoed from input. |
connection_uuid | uuid | No | — | AWS CloudConnection UUID echoed from input. |
region | string | No | — | AWS API endpoint region used. |
service | string | No | — | AWS boto3 service/client name. |
operation | string | No | — | AWS API operation invoked. |
request_id | string | No | — | AWS request ID when available. |
response | json | No | — | Sanitized provider response object. |
items | list | No | — | Primary response item list when the API returns a collection. |
result_count | integer | No | — | Count of primary response items. |
next_page_token | string | No | — | Pagination token for the next page. |
failure_reason | string | No | — | Human-readable failure reason. |
failed_step | string | No | — | Failed logical step. |
failed_layer | json | No | — | Failed DAG layer if engine supplies one. |
failed_at_state | string | No | — | State where failure occurred. |
error | string | No | — | Error message. |
error_type | string | No | — | Error class. |
failed_at | string | No | — | ISO failure timestamp. |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "aws.sso_admin.create_permission_set",
"initial_data": {
"organization_uuid": "value",
"connection_uuid": "value",
"name": "value",
"instance_arn": "value"
}
}