Skip to content
Proud to collaborate with Microsoft for Startups

aws.vpc.revoke_security_group_ingress ​

Call AWS EC2 RevokeSecurityGroupIngress using a CloudConnection UUID.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryBase-aws
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Authenticated organization UUID used for field resolution and connection scoping.
connection_uuiduuidYes—AWS CloudConnection UUID for the target VPC account, scoped to the caller organization.
workflow_run_idstringNo—Engine DAG run ID stamped onto child steps.
regionstringNo—AWS API endpoint region override; omit to use the connection or SDK default.
cidr_ipstringNo—The CIDR IP address range. You can't specify this parameter when specifying a source security group.
from_portintegerNo—If the protocol is TCP or UDP, this is the start of the port range. If the protocol is ICMP, this is the ICMP type or -1 (all ICMP types).
group_idstringNo—The ID of the security group.
group_namestringNo—[Default VPC] The name of the security group. You must specify either the security group ID or the security group name in the request. For security groups in a nondefault VPC, you must specify the...
ip_permissionslistNo—The sets of IP permissions. You can't specify a source security group and a CIDR IP address range in the same set of permissions.
ip_protocolstringNo—The IP protocol name (tcp, udp, icmp) or number (see Protocol Numbers). Use -1 to specify all.
source_security_group_namestringNo—[Default VPC] The name of the source security group. You can't specify this parameter in combination with the following parameters: the CIDR IP address range, the start of the port range, the IP pr...
source_security_group_owner_idstringNo—Not supported.
to_portintegerNo—If the protocol is TCP or UDP, this is the end of the port range. If the protocol is ICMP, this is the ICMP code or -1 (all ICMP codes).
security_group_rule_idslistNo—The IDs of the security group rules.
dry_runbooleanNo—Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is Dry...
provider_native_requestjsonNo—Optional provider-native request overrides for AWS parameters not yet promoted to first-class fields.

Output Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidNo—Organization UUID echoed from input.
connection_uuiduuidNo—AWS CloudConnection UUID echoed from input.
regionstringNo—AWS API endpoint region used.
servicestringNo—AWS boto3 service/client name.
operationstringNo—AWS API operation invoked.
request_idstringNo—AWS request ID when available.
responsejsonNo—Sanitized provider response object.
itemslistNo—Primary response item list when the API returns a collection.
result_countintegerNo—Count of primary response items.
next_page_tokenstringNo—Pagination token for the next page.
failure_reasonstringNo—Human-readable failure reason.
failed_stepstringNo—Failed logical step.
failed_layerjsonNo—Failed DAG layer if engine supplies one.
failed_at_statestringNo—State where failure occurred.
errorstringNo—Error message.
error_typestringNo—Error class.
failed_atstringNo—ISO failure timestamp.

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "aws.vpc.revoke_security_group_ingress",
  "initial_data": {
    "organization_uuid": "value",
    "connection_uuid": "value"
  }
}