Skip to content
Proud to collaborate with Microsoft for Startups

runner.ensure_iam_instance_profile ​

Idempotently ensure an IAM role, its managed-policy attachments, and an instance profile (with the role added) exist for runner EC2 instances.

Idempotently ensure an IAM role + instance profile exist via base atomics.

Overview ​

PropertyValue
Workflow typeLinear
LibraryApp-runners-aws
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidYes—UUID of the CloudConnection used to run the underlying aws.iam.* primitives, picked from the organization's AWS connections.
role_namestringYes——
profile_namestringYes——
assume_role_policyjsonYes——
managed_policy_arnslistNo——
role_descriptionstringNo——
tagsjsonNo——
organization_uuiduuidNo—UUID of the caller's organization, injected server-side from the authenticated request; scopes the operation to the correct tenant.
regionstringNo——
workflow_run_idstringNo——
workflow_run_uuidstringNo—Legacy alias of workflow_run_id for DAG-step correlation; engine-generated, not a user-facing picker.

Output Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidNo—UUID of the CloudConnection used to run the underlying aws.iam.* primitives, echoed back from the input on output. Optional here because this is an output-only echo.
profile_arnstringNo——
profile_namestringNo——
role_arnstringNo——
role_namestringNo——
attached_policy_arnsjsonNo——
completed_atstringNo——
failed_atstringNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_layerstringNo——
failed_stepstringNo——
errorstringNo——
error_typestringNo——
reasonstringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
ensuringNoNo—complete—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecuteensuring—
ensuringcompletecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "runner.ensure_iam_instance_profile",
  "initial_data": {
    "connection_uuid": "value",
    "role_name": "value",
    "profile_name": "value",
    "assume_role_policy": "value"
  }
}