EC2 API actions
Objective
Section titled “Objective”Read this page to find out whether the call you want exists, before writing code against it.
An action listed here behaves as its Amazon EC2 counterpart behaves, unless this
documentation states a difference. An action not listed here returns
InvalidAction, and does so rather than silently doing something approximate.
Requirements
Section titled “Requirements”- Credentials with the relevant EC2 permissions
Instructions
Section titled “Instructions”Instances
Section titled “Instances”| Action | Purpose | Paginated | Idempotent |
|---|---|---|---|
RunInstances | Launch instances | No | Yes, via ClientToken |
DescribeInstances | List and inspect instances | Yes | Read |
TerminateInstances | Destroy instances | No | Naturally |
StartInstances | Start stopped instances | No | Naturally |
StopInstances | Stop running instances | No | Naturally |
RebootInstances | Restart in place | No | No |
DescribeInstanceStatus | Reachability and scheduled events | Yes | Read |
ModifyInstanceAttribute | Change a mutable attribute | No | Naturally |
DescribeInstanceAttribute | Read one attribute of an instance | No | Read |
DescribeInstanceTypes | List instance types and their shapes | Yes | Read |
DryRun
Section titled “DryRun”Every action above accepts a DryRun boolean. When set, permissions are
evaluated and nothing is done:
- the identity is permitted →
DryRunOperation - the identity is not permitted →
UnauthorizedOperation
This is how a policy is tested before running a destructive command, and it is what the policy actions guide means by trying a call that should fail.
Images
Section titled “Images”| Action | Purpose | Paginated |
|---|---|---|
DescribeImages | List images | Yes |
DescribeImageAttribute | Read one attribute of an image | No |
OPEN (Michael): whether CreateImage, RegisterImage, CopyImage and
DeregisterImage exist in v1. They are the difference between customers using
our images and customers building their own.
Key pairs
Section titled “Key pairs”| Action | Purpose | Notes |
|---|---|---|
CreateKeyPair | Generate a pair; returns the private key once | Not idempotent |
ImportKeyPair | Register a public key you already hold | Not idempotent |
DescribeKeyPairs | List names and fingerprints | Never returns secrets |
DeleteKeyPair | Remove our copy of a public key | Naturally idempotent |
Volumes
Section titled “Volumes”| Action | Purpose | Paginated |
|---|---|---|
CreateVolume | Create a volume | No |
DescribeVolumes | List volumes | Yes |
AttachVolume | Attach a volume to an instance | No |
DetachVolume | Detach a volume | No |
DeleteVolume | Destroy a volume and its data | No |
ModifyVolume | Change a volume’s size | No |
DescribeVolumeStatus | Volume health | Yes |
Snapshots
Section titled “Snapshots”| Action | Purpose | Paginated |
|---|---|---|
CreateSnapshot | Point-in-time copy of a volume | No |
DescribeSnapshots | List snapshots | Yes |
DeleteSnapshot | Destroy a snapshot | No |
| Action | Purpose |
|---|---|
CreateTags | Set tags on resources |
DeleteTags | Remove tags |
DescribeTags | List tags across resources |
CreateTags sets tags to the values given. Repeating it with the same values
changes nothing, which is why it needs no client token.
Regions and zones
Section titled “Regions and zones”| Action | Purpose | Paginated |
|---|---|---|
DescribeRegions | List regions | No |
DescribeAvailabilityZones | List zones in a region | No |
DescribeAccountAttributes | Account-level attributes | No |
These three are deliberately unpaginated, because their Amazon EC2 models are unpaginated. Returning a token here would be discarded by every SDK, and the caller would silently receive a truncated list — the worst possible failure, because it looks like success.
Networking
Section titled “Networking”EC2-Classic is disabled in the deployment (disable_ec2_classic = True), so
every project gets a default VPC on first use and its security groups,
instances and addresses are VPC ones. Full detail:
Networking.
| Action | Purpose |
|---|---|
CreateSecurityGroup | Create a security group |
DescribeSecurityGroups | List security groups |
AuthorizeSecurityGroupIngress | Add an ingress rule |
AuthorizeSecurityGroupEgress | Add an egress rule |
RevokeSecurityGroupIngress | Remove an ingress rule |
RevokeSecurityGroupEgress | Remove an egress rule |
DeleteSecurityGroup | Delete a security group |
DescribeAddresses | List addresses |
OPEN (Michael): whether AllocateAddress and AssociateAddress are
offered, which depends on how many public addresses the box has to give out.
[!primary]
Each customer project gets its own network, subnet (
10.200.0.0/24) and router at onboarding, so another customer cannot reach your instances by private address. Inside your own project everything is on one flat subnet; security groups are the only tool for separating your own tiers.
Not implemented in v1
Section titled “Not implemented in v1”Named so that their absence is deliberate:
Spot instances, reserved instances, capacity reservations, placement groups,
dedicated hosts, launch templates, fleets, Elastic Network Interfaces as
first-class resources, customer-managed VPCs and subnets (a default VPC exists;
managing your own does not), route tables, internet gateways, NAT gateways, VPN
connections, transit gateways, VPC peering, network ACLs, IPv6, load balancers,
instance metadata options, hibernation, instance recovery, EBS multi-attach,
fast snapshot restore, DescribeVolumesModifications, GetConsoleOutput,
GetConsoleScreenshot, the EBS direct APIs, and every GPU or accelerator
attribute.
There is also no object storage service of any kind on this platform — no Swift, no S3-compatible endpoint.
Calling any of these returns InvalidAction.