Skip to content

EC2 API actions

Read this page to find out whether the call you want exists, before writing code against it.

An action listed here behaves as its Amazon EC2 counterpart behaves, unless this documentation states a difference. An action not listed here returns InvalidAction, and does so rather than silently doing something approximate.

  • Credentials with the relevant EC2 permissions
ActionPurposePaginatedIdempotent
RunInstancesLaunch instancesNoYes, via ClientToken
DescribeInstancesList and inspect instancesYesRead
TerminateInstancesDestroy instancesNoNaturally
StartInstancesStart stopped instancesNoNaturally
StopInstancesStop running instancesNoNaturally
RebootInstancesRestart in placeNoNo
DescribeInstanceStatusReachability and scheduled eventsYesRead
ModifyInstanceAttributeChange a mutable attributeNoNaturally
DescribeInstanceAttributeRead one attribute of an instanceNoRead
DescribeInstanceTypesList instance types and their shapesYesRead

Every action above accepts a DryRun boolean. When set, permissions are evaluated and nothing is done:

  • the identity is permitted → DryRunOperation
  • the identity is not permitted → UnauthorizedOperation

This is how a policy is tested before running a destructive command, and it is what the policy actions guide means by trying a call that should fail.

ActionPurposePaginated
DescribeImagesList imagesYes
DescribeImageAttributeRead one attribute of an imageNo

OPEN (Michael): whether CreateImage, RegisterImage, CopyImage and DeregisterImage exist in v1. They are the difference between customers using our images and customers building their own.

ActionPurposeNotes
CreateKeyPairGenerate a pair; returns the private key onceNot idempotent
ImportKeyPairRegister a public key you already holdNot idempotent
DescribeKeyPairsList names and fingerprintsNever returns secrets
DeleteKeyPairRemove our copy of a public keyNaturally idempotent
ActionPurposePaginated
CreateVolumeCreate a volumeNo
DescribeVolumesList volumesYes
AttachVolumeAttach a volume to an instanceNo
DetachVolumeDetach a volumeNo
DeleteVolumeDestroy a volume and its dataNo
ModifyVolumeChange a volume’s sizeNo
DescribeVolumeStatusVolume healthYes
ActionPurposePaginated
CreateSnapshotPoint-in-time copy of a volumeNo
DescribeSnapshotsList snapshotsYes
DeleteSnapshotDestroy a snapshotNo
ActionPurpose
CreateTagsSet tags on resources
DeleteTagsRemove tags
DescribeTagsList tags across resources

CreateTags sets tags to the values given. Repeating it with the same values changes nothing, which is why it needs no client token.

ActionPurposePaginated
DescribeRegionsList regionsNo
DescribeAvailabilityZonesList zones in a regionNo
DescribeAccountAttributesAccount-level attributesNo

These three are deliberately unpaginated, because their Amazon EC2 models are unpaginated. Returning a token here would be discarded by every SDK, and the caller would silently receive a truncated list — the worst possible failure, because it looks like success.

EC2-Classic is disabled in the deployment (disable_ec2_classic = True), so every project gets a default VPC on first use and its security groups, instances and addresses are VPC ones. Full detail: Networking.

ActionPurpose
CreateSecurityGroupCreate a security group
DescribeSecurityGroupsList security groups
AuthorizeSecurityGroupIngressAdd an ingress rule
AuthorizeSecurityGroupEgressAdd an egress rule
RevokeSecurityGroupIngressRemove an ingress rule
RevokeSecurityGroupEgressRemove an egress rule
DeleteSecurityGroupDelete a security group
DescribeAddressesList addresses

OPEN (Michael): whether AllocateAddress and AssociateAddress are offered, which depends on how many public addresses the box has to give out.

[!primary]

Each customer project gets its own network, subnet (10.200.0.0/24) and router at onboarding, so another customer cannot reach your instances by private address. Inside your own project everything is on one flat subnet; security groups are the only tool for separating your own tiers.

Named so that their absence is deliberate:

Spot instances, reserved instances, capacity reservations, placement groups, dedicated hosts, launch templates, fleets, Elastic Network Interfaces as first-class resources, customer-managed VPCs and subnets (a default VPC exists; managing your own does not), route tables, internet gateways, NAT gateways, VPN connections, transit gateways, VPC peering, network ACLs, IPv6, load balancers, instance metadata options, hibernation, instance recovery, EBS multi-attach, fast snapshot restore, DescribeVolumesModifications, GetConsoleOutput, GetConsoleScreenshot, the EBS direct APIs, and every GPU or accelerator attribute.

There is also no object storage service of any kind on this platform — no Swift, no S3-compatible endpoint.

Calling any of these returns InvalidAction.