TerminateInstances
Objective
Section titled “Objective”TerminateInstances destroys instances and their root volumes. It cannot be
undone.
Requirements
Section titled “Requirements”- Credentials configured
Permissions
Section titled “Permissions”| Action | Resource scope | ARN shape |
|---|---|---|
ec2:TerminateInstances | Resource-scoped | arn:aws-shelf:ec2:<region>:<account>:instance/<id> |
A policy may name specific instances, or use a wildcard. A policy granting
ec2:TerminateInstances on "Resource": "*" permits terminating everything in
the account.
Instructions
Section titled “Instructions”Request parameters
Section titled “Request parameters”| Parameter | Type | Required | Notes |
|---|---|---|---|
InstanceId.N | list | Yes | One or more instance ids |
DryRun | boolean | No | Check permissions without acting |
What is destroyed
Section titled “What is destroyed”- The instance
- Its root volume, and everything written to it
- Its public address
What survives
Section titled “What survives”- Volumes attached separately, which are detached and kept
- Snapshots
- Key pairs
[!warning]
There is no recovery. We hold no copy of the root volume, support cannot restore one, and there is no console through which to rescue anything.
Behaviour
Section titled “Behaviour”The call returns immediately with each instance in shutting-down. Destruction
completes shortly afterwards and the state becomes terminated.
Terminating an already-terminated instance succeeds and reports its current
state. Terminating an instance that has never existed returns
InvalidInstanceID.NotFound.
That distinction is load-bearing: infrastructure tooling polls for a not-found error to confirm a destroy completed, and treats not-found during a refresh as “deleted out of band”. A server that reported success for resources it had never heard of would leave that tooling unable to tell “destroyed” from “never existed”.
Response
Section titled “Response”| Element | Notes |
|---|---|
requestId | |
instancesSet | One entry per instance |
instancesSet.N.instanceId | |
instancesSet.N.previousState | The state before this call |
instancesSet.N.currentState | Usually shutting-down |
previousState is how a caller distinguishes “I terminated this” from “it was
already gone”: a previousState of terminated means the instance was already
destroyed before this call.
<TerminateInstancesResponse xmlns="http://ec2.amazonaws.com/doc/2016-11-15/"> <requestId>b1e2c3d4-5678-90ab-cdef-1234567890ab</requestId> <instancesSet> <item> <instanceId>i-0a1b2c3d4e5f60718</instanceId> <currentState><code>32</code><name>shutting-down</name></currentState> <previousState><code>16</code><name>running</name></previousState> </item> </instancesSet></TerminateInstancesResponse>Partial failure
Section titled “Partial failure”If any id in the list is invalid, the whole call fails with
InvalidInstanceID.NotFound and nothing is terminated. Validate first, or
terminate one at a time when the list is assembled programmatically.
Errors
Section titled “Errors”| Code | Status | Cause |
|---|---|---|
InvalidInstanceID.NotFound | 400 | An instance does not exist |
InvalidInstanceID.Malformed | 400 | An id is not well-formed |
UnauthorizedOperation | 403 | Policy denies termination |
DryRunOperation | 400 | DryRun was set and the call would have succeeded |
OperationNotPermitted | 400 | Termination protection is enabled |
OPEN (Michael): whether termination protection exists in v1. It is the only guard between a wrong instance id and permanent data loss, and its absence should be a decision rather than an omission.
Testing a policy without destroying anything
Section titled “Testing a policy without destroying anything”aws --profile shelf ec2 terminate-instances \ --instance-ids i-0a1b2c3d4e5f60718 --dry-runDryRunOperation means the call would have succeeded. UnauthorizedOperation
means policy would have denied it. Nothing is terminated either way.
Billing
Section titled “Billing”Charging for the instance stops when it enters shutting-down — rating counts a
running instance, and it is no longer one.
Separately attached volumes are not billed today, because storage is not rated; they do survive the instance and keep occupying the pool until you delete them. Unbilled is not free — see Billing user guide.