1. Support
  2. Integrations
  3. EC2
AWS 45 nodes

EC2

AWS integration · 45 node(s).

00Overview

Elastic Compute Cloud operations

Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.

01Connecting EC2

Add your credentials as a Flomation environment secret, then pick them in each node. The connection fields are:

FieldTypeDetails
AuthenticationstringRequiredAccess Keys, Assume Role (cross-account), Managed Role (Credential)
AWS Access KeysecretRequired
AWS Secret KeysecretRequired
Session Token (optional)secret
AWS Role CredentialcredentialRequired
Good to know

Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.

02Attach

AWS EC2 Attach Volume

aws/ec2/attach_volume · Action

Attach an EBS volume to a running or stopped instance.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Volume IDstringRequiredvol-0abc123
Instance IDstringRequiredi-0abc123
Device NamestringRequired/dev/sdf

Returns: tool_result, state, device

03Authorize

AWS EC2 Authorize Security Group Egress

aws/ec2/authorize_security_group_egress · Action

Add an outbound rule to a security group (protocol, port range and CIDR).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group IDstringRequiredsg-0abc123
ProtocolstringRequiredchoices: TCP, UDP, ICMP, All
From Portintegere.g. 443
To Portintegere.g. 443
CIDRstringRequired0.0.0.0/0
Rule DescriptionstringOptional

Returns: tool_result, group_id

AWS EC2 Authorize Security Group Ingress

aws/ec2/authorize_security_group_ingress · Action

Add an inbound rule to a security group (protocol, port range and CIDR).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group IDstringRequiredsg-0abc123
ProtocolstringRequiredchoices: TCP, UDP, ICMP, All
From Portintegere.g. 443
To Portintegere.g. 443
CIDRstringRequired0.0.0.0/0
Rule DescriptionstringOptional

Returns: tool_result, group_id

04Copy

AWS EC2 Copy Image

aws/ec2/copy_image · Action

Copy an AMI from a source region into this action's region.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Source RegionstringRequiredus-east-1
Source Image (AMI) IDstringRequiredami-0abc123
New Image NamestringRequiredmy-app-golden-copy
DescriptionstringOptional
Encrypt Copyboolean
KMS Key ID (optional)stringalias/aws/ebs or a key ARN

Returns: tool_result, image_id

AWS EC2 Copy Snapshot

aws/ec2/copy_snapshot · Action

Copy an EBS snapshot from a source region into this action's region.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Source RegionstringRequiredus-east-1
Source Snapshot IDstringRequiredsnap-0abc123
DescriptionstringOptional
Encrypt Copyboolean
KMS Key ID (optional)stringalias/aws/ebs or a key ARN

Returns: tool_result, snapshot_id

05Create

AWS EC2 Create Image

aws/ec2/create_image · Action

Create an AMI (machine image) from a running or stopped instance.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance IDstringRequiredi-0abc123
Image NamestringRequiredmy-app-golden
DescriptionstringOptional
No Rebootboolean
Tagskey_value_arrayAdd a Key and Value per tag

Returns: tool_result, image_id

AWS EC2 Create Key Pair

aws/ec2/create_key_pair · Action

Create an EC2 key pair and return its private key material.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key Pair NamestringRequiredmy-key-pair
Key Typestringchoices: RSA, ED25519

Returns: tool_result, key_name, key_pair_id, key_fingerprint, key_material

AWS EC2 Create Security Group

aws/ec2/create_security_group · Action

Create a security group in a VPC. Rules are added separately via authorize ingress.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group NamestringRequiredweb-sg
DescriptionstringRequiredAllows web traffic
VPC IDstringvpc-0abc (optional; default VPC if blank)

Returns: tool_result, group_id

AWS EC2 Create Snapshot

aws/ec2/create_snapshot · Action

Create a point-in-time snapshot of an EBS volume.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Volume IDstringRequiredvol-0abc123
DescriptionstringOptional

Returns: tool_result, snapshot_id, state

AWS EC2 Create Tags

aws/ec2/create_tags · Action

Add or overwrite tags on EC2 resources (instances, volumes, etc).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Resource IDsstringRequiredComma-separated, e.g. i-0abc,vol-0def
Tagskey_value_arrayRequiredAdd a Key and Value per tag

Returns: tool_result, tagged

AWS EC2 Create Volume

aws/ec2/create_volume · Action

Create a new EBS volume in an Availability Zone.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Availability ZonestringRequiredeu-west-2a
Size (GiB)integere.g. 100
Volume Typestringchoices: General Purpose SSD (gp3), General Purpose SSD (gp2), Provisioned IOPS SSD (io1), Provisioned IOPS SSD (io2), Throughput Optimised HDD (st1), Cold HDD (sc1), Magnetic (standard)
IOPS (optional)integerRequired for io1/io2, optional for gp3
Throughput MiB/s (optional)integergp3 only
Snapshot ID (optional)stringsnap-0abc123
Encryptedboolean
KMS Key ID (optional)stringRequires Encrypted
Tagskey_value_arrayAdd a Key and Value per tag

Returns: tool_result, volume_id, state, availability_zone

06Delete

AWS EC2 Delete Key Pair

aws/ec2/delete_key_pair · Action

Delete an EC2 key pair by name.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key Pair NamestringRequiredmy-key-pair

Returns: tool_result

AWS EC2 Delete Security Group

aws/ec2/delete_security_group · Action

Delete a security group by id. Fails if the group is still in use.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group IDstringRequiredsg-0abc123

Returns: tool_result, group_id

AWS EC2 Delete Snapshot

aws/ec2/delete_snapshot · Action

Delete an EBS volume snapshot by its ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Snapshot IDstringRequiredsnap-0abc123

Returns: tool_result

AWS EC2 Delete Tags

aws/ec2/delete_tags · Action

Delete tags from EC2 resources (all user tags when none given).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Resource IDsstringRequiredComma-separated, e.g. i-0abc,vol-0def
Tags (optional)key_value_arrayLeave empty to delete all user tags

Returns: tool_result, resources

AWS EC2 Delete Volume

aws/ec2/delete_volume · Action

Delete an available (unattached) EBS volume.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Volume IDstringRequiredvol-0abc123

Returns: tool_result, volume_id

07Deregister

AWS EC2 Deregister Image

aws/ec2/deregister_image · Action

Deregister an AMI (machine image) by its ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Image (AMI) IDstringRequiredami-0abc123

Returns: tool_result

08Describe

AWS EC2 Describe Availability Zones

aws/ec2/describe_availability_zones · Action

List the Availability Zones available in the selected region.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
All Availability ZonesbooleanInclude zones you have not opted in to

Returns: tool_result, zones, count

AWS EC2 Describe Images

aws/ec2/describe_images · Action

List AMIs by id or owner, with name, state, architecture and creation date.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AMI IDsstringComma-separated (optional)
Ownersstringe.g. self, amazon, or an account id (optional)
Filter by NamestringAMI name; wildcards allowed e.g. ubuntu-*/22.04* (optional)
Filter by Statemulti_selectSelect one or more; none = any state — choices: Available, Pending, Failed
Filter by Architecturemulti_selectSelect one or more; none = any — choices: x86_64, arm64, i386
Filter by Visibilitystringchoices: Any, Public only, Private only
Filter by Platformstringe.g. windows — blank includes Linux/UNIX (optional)
Filter by Tagskey_value_arrayOnly return images with these tags (blank Value matches any value for that key)

Returns: tool_result, images, count

AWS EC2 Describe Instance Status

aws/ec2/describe_instance_status · Action

Report EC2 instance state and system/instance status checks.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance IDsstringComma-separated; leave blank for all (optional)
Include All InstancesbooleanInclude non-running instances (default: running only)

Returns: tool_result, statuses, count

AWS EC2 Describe Instance Types

aws/ec2/describe_instance_types · Action

List EC2 instance types with their vCPU and memory sizing.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance TypesstringComma-separated; leave blank for all (optional)

Returns: tool_result, instance_types_info, count

AWS EC2 Describe Instances

aws/ec2/describe_instances · Action

List EC2 instances with their state, type, IPs, AZ and tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance IDsstringComma-separated; leave blank for all (optional)
Filter by Tagskey_value_arrayOnly return instances with these tags (blank Value matches any value for that key)
Filter by Statemulti_selectSelect one or more; none = any state — choices: Running, Stopped, Pending, Stopping, Shutting down, Terminated
Filter by Instance Typestringe.g. t3.micro (optional)
Filter by VPC IDstringvpc-0abc (optional)
Filter by Subnet IDstringsubnet-0abc (optional)
Filter by Availability Zonestringe.g. eu-west-2a (optional)

Returns: tool_result, instances, instance_ids, count

AWS EC2 Describe Key Pairs

aws/ec2/describe_key_pairs · Action

List EC2 key pairs with their name, id, type and fingerprint.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Filter by Key Namestringe.g. deploy-key (optional)
Filter by Key Typemulti_selectSelect one or more; none = any type — choices: RSA, ED25519
Filter by Tagskey_value_arrayOnly return key pairs with these tags (blank Value matches any value for that key)

Returns: tool_result, key_pairs, count

AWS EC2 Describe Security Group Rules

aws/ec2/describe_security_group_rules · Action

List individual security group rules (ingress and egress) by rule ID or group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Security Group Rule IDsstringComma-separated; blank for all (optional)
Filter by Group IDstringsg-0abc123 (optional)

Returns: tool_result, rules, count

AWS EC2 Describe Security Groups

aws/ec2/describe_security_groups · Action

List security groups with their VPC, description and inbound/outbound rules.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group IDsstringComma-separated; blank for all (optional)
Filter by Group Namestringe.g. web-sg (optional)
Filter by VPC IDstringvpc-0abc (optional)
Filter by DescriptionstringExact description text (optional)
Filter by Tagskey_value_arrayOnly return groups with these tags (blank Value matches any value for that key)

Returns: tool_result, security_groups, count

AWS EC2 Describe Snapshots

aws/ec2/describe_snapshots · Action

List EBS snapshots by id or owner, with volume, size, state and progress.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Snapshot IDsstringComma-separated (optional)
Ownersstringe.g. self (optional; blank lists all visible)
Filter by Statusmulti_selectSelect one or more; none = any status — choices: Completed, Pending, Error
Filter by Source Volume IDstringvol-0abc — snapshots of this volume (optional)
Filter by Tagskey_value_arrayOnly return snapshots with these tags (blank Value matches any value for that key)

Returns: tool_result, snapshots, count

AWS EC2 Describe Volumes

aws/ec2/describe_volumes · Action

List EBS volumes with size, state, type, AZ and attachments.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Volume IDsstringComma-separated; blank for all (optional)
Filter by Statusmulti_selectSelect one or more; none = any status — choices: Available, In use, Creating, Deleting, Deleted, Error
Filter by Volume Typemulti_selectSelect one or more; none = any type — choices: gp3, gp2, io1, io2, st1, sc1, standard (magnetic)
Filter by Availability Zonestringe.g. eu-west-2a (optional)
Filter by Attached Instance IDstringi-0abc — volumes attached to this instance (optional)
Filter by Tagskey_value_arrayOnly return volumes with these tags (blank Value matches any value for that key)

Returns: tool_result, volumes, count

09Detach

AWS EC2 Detach Volume

aws/ec2/detach_volume · Action

Detach an EBS volume from an instance.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Volume IDstringRequiredvol-0abc123
Instance ID (optional)stringi-0abc123
Device Name (optional)string/dev/sdf
Force Detachboolean

Returns: tool_result, state

10Get

AWS EC2 Get Console Output

aws/ec2/get_console_output · Action

Retrieve and decode an EC2 instance's console output.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance IDstringRequiredi-0abc123
Latest OutputbooleanRetrieve the latest console output (Nitro instances)

Returns: tool_result, output, timestamp

AWS EC2 Get Windows Password

aws/ec2/get_password_data · Action

Retrieve and optionally decrypt the Windows Administrator password for an EC2 instance.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance IDstringRequiredi-0abc123...
Key Pair Private Key (PEM)stringWire the launch key pair's private key here (or ${secrets.X}) to decrypt; leave blank to return the encrypted data

Returns: tool_result, password, password_data, available

11Import

AWS EC2 Import Key Pair

aws/ec2/import_key_pair · Action

Import an existing public key as an EC2 key pair.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key Pair NamestringRequiredmy-key-pair
Public Key MaterialstringRequiredssh-rsa AAAA... or ssh-ed25519 AAAA...

Returns: tool_result, key_name, key_fingerprint

12Modify

AWS EC2 Modify Instance Attribute

aws/ec2/modify_instance_attribute · Action

Change an EC2 instance's type or its termination, source/dest and EBS-optimised flags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance IDstringRequiredi-0abc123
Instance Typestringe.g. t3.large (optional; instance must be stopped)
Disable API TerminationbooleanEnable termination protection (leave blank to leave unchanged)
Source/Dest CheckbooleanEnable source/destination checks (leave blank to leave unchanged)
EBS OptimisedbooleanEnable EBS optimisation (leave blank to leave unchanged)

Returns: tool_result

AWS EC2 Modify Security Group Rules

aws/ec2/modify_security_group_rules · Action

Update an existing security group rule (protocol, port range, CIDR and description).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group IDstringRequiredsg-0abc123
Security Group Rule IDstringRequiredsgr-0abc123
Protocolstringchoices: TCP, UDP, ICMP, All
From Portintegere.g. 443
To Portintegere.g. 443
CIDR (IPv4)string0.0.0.0/0 (optional)
Rule DescriptionstringOptional

Returns: tool_result, security_group_rule_id

AWS EC2 Modify Volume

aws/ec2/modify_volume · Action

Modify an EBS volume's size, type, IOPS or throughput.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Volume IDstringRequiredvol-0abc123
Size (GiB, optional)integerLarger than current
Volume Type (optional)stringchoices: General Purpose SSD (gp3), General Purpose SSD (gp2), Provisioned IOPS SSD (io1), Provisioned IOPS SSD (io2), Throughput Optimised HDD (st1), Cold HDD (sc1), Magnetic (standard)
IOPS (optional)integer
Throughput MiB/s (optional)integer

Returns: tool_result, volume_id, modification_state

13Monitor

AWS EC2 Monitor Instances

aws/ec2/monitor_instances · Action

Enable detailed CloudWatch monitoring for EC2 instances.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance IDsstringRequiredComma-separated

Returns: tool_result, monitoring

14Reboot

AWS EC2 Reboot Instances

aws/ec2/reboot_instances · Action

Reboot one or more EC2 instances.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance IDsstringRequiredComma-separated, e.g. i-0abc,i-0def

Returns: tool_result, instance_ids

15Revoke

AWS EC2 Revoke Security Group Egress

aws/ec2/revoke_security_group_egress · Action

Remove an outbound rule from a security group (protocol, port range and CIDR).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group IDstringRequiredsg-0abc123
ProtocolstringRequiredchoices: TCP, UDP, ICMP, All
From Portintegere.g. 443
To Portintegere.g. 443
CIDRstringRequired0.0.0.0/0
Rule DescriptionstringOptional

Returns: tool_result, group_id

AWS EC2 Revoke Security Group Ingress

aws/ec2/revoke_security_group_ingress · Action

Remove an inbound rule from a security group (protocol, port range and CIDR).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group IDstringRequiredsg-0abc123
ProtocolstringRequiredchoices: TCP, UDP, ICMP, All
From Portintegere.g. 443
To Portintegere.g. 443
CIDRstringRequired0.0.0.0/0

Returns: tool_result, group_id

16Run

AWS EC2 Run Instances

aws/ec2/run_instances · Action

Launch new EC2 instances from an AMI, with type, key pair, subnet and security groups.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AMI IDstringRequiredami-0abc123
Instance TypestringRequiredt3.micro
Countinteger1
Key Pair NamestringOptional SSH key pair
Subnet IDstringOptional subnet
Security Group IDsstringComma-separated (optional)
Name TagstringSets the Name tag (optional)
User DatatextStartup script, plain text (optional)

Returns: tool_result, instance_ids, count

17Start

AWS EC2 Start Instances

aws/ec2/start_instances · Action

Start one or more stopped EC2 instances.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance IDsstringRequiredComma-separated, e.g. i-0abc,i-0def

Returns: tool_result, state_changes

18Stop

AWS EC2 Stop Instances

aws/ec2/stop_instances · Action

Stop one or more running EC2 instances.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance IDsstringRequiredComma-separated, e.g. i-0abc,i-0def
Force StopbooleanForce stop without a clean shutdown

Returns: tool_result, state_changes

19Terminate

AWS EC2 Terminate Instances

aws/ec2/terminate_instances · Action

Permanently terminate EC2 instances. Destructive and irreversible.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance IDsstringRequiredComma-separated, e.g. i-0abc,i-0def

Returns: tool_result, state_changes

20Unmonitor

AWS EC2 Unmonitor Instances

aws/ec2/unmonitor_instances · Action

Disable detailed CloudWatch monitoring for EC2 instances.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Instance IDsstringRequiredComma-separated

Returns: tool_result

21Update

AWS EC2 Update Security Group Rule Descriptions (Egress)

aws/ec2/update_security_group_rule_descriptions_egress · Action

Update the description of an outbound security group rule.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group IDstringRequiredsg-0abc123
Security Group Rule IDstringRequiredsgr-0abc123
Rule DescriptionstringRequiredNew description text

Returns: tool_result, security_group_rule_id

AWS EC2 Update Security Group Rule Descriptions (Ingress)

aws/ec2/update_security_group_rule_descriptions_ingress · Action

Update the description of an inbound security group rule.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Group IDstringRequiredsg-0abc123
Security Group Rule IDstringRequiredsgr-0abc123
Rule DescriptionstringRequiredNew description text

Returns: tool_result, security_group_rule_id

22Notes & Limitations

Behaviours and constraints worth knowing before you build with these nodes.

  • Every action operates only within the selected Region, so instances, volumes, security groups and key pairs that live in a different region will not appear in results or be available as targets.
  • AWS is eventually consistent, so a resource created in one step may not yet be visible to a describe or dependent action that runs immediately afterwards, occasionally requiring a short retry.
  • The private key returned by Create Key Pair is available only at the moment of creation and cannot be retrieved again, so capture or store it within the same flow.
  • An EBS volume can only be attached to an instance in the same Availability Zone, so create the volume in the zone where the target instance runs.
  • An EBS volume's size can only be increased and never decreased, and AWS requires a wait of at least six hours before the same volume can be modified again.