1. Support
  2. Integrations
  3. VPC
AWS 182 nodes

VPC

AWS integration · 182 node(s).

00Overview

Build and operate Amazon VPC networks straight from a flow: create VPCs, subnets, route tables and gateways, wire up NAT, internet and egress-only gateways, and control traffic with network ACLs, prefix lists and flow logs. Connect networks together through VPC peering, transit gateways, PrivateLink endpoints and Site-to-Site or Client VPN, and hand out addresses with Elastic IPs and IPAM pools. Describe actions let a flow read the live state of any of these, so it can make a decision and drive the next step.

Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.

01Connecting VPC

  1. In the node's Authentication dropdown, choose how Flomation signs in: Access Keys (your own IAM user keys), Assume Role (cross-account) (Flomation's principal assumes a role in your account), or Managed Role (Credential) (a role credential already stored in Flomation).
  2. For Access Keys, open the AWS console at IAM → Users, pick or create a user, and under Security credentials choose Create access key; paste the two values into AWS Access Key and AWS Secret Key, and leave Session Token (optional) blank unless you are using temporary STS credentials.
  3. For Assume Role (cross-account), create a role under IAM → Roles whose trust policy lets Flomation's principal call sts:AssumeRole, then paste its ARN into Role ARN to Assume — and, if the trust policy requires one, add the matching Assume Role External ID (optional).
  4. Set Region to the AWS Region your network lives in (for example eu-west-2) — the node only acts within that Region.
  5. Store the secret value as a Flomation environment secret (e.g. vpc_secret) and select it in the node's AWS Secret Key field; for the Managed Role (Credential) method, pick your stored credential in the AWS Role Credential field instead.
FieldTypeDetails
AuthenticationstringRequiredAccess Keys, Assume Role (cross-account), Managed Role (Credential)
AWS Access KeysecretRequired
AWS Secret KeysecretRequired
Session Token (optional)secret
AWS Role CredentialcredentialRequired
Good to know

Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.

02Accept

AWS VPC Accept Transit Gateway Peering Attachment

aws/vpc/accept_transit_gateway_peering_attachment · Action

Accept a pending transit gateway peering attachment request.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Attachment IDstringRequiredtgw-attach-0123456789abcdef0

Returns: tool_result, attachment

AWS VPC Accept Transit Gateway VPC Attachment

aws/vpc/accept_transit_gateway_vpc_attachment · Action

Accept a pending cross-account transit gateway VPC attachment.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Attachment IDstringRequiredtgw-attach-0123456789abcdef0

Returns: tool_result, attachment

AWS VPC Accept Endpoint Connections

aws/vpc/accept_vpc_endpoint_connections · Action

Accept consumer connection requests to a VPC endpoint service you own.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Service IDstringRequiredvpce-svc-0abc
VPC Endpoint IDsstringRequiredComma-separated, e.g. vpce-0abc,vpce-0def

Returns: tool_result, unsuccessful, success

AWS VPC Accept Peering Connection

aws/vpc/accept_vpc_peering_connection · Action

Accept a pending VPC peering connection request.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC Peering Connection IDstringRequiredpcx-0abc

Returns: tool_result, vpc_peering_connection

03Allocate

AWS VPC Allocate Address

aws/vpc/allocate_address · Action

Allocate a new Elastic IP address.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Domainstringchoices: VPC, Standard (EC2-Classic)
Tagskey_value_arrayOptional tags to apply to the Elastic IP

Returns: tool_result, address, allocation_id

AWS IPAM Allocate Pool CIDR

aws/vpc/allocate_ipam_pool_cidr · Action

Allocate a CIDR from an IPAM pool by CIDR or netmask length.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
IPAM Pool IDstringRequired
CIDR (optional)string10.0.0.0/24
Netmask Length (optional)integer24
Description (optional)string

Returns: tool_result, allocation, ipam_pool_allocation_id

04Assign

AWS VPC Assign IPv6 Addresses

aws/vpc/assign_ipv6_addresses · Action

Assign IPv6 addresses to a network interface.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Network Interface IDstringRequiredeni-0abc...
IPv6 Addresses (optional)stringComma-separated, e.g. 2001:db8::1,2001:db8::2
IPv6 Address Count (optional)integere.g. 2

Returns: tool_result, assigned_ipv6_addresses, network_interface_id

AWS VPC Assign Private IP Addresses

aws/vpc/assign_private_ip_addresses · Action

Assign secondary private IPv4 addresses to a network interface.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Network Interface IDstringRequiredeni-0abc...
Private IP Addresses (optional)stringComma-separated, e.g. 10.0.1.10,10.0.1.11
Secondary IP Count (optional)integere.g. 2

Returns: tool_result, assigned_private_ip_addresses, network_interface_id

05Associate

AWS VPC Associate Address

aws/vpc/associate_address · Action

Associate an Elastic IP with an instance or network interface.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Allocation IDstringRequiredeipalloc-0abc123
Instance IDstringi-0abc123 (instance or network interface required)
Network Interface IDstringeni-0abc123 (instance or network interface required)
Private IP AddressstringOptional, when the interface has multiple private IPs

Returns: tool_result, association_id

AWS VPC Associate Client VPN Target Network

aws/vpc/associate_client_vpn_target_network · Action

Associate a target subnet with an AWS Client VPN endpoint.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Client VPN Endpoint IDstringRequiredcvpn-endpoint-0abc123
Subnet IDstringRequiredsubnet-0abc123

Returns: tool_result, association_id, status

AWS VPC Associate DHCP Options

aws/vpc/associate_dhcp_options · Action

Associate a DHCP options set with a VPC, or 'default' to reset it.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
DHCP Options IDstringRequireddopt-0abc (or 'default' to reset)
VPC IDstringRequiredvpc-0abc

Returns: tool_result

AWS VPC Associate NAT Gateway Address

aws/vpc/associate_nat_gateway_address · Action

Associate Elastic IP allocations (secondary addresses) with a public NAT gateway.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
NAT Gateway IDstringRequirednat-0abc123
Elastic IP Allocation IDsstringRequiredComma-separated, e.g. eipalloc-0abc,eipalloc-0def

Returns: tool_result, nat_gateway, nat_gateway_id

AWS VPC Associate Route Table

aws/vpc/associate_route_table · Action

Associate a route table with a subnet or gateway.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Route Table IDstringRequiredrtb-0abc...
Subnet ID (optional)stringsubnet-0abc...
Gateway ID (optional)stringigw-0abc...

Returns: tool_result, association_id

AWS VPC Associate Transit Gateway Route Table

aws/vpc/associate_transit_gateway_route_table · Action

Associate a transit gateway attachment with a route table.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Route Table IDstringRequiredtgw-rtb-0123456789abcdef0
Transit Gateway Attachment IDstringRequiredtgw-attach-0123456789abcdef0

Returns: tool_result, association

AWS VPC Associate CIDR Block

aws/vpc/associate_vpc_cidr_block · Action

Associate a secondary IPv4 or IPv6 CIDR block with a VPC.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC IDstringRequiredvpc-0abc...
Secondary IPv4 CIDR Block (optional)string10.1.0.0/16
Request Amazon-provided IPv6 CIDRboolean
IPv6 CIDR Block (optional)string2600:1f16:...::/56

Returns: tool_result, cidr_association

06Attach

AWS VPC Attach Internet Gateway

aws/vpc/attach_internet_gateway · Action

Attach an internet gateway to a VPC.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Internet Gateway IDstringRequiredigw-0abc123
VPC IDstringRequiredvpc-0abc123

Returns: tool_result

AWS VPC Attach Network Interface

aws/vpc/attach_network_interface · Action

Attach an elastic network interface (ENI) to an EC2 instance.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Network Interface IDstringRequiredeni-0abc
Instance IDstringRequiredi-0abc
Device IndexintegerRequirede.g. 1 (0 is the primary interface)

Returns: tool_result, attachment_id

AWS VPC Attach VPN Gateway

aws/vpc/attach_vpn_gateway · Action

Attach a virtual private gateway to a VPC.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPN Gateway IDstringRequiredvgw-0abc123
VPC IDstringRequiredvpc-0abc123

Returns: tool_result, state

07Authorize

AWS VPC Authorize Client VPN Ingress

aws/vpc/authorize_client_vpn_ingress · Action

Add an ingress authorization rule to an AWS Client VPN endpoint.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Client VPN Endpoint IDstringRequiredcvpn-endpoint-0abc123
Target Network CIDRstringRequired10.0.0.0/16
Authorize All Groups (optional)boolean
Access Group ID (optional)stringRequired unless authorizing all groups
Description (optional)string

Returns: tool_result, status

08Create

AWS VPC Create Client VPN Endpoint

aws/vpc/create_client_vpn_endpoint · Action

Create an AWS Client VPN endpoint for remote users to connect via a VPN client.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Client CIDR BlockstringRequired10.0.0.0/22 (min /22, max /12)
Server Certificate ARNstringRequiredarn:aws:acm:...:certificate/...
Authentication TypestringRequiredchoices: Mutual (Certificate), Active Directory, Federated (SAML)
Client Root Certificate Chain ARN (for certificate auth)stringarn:aws:acm:...:certificate/...
Enable Connection LoggingbooleanRequired
CloudWatch Log Group (if logging enabled)string
VPC ID (optional)stringvpc-0abc123
Description (optional)string
Tagskey_value_array

Returns: tool_result, endpoint, client_vpn_endpoint_id

AWS VPC Create Client VPN Route

aws/vpc/create_client_vpn_route · Action

Add a route to an AWS Client VPN endpoint's route table.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Client VPN Endpoint IDstringRequiredcvpn-endpoint-0abc123
Destination CIDR BlockstringRequired0.0.0.0/0
Target VPC Subnet IDstringRequiredsubnet-0abc123
Description (optional)string

Returns: tool_result, status

AWS VPC Create Customer Gateway

aws/vpc/create_customer_gateway · Action

Register a customer gateway (the on-premises end of a Site-to-Site VPN).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPN TypestringRequiredchoices: ipsec.1
BGP ASN (optional)integer65000
Outside IP Address (optional)string203.0.113.10
Certificate ARN (optional)string
Device Name (optional)string
Tagskey_value_array

Returns: tool_result, customer_gateway, customer_gateway_id

AWS VPC Create DHCP Options

aws/vpc/create_dhcp_options · Action

Create a DHCP options set with domain name, DNS, and NTP servers.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Domain Name (optional)stringexample.internal
DNS Servers (optional)stringComma-separated, e.g. 10.0.0.2,AmazonProvidedDNS
NTP Servers (optional)stringComma-separated, e.g. 169.254.169.123
Tagskey_value_array

Returns: tool_result, dhcp_options, dhcp_options_id

AWS VPC Create Egress-Only Internet Gateway

aws/vpc/create_egress_only_internet_gateway · Action

Create an egress-only internet gateway for outbound IPv6 traffic in a VPC.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC IDstringRequiredvpc-0abc
Tagskey_value_array

Returns: tool_result, egress_only_internet_gateway, egress_only_internet_gateway_id

AWS VPC Create Flow Logs

aws/vpc/create_flow_logs · Action

Create flow logs capturing traffic for a VPC, subnet, or network interface.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Resource IDsstringRequiredComma-separated, e.g. vpc-0abc,subnet-0def
Resource TypestringRequiredchoices: VPC, Subnet, Network Interface
Traffic TypestringRequiredchoices: Accept, Reject, All
Log Destination Typestringchoices: CloudWatch Logs, S3
CloudWatch Log Group Namestring/vpc/flow-logs
S3 Destination ARNstringarn:aws:s3:::my-bucket/prefix/
IAM Role ARN (for CloudWatch Logs)stringarn:aws:iam::<account>:role/flow-logs
Tagskey_value_array

Returns: tool_result, flow_logs, flow_log_id

AWS VPC Create Internet Gateway

aws/vpc/create_internet_gateway · Action

Create a new internet gateway, optionally with tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Tagskey_value_arrayOptional tags to apply to the internet gateway

Returns: tool_result, internet_gateway, internet_gateway_id

AWS IPAM Create IPAM

aws/vpc/create_ipam · Action

Create an AWS IPAM (IP Address Manager) with operating Regions and tier.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Description (optional)string
Operating RegionsstringRequiredeu-west-2,us-east-1
Tierstringchoices: Free, Advanced
Tagskey_value_array

Returns: tool_result, ipam, ipam_id

AWS IPAM Create Pool

aws/vpc/create_ipam_pool · Action

Create an IPAM pool within a scope for allocating CIDRs.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
IPAM Scope IDstringRequired
Address FamilystringRequiredchoices: IPv4, IPv6
Source IPAM Pool ID (optional)string
Description (optional)string
Auto Importboolean
Locale (optional)stringeu-west-2
Tagskey_value_array

Returns: tool_result, ipam_pool, ipam_pool_id

AWS IPAM Create Scope

aws/vpc/create_ipam_scope · Action

Create a private IPAM scope within an AWS IPAM.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
IPAM IDstringRequired
Description (optional)string
Tagskey_value_array

Returns: tool_result, ipam_scope, ipam_scope_id

AWS VPC Create Managed Prefix List

aws/vpc/create_managed_prefix_list · Action

Create a customer-managed prefix list of CIDR entries.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Prefix List NamestringRequiredoffice-networks
Maximum EntriesintegerRequiredThe maximum number of CIDR entries the list can hold
Address FamilystringRequiredchoices: IPv4, IPv6
Entries (optional)textJSON array e.g. [{"cidr":"10.0.0.0/16","description":"HQ"}]
Tagskey_value_array

Returns: tool_result, prefix_list, prefix_list_id

AWS VPC Create NAT Gateway

aws/vpc/create_nat_gateway · Action

Create a NAT gateway in a subnet (public with an EIP, or private).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Subnet IDstringRequiredsubnet-0abc123
Elastic IP Allocation IDstringeipalloc-0abc (required for a public NAT gateway)
Connectivity Typestringchoices: Public, Private
Tagskey_value_arrayOptional tags to apply to the NAT gateway

Returns: tool_result, nat_gateway, nat_gateway_id

AWS VPC Create Network ACL

aws/vpc/create_network_acl · Action

Create a network ACL in a VPC. Rules are added separately via create entry.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC IDstringRequiredvpc-0abc
Tagskey_value_array

Returns: tool_result, network_acl, network_acl_id

AWS VPC Create Network ACL Entry

aws/vpc/create_network_acl_entry · Action

Add an inbound or outbound rule to a network ACL.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Network ACL IDstringRequiredacl-0abc
Rule NumberintegerRequired100 (1-32766, processed ascending)
Protocol NumberstringRequired6 = TCP, 17 = UDP, -1 = all
Rule ActionstringRequiredchoices: Allow, Deny
Egress (outbound rule)booleanRequired
CIDR BlockstringRequired0.0.0.0/0
Port From (optional)integerFor TCP/UDP, e.g. 80
Port To (optional)integerFor TCP/UDP, e.g. 80

Returns: tool_result

AWS VPC Create Network Insights Path

aws/vpc/create_network_insights_path · Action

Create a Reachability Analyzer path between a source and destination resource.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
SourcestringRequiredResource ID or ARN (e.g. igw-0abc... or an instance ID)
Destination (optional)stringResource ID or ARN
ProtocolstringRequiredchoices: TCP, UDP
Destination Port (optional)integer
Tagskey_value_array

Returns: tool_result, path, network_insights_path_id

AWS VPC Create Network Interface

aws/vpc/create_network_interface · Action

Create an elastic network interface (ENI) in a subnet.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Subnet IDstringRequiredsubnet-0abc
Description (optional)stringe.g. App server ENI
Private IP Address (optional)stringe.g. 10.0.1.10
Security Group IDs (optional)stringComma-separated, e.g. sg-0abc,sg-0def
Tagskey_value_array

Returns: tool_result, network_interface, network_interface_id

AWS VPC Create Route

aws/vpc/create_route · Action

Add a route to a route table pointing at a gateway or other target.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Route Table IDstringRequiredrtb-0abc...
Destination CIDR BlockstringRequired0.0.0.0/0
Target TypestringRequiredchoices: Internet Gateway, NAT Gateway, Network Interface, VPC Peering Connection, Transit Gateway, Egress-only Internet Gateway
Target IDstringRequiredigw-0abc... / nat-... / eni-... etc

Returns: tool_result

AWS VPC Create Route Table

aws/vpc/create_route_table · Action

Create a route table within a VPC.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC IDstringRequiredvpc-0abc...
Tagskey_value_array

Returns: tool_result, route_table, route_table_id

AWS VPC Create Subnet

aws/vpc/create_subnet · Action

Create a subnet within a VPC with a CIDR block and optional AZ.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC IDstringRequiredvpc-0abc...
CIDR BlockstringRequired10.0.1.0/24
Availability Zone (optional)stringeu-west-2a
Tagskey_value_array

Returns: tool_result, subnet, subnet_id

AWS VPC Create Traffic Mirror Filter

aws/vpc/create_traffic_mirror_filter · Action

Create a VPC Traffic Mirror filter to hold ingress/egress mirroring rules.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Description (optional)string
Tagskey_value_array

Returns: tool_result, filter, traffic_mirror_filter_id

AWS VPC Create Traffic Mirror Filter Rule

aws/vpc/create_traffic_mirror_filter_rule · Action

Add an ingress or egress rule to a VPC Traffic Mirror filter.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Traffic Mirror Filter IDstringRequiredtmf-0abc
Traffic DirectionstringRequiredchoices: Ingress, Egress
Rule NumberintegerRequirede.g. 100 (unique per direction, evaluated ascending)
Rule ActionstringRequiredchoices: Accept, Reject
Protocol Number (optional)integere.g. 6 (TCP), 17 (UDP)
Destination CIDR BlockstringRequired0.0.0.0/0
Source CIDR BlockstringRequired10.0.0.0/16
Description (optional)string

Returns: tool_result, rule, traffic_mirror_filter_rule_id

AWS VPC Create Traffic Mirror Session

aws/vpc/create_traffic_mirror_session · Action

Create a VPC Traffic Mirror session from a source ENI to a target with a filter.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Source Network Interface IDstringRequiredeni-0abc
Traffic Mirror Target IDstringRequiredtmt-0abc
Traffic Mirror Filter IDstringRequiredtmf-0abc
Session NumberintegerRequired1-32766 (evaluation order for the source ENI)
Packet Length (optional)integerBytes to mirror after the VXLAN header
Virtual Network ID (optional)integerVXLAN ID; random if left blank
Description (optional)string
Tagskey_value_array

Returns: tool_result, session, traffic_mirror_session_id

AWS VPC Create Traffic Mirror Target

aws/vpc/create_traffic_mirror_target · Action

Create a VPC Traffic Mirror target (ENI, NLB, or Gateway LB endpoint).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Network Interface ID (optional)stringeni-0abc
Network Load Balancer ARN (optional)stringarn:aws:elasticloadbalancing:...
Gateway Load Balancer Endpoint ID (optional)stringvpce-0abc
Description (optional)string
Tagskey_value_array

Returns: tool_result, target, traffic_mirror_target_id

AWS VPC Create Transit Gateway

aws/vpc/create_transit_gateway · Action

Create a transit gateway to connect VPCs and on-premises networks.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Description (optional)stringe.g. Production transit gateway
Amazon Side ASN (optional)integer64512–65534, or 4200000000–4294967294
Tagskey_value_array

Returns: tool_result, transit_gateway, transit_gateway_id

AWS VPC Create Transit Gateway Connect

aws/vpc/create_transit_gateway_connect · Action

Create a Connect attachment over an existing VPC or Direct Connect attachment.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transport Attachment IDstringRequiredtgw-attach-0123456789abcdef0
ProtocolstringRequiredchoices: GRE
Tagskey_value_array

Returns: tool_result, connect, transit_gateway_attachment_id

AWS VPC Create Transit Gateway Multicast Domain

aws/vpc/create_transit_gateway_multicast_domain · Action

Create a multicast domain on a transit gateway.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway IDstringRequiredtgw-0123456789abcdef0
Tagskey_value_array

Returns: tool_result, multicast_domain, transit_gateway_multicast_domain_id

AWS VPC Create Transit Gateway Peering Attachment

aws/vpc/create_transit_gateway_peering_attachment · Action

Request a peering attachment between two transit gateways across accounts or Regions.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway IDstringRequiredtgw-0123456789abcdef0
Peer Transit Gateway IDstringRequiredtgw-0123456789abcdef0
Peer Account IDstringRequired123456789012
Peer RegionstringRequiredus-east-1
Tagskey_value_array

Returns: tool_result, attachment, transit_gateway_attachment_id

AWS VPC Create Transit Gateway Route

aws/vpc/create_transit_gateway_route · Action

Create a static route in a transit gateway route table.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Route Table IDstringRequiredtgw-rtb-0123456789abcdef0
Destination CIDR BlockstringRequired10.1.0.0/16
Transit Gateway Attachment ID (optional)stringTarget attachment; omit for a blackhole route
BlackholebooleanDrop traffic matching this route

Returns: tool_result, route

AWS VPC Create Transit Gateway Route Table

aws/vpc/create_transit_gateway_route_table · Action

Create a transit gateway route table for custom routing domains.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway IDstringRequiredtgw-0123456789abcdef0
Tagskey_value_array

Returns: tool_result, route_table, transit_gateway_route_table_id

AWS VPC Create Transit Gateway VPC Attachment

aws/vpc/create_transit_gateway_vpc_attachment · Action

Attach a VPC to a transit gateway across one or more subnets.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway IDstringRequiredtgw-0123456789abcdef0
VPC IDstringRequiredvpc-0123456789abcdef0
Subnet IDsstringRequiredComma-separated; one subnet per Availability Zone
Tagskey_value_array

Returns: tool_result, attachment, transit_gateway_attachment_id

AWS VPC Create VPC

aws/vpc/create_vpc · Action

Create a new Amazon VPC with a CIDR block, tenancy, and optional IPv6.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
CIDR BlockstringRequired10.0.0.0/16
Instance Tenancystringchoices: Default, Dedicated
Request Amazon-provided IPv6 CIDRboolean
Tagskey_value_array

Returns: tool_result, vpc, vpc_id

AWS VPC Create VPC Endpoint

aws/vpc/create_vpc_endpoint · Action

Create a Gateway or Interface VPC endpoint to an AWS service.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC IDstringRequiredvpc-0abc
Service NamestringRequiredcom.amazonaws.eu-west-2.s3
Endpoint Typestringchoices: Gateway, Interface, Gateway Load Balancer
Route Table IDs (Gateway)stringComma-separated, e.g. rtb-0abc,rtb-0def
Subnet IDs (Interface)stringComma-separated, e.g. subnet-0abc
Security Group IDs (Interface)stringComma-separated, e.g. sg-0abc
Enable Private DNS (Interface)boolean
Tagskey_value_array

Returns: tool_result, vpc_endpoint, vpc_endpoint_id

AWS VPC Create Endpoint Service Configuration

aws/vpc/create_vpc_endpoint_service_configuration · Action

Create a VPC endpoint service (PrivateLink provider) fronted by load balancers.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Network Load Balancer ARNs (optional)stringComma-separated NLB ARNs
Gateway Load Balancer ARNs (optional)stringComma-separated GWLB ARNs
Require Acceptance (optional)boolean
Private DNS Name (optional)stringservice.example.com
Tagskey_value_array

Returns: tool_result, service, service_id

AWS VPC Create Peering Connection

aws/vpc/create_vpc_peering_connection · Action

Request a VPC peering connection between two VPCs (same or cross account/region).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Requester VPC IDstringRequiredvpc-0abc
Peer (Accepter) VPC IDstringRequiredvpc-0def
Peer Owner Account ID (optional)stringLeave blank for same account
Peer Region (optional)stringLeave blank for same region
Tagskey_value_array

Returns: tool_result, vpc_peering_connection, vpc_peering_connection_id

AWS VPC Create VPN Connection

aws/vpc/create_vpn_connection · Action

Create a Site-to-Site VPN connection between a customer gateway and an Amazon gateway.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPN TypestringRequiredchoices: ipsec.1
Customer Gateway IDstringRequiredcgw-0abc123
VPN Gateway ID (optional)stringvgw-0abc123 — provide this OR a transit gateway
Transit Gateway ID (optional)stringtgw-0abc123 — provide this OR a VPN gateway
Static Routes Onlyboolean
Tagskey_value_array

Returns: tool_result, vpn_connection, vpn_connection_id

AWS VPC Create VPN Connection Route

aws/vpc/create_vpn_connection_route · Action

Create a static route for a Site-to-Site VPN connection (policy-based VPN).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPN Connection IDstringRequiredvpn-0abc123
Destination CIDR BlockstringRequired192.168.10.0/24

Returns: tool_result

AWS VPC Create VPN Gateway

aws/vpc/create_vpn_gateway · Action

Create a virtual private gateway (the Amazon end of a Site-to-Site VPN).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPN TypestringRequiredchoices: ipsec.1
Amazon Side ASN (optional)integer64512
Availability Zone (optional)stringeu-west-2a
Tagskey_value_array

Returns: tool_result, vpn_gateway, vpn_gateway_id

09Delete

AWS VPC Delete Client VPN Endpoint

aws/vpc/delete_client_vpn_endpoint · Action

Delete an AWS Client VPN endpoint by id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Client VPN Endpoint IDstringRequiredcvpn-endpoint-0abc123

Returns: tool_result, status

AWS VPC Delete Client VPN Route

aws/vpc/delete_client_vpn_route · Action

Remove a route from an AWS Client VPN endpoint's route table.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Client VPN Endpoint IDstringRequiredcvpn-endpoint-0abc123
Destination CIDR BlockstringRequired0.0.0.0/0
Target VPC Subnet ID (optional)stringsubnet-0abc123

Returns: tool_result, status

AWS VPC Delete Customer Gateway

aws/vpc/delete_customer_gateway · Action

Delete a customer gateway.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Customer Gateway IDstringRequiredcgw-0abc123

Returns: tool_result

AWS VPC Delete DHCP Options

aws/vpc/delete_dhcp_options · Action

Delete a DHCP options set. It must not be associated with any VPC.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
DHCP Options IDstringRequireddopt-0abc

Returns: tool_result

AWS VPC Delete Egress-Only Internet Gateway

aws/vpc/delete_egress_only_internet_gateway · Action

Delete an egress-only internet gateway.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Egress-Only Internet Gateway IDstringRequiredeigw-0abc

Returns: tool_result

AWS VPC Delete Flow Logs

aws/vpc/delete_flow_logs · Action

Delete one or more VPC flow logs by ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Flow Log IDsstringRequiredComma-separated, e.g. fl-0abc,fl-0def

Returns: tool_result

AWS VPC Delete Internet Gateway

aws/vpc/delete_internet_gateway · Action

Delete an internet gateway by ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Internet Gateway IDstringRequiredigw-0abc123

Returns: tool_result

AWS IPAM Delete IPAM

aws/vpc/delete_ipam · Action

Delete an AWS IPAM by id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
IPAM IDstringRequired

Returns: tool_result, ipam

AWS IPAM Delete Pool

aws/vpc/delete_ipam_pool · Action

Delete an AWS IPAM pool by id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
IPAM Pool IDstringRequired

Returns: tool_result, ipam_pool

AWS IPAM Delete Scope

aws/vpc/delete_ipam_scope · Action

Delete an AWS IPAM scope by id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
IPAM Scope IDstringRequired

Returns: tool_result, ipam_scope

AWS VPC Delete Managed Prefix List

aws/vpc/delete_managed_prefix_list · Action

Delete a customer-managed prefix list.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Prefix List IDstringRequiredpl-0abc...

Returns: tool_result, prefix_list

AWS VPC Delete NAT Gateway

aws/vpc/delete_nat_gateway · Action

Delete a NAT gateway by ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
NAT Gateway IDstringRequirednat-0abc123

Returns: tool_result

AWS VPC Delete Network ACL

aws/vpc/delete_network_acl · Action

Delete a network ACL. The default network ACL cannot be deleted.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Network ACL IDstringRequiredacl-0abc

Returns: tool_result

AWS VPC Delete Network ACL Entry

aws/vpc/delete_network_acl_entry · Action

Remove an inbound or outbound rule from a network ACL.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Network ACL IDstringRequiredacl-0abc
Rule NumberintegerRequired100
Egress (outbound rule)booleanRequired

Returns: tool_result

AWS VPC Delete Network Insights Analysis

aws/vpc/delete_network_insights_analysis · Action

Delete a Reachability Analyzer analysis by its ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Analysis IDstringRequired

Returns: tool_result, network_insights_analysis_id

AWS VPC Delete Network Insights Path

aws/vpc/delete_network_insights_path · Action

Delete a Reachability Analyzer path by its ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Path IDstringRequired

Returns: tool_result, network_insights_path_id

AWS VPC Delete Network Interface

aws/vpc/delete_network_interface · Action

Delete a detached elastic network interface (ENI).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Network Interface IDstringRequiredeni-0abc

Returns: tool_result

AWS VPC Delete Route

aws/vpc/delete_route · Action

Remove a route from a route table by destination CIDR.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Route Table IDstringRequiredrtb-0abc...
Destination CIDR BlockstringRequired0.0.0.0/0

Returns: tool_result

AWS VPC Delete Route Table

aws/vpc/delete_route_table · Action

Delete a route table by its id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Route Table IDstringRequiredrtb-0abc...

Returns: tool_result

AWS VPC Delete Subnet

aws/vpc/delete_subnet · Action

Delete a subnet by its id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Subnet IDstringRequiredsubnet-0abc...

Returns: tool_result

AWS VPC Delete Traffic Mirror Filter

aws/vpc/delete_traffic_mirror_filter · Action

Delete a VPC Traffic Mirror filter by its id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Traffic Mirror Filter IDstringRequiredtmf-0abc

Returns: tool_result, traffic_mirror_filter_id

AWS VPC Delete Traffic Mirror Filter Rule

aws/vpc/delete_traffic_mirror_filter_rule · Action

Delete a rule from a VPC Traffic Mirror filter by its rule id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Traffic Mirror Filter Rule IDstringRequiredtmfr-0abc

Returns: tool_result, traffic_mirror_filter_rule_id

AWS VPC Delete Traffic Mirror Session

aws/vpc/delete_traffic_mirror_session · Action

Delete a VPC Traffic Mirror session by its id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Traffic Mirror Session IDstringRequiredtms-0abc

Returns: tool_result, traffic_mirror_session_id

AWS VPC Delete Traffic Mirror Target

aws/vpc/delete_traffic_mirror_target · Action

Delete a VPC Traffic Mirror target by its id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Traffic Mirror Target IDstringRequiredtmt-0abc

Returns: tool_result, traffic_mirror_target_id

AWS VPC Delete Transit Gateway

aws/vpc/delete_transit_gateway · Action

Delete a transit gateway.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway IDstringRequiredtgw-0abc

Returns: tool_result, transit_gateway

AWS VPC Delete Transit Gateway Connect

aws/vpc/delete_transit_gateway_connect · Action

Delete a transit gateway Connect attachment.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Attachment IDstringRequiredtgw-attach-0123456789abcdef0

Returns: tool_result, connect

AWS VPC Delete Transit Gateway Multicast Domain

aws/vpc/delete_transit_gateway_multicast_domain · Action

Delete a transit gateway multicast domain.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Multicast Domain IDstringRequiredtgw-mcast-domain-0123456789abcdef0

Returns: tool_result, multicast_domain

AWS VPC Delete Transit Gateway Peering Attachment

aws/vpc/delete_transit_gateway_peering_attachment · Action

Delete a transit gateway peering attachment.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Attachment IDstringRequiredtgw-attach-0123456789abcdef0

Returns: tool_result, attachment

AWS VPC Delete Transit Gateway Route

aws/vpc/delete_transit_gateway_route · Action

Delete a static route from a transit gateway route table.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Route Table IDstringRequiredtgw-rtb-0123456789abcdef0
Destination CIDR BlockstringRequired10.1.0.0/16

Returns: tool_result, route

AWS VPC Delete Transit Gateway Route Table

aws/vpc/delete_transit_gateway_route_table · Action

Delete a transit gateway route table.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Route Table IDstringRequiredtgw-rtb-0123456789abcdef0

Returns: tool_result, route_table

AWS VPC Delete Transit Gateway VPC Attachment

aws/vpc/delete_transit_gateway_vpc_attachment · Action

Delete a transit gateway VPC attachment.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Attachment IDstringRequiredtgw-attach-0123456789abcdef0

Returns: tool_result, attachment

AWS VPC Delete VPC

aws/vpc/delete_vpc · Action

Delete an Amazon VPC by its id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC IDstringRequiredvpc-0abc...

Returns: tool_result

AWS VPC Delete Endpoint Service Configurations

aws/vpc/delete_vpc_endpoint_service_configurations · Action

Delete one or more VPC endpoint services (PrivateLink provider side) you own.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Service IDsstringRequiredComma-separated, e.g. vpce-svc-0abc,vpce-svc-0def

Returns: tool_result, unsuccessful, success

AWS VPC Delete VPC Endpoints

aws/vpc/delete_vpc_endpoints · Action

Delete one or more VPC endpoints by ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC Endpoint IDsstringRequiredComma-separated, e.g. vpce-0abc,vpce-0def

Returns: tool_result

AWS VPC Delete Peering Connection

aws/vpc/delete_vpc_peering_connection · Action

Delete a VPC peering connection.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC Peering Connection IDstringRequiredpcx-0abc

Returns: tool_result

AWS VPC Delete VPN Connection

aws/vpc/delete_vpn_connection · Action

Delete a Site-to-Site VPN connection.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPN Connection IDstringRequiredvpn-0abc123

Returns: tool_result

AWS VPC Delete VPN Connection Route

aws/vpc/delete_vpn_connection_route · Action

Delete a static route from a Site-to-Site VPN connection (policy-based VPN).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPN Connection IDstringRequiredvpn-0abc123
Destination CIDR BlockstringRequired192.168.10.0/24

Returns: tool_result

AWS VPC Delete VPN Gateway

aws/vpc/delete_vpn_gateway · Action

Delete a virtual private gateway.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPN Gateway IDstringRequiredvgw-0abc123

Returns: tool_result

10Describe

AWS VPC Describe Addresses

aws/vpc/describe_addresses · Action

List Elastic IP addresses, optionally filtered by allocation ID or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Allocation IDsstringComma-separated; blank for all (optional)
Filter by Tagskey_value_arrayOnly return addresses with these tags (blank Value matches any value for that key)

Returns: tool_result, addresses, count

AWS VPC Describe Client VPN Connections

aws/vpc/describe_client_vpn_connections · Action

List the client connections for an AWS Client VPN endpoint.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Client VPN Endpoint IDstringRequiredcvpn-endpoint-0abc123

Returns: tool_result, connections, count

AWS VPC Describe Client VPN Endpoints

aws/vpc/describe_client_vpn_endpoints · Action

List AWS Client VPN endpoints, optionally filtered by id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Client VPN Endpoint ID (optional)stringLeave blank to list all
Filter by Tags (optional)key_value_array

Returns: tool_result, endpoints, count

AWS VPC Describe Client VPN Routes

aws/vpc/describe_client_vpn_routes · Action

List the routes for an AWS Client VPN endpoint.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Client VPN Endpoint IDstringRequiredcvpn-endpoint-0abc123

Returns: tool_result, routes, count

AWS VPC Describe Client VPN Target Networks

aws/vpc/describe_client_vpn_target_networks · Action

List the target networks associated with an AWS Client VPN endpoint.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Client VPN Endpoint IDstringRequiredcvpn-endpoint-0abc123

Returns: tool_result, target_networks, count

AWS VPC Describe Customer Gateways

aws/vpc/describe_customer_gateways · Action

List customer gateways, optionally filtered by id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Customer Gateway ID (optional)stringLeave blank to list all
Filter by Tags (optional)key_value_array

Returns: tool_result, customer_gateways, count

AWS VPC Describe DHCP Options

aws/vpc/describe_dhcp_options · Action

List DHCP option sets, optionally filtered by ID or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
DHCP Options ID (optional)stringLeave blank to list all
Filter by Tags (optional)key_value_array

Returns: tool_result, dhcp_option_sets, count

AWS VPC Describe Egress-Only Internet Gateways

aws/vpc/describe_egress_only_internet_gateways · Action

List egress-only internet gateways, optionally by id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Egress-Only Internet Gateway IDs (optional)stringComma-separated; blank lists all
Filter by Tagskey_value_arrayOnly return gateways with these tags (blank Value matches any value for that key)

Returns: tool_result, egress_only_internet_gateways, count

AWS VPC Describe Flow Logs

aws/vpc/describe_flow_logs · Action

List VPC flow logs, optionally filtered by ID or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Flow Log ID (optional)stringLeave blank to list all
Filter by Tags (optional)key_value_array

Returns: tool_result, flow_logs, count

AWS VPC Describe Internet Gateways

aws/vpc/describe_internet_gateways · Action

List internet gateways, optionally filtered by ID or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Internet Gateway IDsstringComma-separated; blank for all (optional)
Filter by Tagskey_value_arrayOnly return gateways with these tags (blank Value matches any value for that key)

Returns: tool_result, internet_gateways, count

AWS IPAM Describe Pools

aws/vpc/describe_ipam_pools · Action

List AWS IPAM pools, optionally filtered by pool id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
IPAM Pool ID (optional)stringLeave blank to list all

Returns: tool_result, ipam_pools, count

AWS IPAM Describe Scopes

aws/vpc/describe_ipam_scopes · Action

List AWS IPAM scopes, optionally filtered by scope id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
IPAM Scope ID (optional)stringLeave blank to list all

Returns: tool_result, ipam_scopes, count

AWS IPAM Describe IPAMs

aws/vpc/describe_ipams · Action

List AWS IPAMs, optionally filtered by IPAM id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
IPAM ID (optional)stringLeave blank to list all

Returns: tool_result, ipams, count

AWS VPC Describe Managed Prefix Lists

aws/vpc/describe_managed_prefix_lists · Action

List managed prefix lists, optionally by id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Prefix List IDs (optional)stringComma-separated; blank lists all
Filter by Tagskey_value_arrayOnly return prefix lists with these tags (blank Value matches any value for that key)

Returns: tool_result, prefix_lists, count

AWS VPC Describe NAT Gateways

aws/vpc/describe_nat_gateways · Action

List NAT gateways, optionally filtered by ID or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
NAT Gateway IDsstringComma-separated; blank for all (optional)
Filter by Tagskey_value_arrayOnly return gateways with these tags (blank Value matches any value for that key)

Returns: tool_result, nat_gateways, count

AWS VPC Describe Network ACLs

aws/vpc/describe_network_acls · Action

List network ACLs, optionally filtered by ID, VPC, or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Network ACL ID (optional)stringLeave blank to list all
VPC ID (optional filter)stringvpc-0abc
Filter by Tags (optional)key_value_array

Returns: tool_result, network_acls, count

AWS VPC Describe Network Insights Analyses

aws/vpc/describe_network_insights_analyses · Action

List Reachability Analyzer analyses, optionally filtered by analysis or path id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Analysis ID (optional)stringLeave blank to list all
Path ID (optional)stringFilter analyses to one path

Returns: tool_result, analyses, count

AWS VPC Describe Network Insights Paths

aws/vpc/describe_network_insights_paths · Action

List Reachability Analyzer paths, optionally filtered by path id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Path ID (optional)stringLeave blank to list all

Returns: tool_result, paths, count

AWS VPC Describe Network Interfaces

aws/vpc/describe_network_interfaces · Action

List elastic network interfaces (ENIs), optionally by id, subnet or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Network Interface IDs (optional)stringComma-separated; blank lists all
Filter by Subnet ID (optional)stringsubnet-0abc
Filter by Tagskey_value_arrayOnly return interfaces with these tags (blank Value matches any value for that key)

Returns: tool_result, network_interfaces, count

AWS VPC Describe Route Tables

aws/vpc/describe_route_tables · Action

List route tables, optionally filtered by id, VPC id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Route Table ID (optional)stringLeave blank to list all
VPC ID (optional)stringFilter by VPC
Filter by Tags (optional)key_value_array

Returns: tool_result, route_tables, count

AWS VPC Describe Subnets

aws/vpc/describe_subnets · Action

List subnets, optionally filtered by subnet id, VPC id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Subnet ID (optional)stringLeave blank to list all
VPC ID (optional)stringFilter by VPC
Filter by Tags (optional)key_value_array

Returns: tool_result, subnets, count

AWS VPC Describe Traffic Mirror Filters

aws/vpc/describe_traffic_mirror_filters · Action

List VPC Traffic Mirror filters, optionally filtered by filter id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Traffic Mirror Filter ID (optional)stringLeave blank to list all
Filter by Tags (optional)key_value_array

Returns: tool_result, filters, count

AWS VPC Describe Traffic Mirror Sessions

aws/vpc/describe_traffic_mirror_sessions · Action

List VPC Traffic Mirror sessions, optionally filtered by session id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Traffic Mirror Session ID (optional)stringLeave blank to list all
Filter by Tags (optional)key_value_array

Returns: tool_result, sessions, count

AWS VPC Describe Traffic Mirror Targets

aws/vpc/describe_traffic_mirror_targets · Action

List VPC Traffic Mirror targets, optionally filtered by target id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Traffic Mirror Target ID (optional)stringLeave blank to list all
Filter by Tags (optional)key_value_array

Returns: tool_result, targets, count

AWS VPC Describe Transit Gateway Multicast Domains

aws/vpc/describe_transit_gateway_multicast_domains · Action

List transit gateway multicast domains, optionally by id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Multicast Domain IDs (optional)stringComma-separated; blank lists all
Filter by Tagskey_value_arrayOnly return domains with these tags (blank Value matches any value for that key)

Returns: tool_result, multicast_domains, count

AWS VPC Describe Transit Gateway Peering Attachments

aws/vpc/describe_transit_gateway_peering_attachments · Action

List transit gateway peering attachments, optionally by id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Attachment IDs (optional)stringComma-separated; blank lists all
Filter by Tagskey_value_arrayOnly return attachments with these tags (blank Value matches any value for that key)

Returns: tool_result, attachments, count

AWS VPC Describe Transit Gateway Route Tables

aws/vpc/describe_transit_gateway_route_tables · Action

List transit gateway route tables, optionally by id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Route Table IDs (optional)stringComma-separated; blank lists all
Filter by Tagskey_value_arrayOnly return route tables with these tags (blank Value matches any value for that key)

Returns: tool_result, route_tables, count

AWS VPC Describe Transit Gateway VPC Attachments

aws/vpc/describe_transit_gateway_vpc_attachments · Action

List transit gateway VPC attachments, optionally by id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Attachment IDs (optional)stringComma-separated; blank lists all
Filter by Tagskey_value_arrayOnly return attachments with these tags (blank Value matches any value for that key)

Returns: tool_result, attachments, count

AWS VPC Describe Transit Gateways

aws/vpc/describe_transit_gateways · Action

List transit gateways, optionally by id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway IDs (optional)stringComma-separated; blank lists all
Filter by Tagskey_value_arrayOnly return gateways with these tags (blank Value matches any value for that key)

Returns: tool_result, transit_gateways, count

AWS VPC Describe Endpoint Connections

aws/vpc/describe_vpc_endpoint_connections · Action

List consumer connections to the VPC endpoint services you own.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Service ID (optional)stringvpce-svc-0abc; blank lists all
Filter by Tags (optional)key_value_array

Returns: tool_result, connections, count

AWS VPC Describe Endpoint Service Configurations

aws/vpc/describe_vpc_endpoint_service_configurations · Action

List the VPC endpoint services you own, optionally filtered by ID or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Service IDs (optional)stringComma-separated; blank lists all
Filter by Tags (optional)key_value_array

Returns: tool_result, services, count

AWS VPC Describe Endpoint Service Permissions

aws/vpc/describe_vpc_endpoint_service_permissions · Action

List the principals allowed to connect to a VPC endpoint service you own.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Service IDstringRequiredvpce-svc-0abc

Returns: tool_result, allowed_principals, count

AWS VPC Describe Endpoint Services

aws/vpc/describe_vpc_endpoint_services · Action

Discover VPC endpoint services you can consume (finds the service_name to connect to).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Service Names (optional)stringComma-separated, e.g. com.amazonaws.eu-west-2.s3
Filter by Tags (optional)key_value_array

Returns: tool_result, service_names, services, count

AWS VPC Describe VPC Endpoints

aws/vpc/describe_vpc_endpoints · Action

List VPC endpoints, optionally filtered by ID or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC Endpoint ID (optional)stringLeave blank to list all
Filter by Tags (optional)key_value_array

Returns: tool_result, vpc_endpoints, count

AWS VPC Describe Peering Connections

aws/vpc/describe_vpc_peering_connections · Action

List VPC peering connections, optionally by id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC Peering Connection IDs (optional)stringComma-separated; blank lists all
Filter by Tagskey_value_arrayOnly return connections with these tags (blank Value matches any value for that key)

Returns: tool_result, vpc_peering_connections, count

AWS VPC Describe VPCs

aws/vpc/describe_vpcs · Action

List Amazon VPCs, optionally filtered by VPC id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC ID (optional)stringLeave blank to list all
Filter by Tags (optional)key_value_array

Returns: tool_result, vpcs, count

AWS VPC Describe VPN Connections

aws/vpc/describe_vpn_connections · Action

List Site-to-Site VPN connections, optionally filtered by id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPN Connection ID (optional)stringLeave blank to list all
Filter by Tags (optional)key_value_array

Returns: tool_result, vpn_connections, count

AWS VPC Describe VPN Gateways

aws/vpc/describe_vpn_gateways · Action

List virtual private gateways, optionally filtered by id or tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPN Gateway ID (optional)stringLeave blank to list all
Filter by Tags (optional)key_value_array

Returns: tool_result, vpn_gateways, count

11Detach

AWS VPC Detach Internet Gateway

aws/vpc/detach_internet_gateway · Action

Detach an internet gateway from a VPC.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Internet Gateway IDstringRequiredigw-0abc123
VPC IDstringRequiredvpc-0abc123

Returns: tool_result

AWS VPC Detach Network Interface

aws/vpc/detach_network_interface · Action

Detach an elastic network interface (ENI) from an instance by attachment id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Attachment IDstringRequiredeni-attach-0abc
Force Detachboolean

Returns: tool_result

AWS VPC Detach VPN Gateway

aws/vpc/detach_vpn_gateway · Action

Detach a virtual private gateway from a VPC.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPN Gateway IDstringRequiredvgw-0abc123
VPC IDstringRequiredvpc-0abc123

Returns: tool_result

12Disable

AWS VPC Disable Transit Gateway Route Table Propagation

aws/vpc/disable_transit_gateway_route_table_propagation · Action

Disable route propagation from an attachment into a route table.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Route Table IDstringRequiredtgw-rtb-0123456789abcdef0
Transit Gateway Attachment IDstringRequiredtgw-attach-0123456789abcdef0

Returns: tool_result, propagation

13Disassociate

AWS VPC Disassociate Address

aws/vpc/disassociate_address · Action

Disassociate an Elastic IP address by association ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Association IDstringRequiredeipassoc-0abc123

Returns: tool_result

AWS VPC Disassociate Client VPN Target Network

aws/vpc/disassociate_client_vpn_target_network · Action

Remove a target network association from an AWS Client VPN endpoint.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Client VPN Endpoint IDstringRequiredcvpn-endpoint-0abc123
Association IDstringRequiredcvpn-assoc-0abc123

Returns: tool_result, status

AWS VPC Disassociate NAT Gateway Address

aws/vpc/disassociate_nat_gateway_address · Action

Disassociate secondary Elastic IP addresses from a public NAT gateway.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
NAT Gateway IDstringRequirednat-0abc123
Address Association IDsstringRequiredComma-separated, e.g. eipassoc-0abc,eipassoc-0def

Returns: tool_result

AWS VPC Disassociate Route Table

aws/vpc/disassociate_route_table · Action

Remove a route table association by its association id.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Association IDstringRequiredrtbassoc-0abc...

Returns: tool_result

AWS VPC Disassociate Transit Gateway Route Table

aws/vpc/disassociate_transit_gateway_route_table · Action

Disassociate a transit gateway attachment from a route table.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Route Table IDstringRequiredtgw-rtb-0123456789abcdef0
Transit Gateway Attachment IDstringRequiredtgw-attach-0123456789abcdef0

Returns: tool_result, association

AWS VPC Disassociate CIDR Block

aws/vpc/disassociate_vpc_cidr_block · Action

Remove a secondary IPv4 or IPv6 CIDR block association from a VPC.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
CIDR Association IDstringRequiredvpc-cidr-assoc-0abc...

Returns: tool_result

14Enable

AWS VPC Enable Transit Gateway Route Table Propagation

aws/vpc/enable_transit_gateway_route_table_propagation · Action

Enable route propagation from an attachment into a route table.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Route Table IDstringRequiredtgw-rtb-0123456789abcdef0
Transit Gateway Attachment IDstringRequiredtgw-attach-0123456789abcdef0

Returns: tool_result, propagation

15Export

AWS VPC Export Client VPN Client Configuration

aws/vpc/export_client_vpn_client_configuration · Action

Export the OpenVPN client configuration for an AWS Client VPN endpoint.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Client VPN Endpoint IDstringRequiredcvpn-endpoint-0abc123

Returns: tool_result, configuration

16Get

AWS IPAM Get Pool Allocations

aws/vpc/get_ipam_pool_allocations · Action

List the CIDR allocations within an IPAM pool.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
IPAM Pool IDstringRequired

Returns: tool_result, allocations, count

AWS IPAM Get Pool CIDRs

aws/vpc/get_ipam_pool_cidrs · Action

List the CIDRs provisioned to an IPAM pool.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
IPAM Pool IDstringRequired

Returns: tool_result, cidrs, count

AWS VPC Get Managed Prefix List Associations

aws/vpc/get_managed_prefix_list_associations · Action

List the resources that reference a managed prefix list.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Prefix List IDstringRequiredpl-0abc...

Returns: tool_result, associations, count

AWS VPC Get Managed Prefix List Entries

aws/vpc/get_managed_prefix_list_entries · Action

List the CIDR entries of a managed prefix list.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Prefix List IDstringRequiredpl-0abc...

Returns: tool_result, entries, count

17Modify

AWS VPC Modify Client VPN Endpoint

aws/vpc/modify_client_vpn_endpoint · Action

Update an AWS Client VPN endpoint's description or server certificate.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Client VPN Endpoint IDstringRequiredcvpn-endpoint-0abc123
Description (optional)string
Server Certificate ARN (optional)stringarn:aws:acm:...:certificate/...

Returns: tool_result, success

AWS IPAM Modify IPAM

aws/vpc/modify_ipam · Action

Modify an AWS IPAM's description or operating Regions.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
IPAM IDstringRequired
Description (optional)string
Add Operating Regions (optional)stringus-east-1,eu-west-1
Remove Operating Regions (optional)stringus-east-1

Returns: tool_result, ipam

AWS IPAM Modify Pool

aws/vpc/modify_ipam_pool · Action

Modify an AWS IPAM pool's description or auto-import setting.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
IPAM Pool IDstringRequired
Description (optional)string
Auto Import (leave unset to keep current)boolean

Returns: tool_result, ipam_pool

AWS VPC Modify Managed Prefix List

aws/vpc/modify_managed_prefix_list · Action

Rename a managed prefix list, or add/remove CIDR entries.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Prefix List IDstringRequiredpl-0abc...
New Name (optional)stringLeave blank to keep current name
Add Entries (optional)textJSON array e.g. [{"cidr":"10.0.0.0/16","description":"HQ"}]
Remove Entries (optional)textJSON array e.g. [{"cidr":"10.0.0.0/16"}]
Current Version (optional)integerRequired when adding or removing entries

Returns: tool_result, prefix_list

AWS VPC Modify Network Interface Attribute

aws/vpc/modify_network_interface_attribute · Action

Modify an ENI's description, source/dest check, or security groups.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Network Interface IDstringRequiredeni-0abc...
Description (optional)stringe.g. App server ENI
Source/Dest Checkstringchoices: Leave unchanged, Enable, Disable
Security Group IDs (optional)stringComma-separated, e.g. sg-0abc,sg-0def

Returns: tool_result, network_interface_id

AWS VPC Modify Subnet Attribute

aws/vpc/modify_subnet_attribute · Action

Toggle auto-assign public IPv4 or IPv6 address on launch for a subnet.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Subnet IDstringRequiredsubnet-0abc...
Auto-assign Public IPv4 on Launchstringchoices: Leave unchanged, Enable, Disable
Auto-assign IPv6 on Creationstringchoices: Leave unchanged, Enable, Disable

Returns: tool_result

AWS VPC Modify Traffic Mirror Session

aws/vpc/modify_traffic_mirror_session · Action

Update a VPC Traffic Mirror session's number, packet length, or description.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Traffic Mirror Session IDstringRequiredtms-0abc
Session Number (optional)integer1-32766
Packet Length (optional)integerBytes to mirror after the VXLAN header
Description (optional)string

Returns: tool_result, session, traffic_mirror_session_id

AWS VPC Modify Transit Gateway

aws/vpc/modify_transit_gateway · Action

Update a transit gateway's description.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway IDstringRequiredtgw-0abc
Description (optional)stringNew description

Returns: tool_result, transit_gateway

AWS VPC Modify Transit Gateway VPC Attachment

aws/vpc/modify_transit_gateway_vpc_attachment · Action

Add or remove subnets on a transit gateway VPC attachment.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Attachment IDstringRequiredtgw-attach-0123456789abcdef0
Subnet IDs to Add (optional)stringComma-separated; one subnet per Availability Zone
Subnet IDs to Remove (optional)stringComma-separated

Returns: tool_result, attachment

AWS VPC Modify VPC Attribute

aws/vpc/modify_vpc_attribute · Action

Enable or disable DNS support and DNS hostnames on a VPC.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC IDstringRequiredvpc-0abc...
Enable DNS Supportstringchoices: Leave unchanged, Enable, Disable
Enable DNS Hostnamesstringchoices: Leave unchanged, Enable, Disable

Returns: tool_result

AWS VPC Modify VPC Endpoint

aws/vpc/modify_vpc_endpoint · Action

Modify a VPC endpoint's route tables, subnets, or private DNS setting.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC Endpoint IDstringRequiredvpce-0abc
Add Route Table IDsstringComma-separated, e.g. rtb-0abc
Remove Route Table IDsstringComma-separated, e.g. rtb-0abc
Add Subnet IDsstringComma-separated, e.g. subnet-0abc
Remove Subnet IDsstringComma-separated, e.g. subnet-0abc
Enable Private DNS (optional)boolean

Returns: tool_result

AWS VPC Modify Endpoint Service Configuration

aws/vpc/modify_vpc_endpoint_service_configuration · Action

Change a VPC endpoint service: acceptance, load balancers or private DNS name.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Service IDstringRequiredvpce-svc-0abc
Require Acceptance (optional)boolean
Add Network Load Balancer ARNs (optional)stringComma-separated NLB ARNs
Remove Network Load Balancer ARNs (optional)stringComma-separated NLB ARNs
Private DNS Name (optional)stringservice.example.com

Returns: tool_result, success

AWS VPC Modify Endpoint Service Permissions

aws/vpc/modify_vpc_endpoint_service_permissions · Action

Add or remove principals allowed to connect to a VPC endpoint service you own.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Service IDstringRequiredvpce-svc-0abc
Add Allowed Principals (optional)stringComma-separated ARNs, e.g. arn:aws:iam::123456789012:root
Remove Allowed Principals (optional)stringComma-separated ARNs

Returns: tool_result, success

AWS VPC Modify Peering Connection Options

aws/vpc/modify_vpc_peering_connection_options · Action

Change the DNS resolution options of a VPC peering connection (requester/accepter).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC Peering Connection IDstringRequiredpcx-0abc123
Requester: Allow DNS Resolution from Remote VPC (optional)boolean
Accepter: Allow DNS Resolution from Remote VPC (optional)boolean

Returns: tool_result

AWS VPC Modify Tenancy

aws/vpc/modify_vpc_tenancy · Action

Change a VPC's instance tenancy attribute back to default.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC IDstringRequiredvpc-0abc...
Instance TenancystringRequiredchoices: Default

Returns: tool_result

AWS VPC Modify VPN Connection

aws/vpc/modify_vpn_connection · Action

Change the target gateway (transit, VPN, or customer) of a Site-to-Site VPN connection.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPN Connection IDstringRequiredvpn-0abc123
Transit Gateway ID (optional)stringtgw-0abc123
VPN Gateway ID (optional)stringvgw-0abc123
Customer Gateway ID (optional)stringcgw-0abc123

Returns: tool_result, vpn_connection, vpn_connection_id

AWS VPC Modify VPN Connection Options

aws/vpc/modify_vpn_connection_options · Action

Change the local/remote IPv4 network CIDRs of a Site-to-Site VPN connection.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPN Connection IDstringRequiredvpn-0abc123
Local IPv4 Network CIDR (optional)string10.0.0.0/16 — customer gateway side
Remote IPv4 Network CIDR (optional)string172.16.0.0/16 — Amazon side

Returns: tool_result, vpn_connection, vpn_connection_id

AWS VPC Modify VPN Tunnel Options

aws/vpc/modify_vpn_tunnel_options · Action

Modify the IPSec options of a single tunnel in a Site-to-Site VPN connection.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPN Connection IDstringRequiredvpn-0abc123
Tunnel Outside IP AddressstringRequired203.0.113.10 — external IP of the tunnel to modify
Tunnel OptionstextRequiredJSON object e.g. {"pre_shared_key":"...","phase1_lifetime_seconds":28800,"phase2_lifetime_seconds":3600}

Returns: tool_result, vpn_connection, vpn_connection_id

18Provision

AWS IPAM Provision Pool CIDR

aws/vpc/provision_ipam_pool_cidr · Action

Provision a CIDR to an IPAM pool by CIDR or netmask length.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
IPAM Pool IDstringRequired
CIDR (optional)string10.0.0.0/16
Netmask Length (optional)integer16

Returns: tool_result, cidr

19Reject

AWS VPC Reject Transit Gateway Peering Attachment

aws/vpc/reject_transit_gateway_peering_attachment · Action

Reject a pending transit gateway peering attachment request.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Attachment IDstringRequiredtgw-attach-0123456789abcdef0

Returns: tool_result, attachment

AWS VPC Reject Transit Gateway VPC Attachment

aws/vpc/reject_transit_gateway_vpc_attachment · Action

Reject a pending cross-account transit gateway VPC attachment.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Attachment IDstringRequiredtgw-attach-0123456789abcdef0

Returns: tool_result, attachment

AWS VPC Reject Endpoint Connections

aws/vpc/reject_vpc_endpoint_connections · Action

Reject consumer connection requests to a VPC endpoint service you own.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Service IDstringRequiredvpce-svc-0abc
VPC Endpoint IDsstringRequiredComma-separated, e.g. vpce-0abc,vpce-0def

Returns: tool_result, unsuccessful, success

AWS VPC Reject Peering Connection

aws/vpc/reject_vpc_peering_connection · Action

Reject a pending VPC peering connection request.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
VPC Peering Connection IDstringRequiredpcx-0abc123

Returns: tool_result

20Release

AWS VPC Release Address

aws/vpc/release_address · Action

Release an Elastic IP address by allocation ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Allocation IDstringRequiredeipalloc-0abc123

Returns: tool_result

AWS IPAM Release Pool Allocation

aws/vpc/release_ipam_pool_allocation · Action

Release a CIDR allocation back to an IPAM pool.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
IPAM Pool IDstringRequired
IPAM Pool Allocation IDstringRequired
CIDRstringRequired10.0.0.0/24

Returns: tool_result, success

21Replace

AWS VPC Replace Network ACL Association

aws/vpc/replace_network_acl_association · Action

Associate a different network ACL with an existing subnet association.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Association IDstringRequiredaclassoc-0abc...
New Network ACL IDstringRequiredacl-0abc...

Returns: tool_result, new_association_id

AWS VPC Replace Network ACL Entry

aws/vpc/replace_network_acl_entry · Action

Replace an existing inbound or outbound rule in a network ACL.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Network ACL IDstringRequiredacl-0abc
Rule NumberintegerRequired100 (1-32766, processed ascending)
Protocol NumberstringRequired6 = TCP, 17 = UDP, -1 = all
Rule ActionstringRequiredchoices: Allow, Deny
Egress (outbound rule)booleanRequired
CIDR BlockstringRequired0.0.0.0/0
Port From (optional)integerFor TCP/UDP, e.g. 80
Port To (optional)integerFor TCP/UDP, e.g. 80

Returns: tool_result

AWS VPC Replace Route

aws/vpc/replace_route · Action

Replace an existing route in a route table with a new target.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Route Table IDstringRequiredrtb-0abc...
Destination CIDR BlockstringRequired0.0.0.0/0
Target TypestringRequiredchoices: Internet Gateway, NAT Gateway, Network Interface, VPC Peering Connection, Transit Gateway, Egress-only Internet Gateway
Target IDstringRequiredigw-0abc... / nat-... / eni-... etc

Returns: tool_result

AWS VPC Replace Route Table Association

aws/vpc/replace_route_table_association · Action

Associate a different route table with an existing subnet association.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Association IDstringRequiredrtbassoc-0abc...
New Route Table IDstringRequiredrtb-0abc...

Returns: tool_result, new_association_id

AWS VPC Replace Transit Gateway Route

aws/vpc/replace_transit_gateway_route · Action

Replace an existing route in a transit gateway route table.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Transit Gateway Route Table IDstringRequiredtgw-rtb-0123456789abcdef0
Destination CIDR BlockstringRequired10.1.0.0/16
Transit Gateway Attachment ID (optional)stringNew target attachment; omit for a blackhole route
BlackholebooleanDrop traffic matching this route

Returns: tool_result, route

22Revoke

AWS VPC Revoke Client VPN Ingress

aws/vpc/revoke_client_vpn_ingress · Action

Remove an ingress authorization rule from an AWS Client VPN endpoint.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Client VPN Endpoint IDstringRequiredcvpn-endpoint-0abc123
Target Network CIDRstringRequired10.0.0.0/16
Access Group ID (optional)string
Revoke All Groups (optional)boolean

Returns: tool_result, status

23Start

AWS VPC Start Network Insights Analysis

aws/vpc/start_network_insights_analysis · Action

Run a Reachability Analyzer analysis for a network insights path.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Path IDstringRequired
Tagskey_value_array

Returns: tool_result, analysis, network_insights_analysis_id

24Unassign

AWS VPC Unassign IPv6 Addresses

aws/vpc/unassign_ipv6_addresses · Action

Remove IPv6 addresses from a network interface.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Network Interface IDstringRequiredeni-0abc...
IPv6 AddressesstringRequiredComma-separated, e.g. 2001:db8::1,2001:db8::2

Returns: tool_result, network_interface_id

AWS VPC Unassign Private IP Addresses

aws/vpc/unassign_private_ip_addresses · Action

Remove secondary private IPv4 addresses from a network interface.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Network Interface IDstringRequiredeni-0abc...
Private IP AddressesstringRequiredComma-separated, e.g. 10.0.1.10,10.0.1.11

Returns: tool_result, network_interface_id

25Notes & Limitations

Behaviours and constraints worth knowing before you build with these nodes.

  • NAT gateways, VPN connections, and interface VPC endpoints are provisioned asynchronously and initially report a lifecycle state of pending, whereas internet gateways are created and attached immediately.
  • Each connection is scoped to a single AWS Region, which is a required setting, because VPC resources are Region-specific.
  • AWS APIs are eventually consistent, so a newly created or modified resource may not appear immediately in subsequent reads.
  • A resource cannot be deleted until all of its dependent resources have been removed first.
  • A VPC peering connection must be accepted before it becomes active.