- Support
- Integrations
- VPC
VPC
AWS integration · 182 node(s).
00Overview
Build and operate Amazon VPC networks straight from a flow: create VPCs, subnets, route tables and gateways, wire up NAT, internet and egress-only gateways, and control traffic with network ACLs, prefix lists and flow logs. Connect networks together through VPC peering, transit gateways, PrivateLink endpoints and Site-to-Site or Client VPN, and hand out addresses with Elastic IPs and IPAM pools. Describe actions let a flow read the live state of any of these, so it can make a decision and drive the next step.
Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.
01Connecting VPC
- In the node's Authentication dropdown, choose how Flomation signs in: Access Keys (your own IAM user keys), Assume Role (cross-account) (Flomation's principal assumes a role in your account), or Managed Role (Credential) (a role credential already stored in Flomation).
- For Access Keys, open the AWS console at IAM → Users, pick or create a user, and under Security credentials choose Create access key; paste the two values into AWS Access Key and AWS Secret Key, and leave Session Token (optional) blank unless you are using temporary STS credentials.
- For Assume Role (cross-account), create a role under IAM → Roles whose trust policy lets Flomation's principal call
sts:AssumeRole, then paste its ARN into Role ARN to Assume — and, if the trust policy requires one, add the matching Assume Role External ID (optional). - Set Region to the AWS Region your network lives in (for example
eu-west-2) — the node only acts within that Region. - Store the secret value as a Flomation environment secret (e.g.
vpc_secret) and select it in the node's AWS Secret Key field; for the Managed Role (Credential) method, pick your stored credential in the AWS Role Credential field instead.
| Field | Type | Details | |
|---|---|---|---|
| Authentication | string | Required | Access Keys, Assume Role (cross-account), Managed Role (Credential) |
| AWS Access Key | secret | Required | |
| AWS Secret Key | secret | Required | |
| Session Token (optional) | secret | ||
| AWS Role Credential | credential | Required |
Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.
02Accept
AWS VPC Accept Transit Gateway Peering Attachment
aws/vpc/accept_transit_gateway_peering_attachment · Action
Accept a pending transit gateway peering attachment request.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Attachment ID | string | Required | tgw-attach-0123456789abcdef0 |
Returns: tool_result, attachment
AWS VPC Accept Transit Gateway VPC Attachment
aws/vpc/accept_transit_gateway_vpc_attachment · Action
Accept a pending cross-account transit gateway VPC attachment.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Attachment ID | string | Required | tgw-attach-0123456789abcdef0 |
Returns: tool_result, attachment
AWS VPC Accept Endpoint Connections
aws/vpc/accept_vpc_endpoint_connections · Action
Accept consumer connection requests to a VPC endpoint service you own.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Service ID | string | Required | vpce-svc-0abc |
| VPC Endpoint IDs | string | Required | Comma-separated, e.g. vpce-0abc,vpce-0def |
Returns: tool_result, unsuccessful, success
AWS VPC Accept Peering Connection
aws/vpc/accept_vpc_peering_connection · Action
Accept a pending VPC peering connection request.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC Peering Connection ID | string | Required | pcx-0abc |
Returns: tool_result, vpc_peering_connection
03Allocate
AWS VPC Allocate Address
aws/vpc/allocate_address · Action
Allocate a new Elastic IP address.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Domain | string | choices: VPC, Standard (EC2-Classic) | |
| Tags | key_value_array | Optional tags to apply to the Elastic IP |
Returns: tool_result, address, allocation_id
AWS IPAM Allocate Pool CIDR
aws/vpc/allocate_ipam_pool_cidr · Action
Allocate a CIDR from an IPAM pool by CIDR or netmask length.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| IPAM Pool ID | string | Required | |
| CIDR (optional) | string | 10.0.0.0/24 | |
| Netmask Length (optional) | integer | 24 | |
| Description (optional) | string |
Returns: tool_result, allocation, ipam_pool_allocation_id
04Assign
AWS VPC Assign IPv6 Addresses
aws/vpc/assign_ipv6_addresses · Action
Assign IPv6 addresses to a network interface.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Network Interface ID | string | Required | eni-0abc... |
| IPv6 Addresses (optional) | string | Comma-separated, e.g. 2001:db8::1,2001:db8::2 | |
| IPv6 Address Count (optional) | integer | e.g. 2 |
Returns: tool_result, assigned_ipv6_addresses, network_interface_id
AWS VPC Assign Private IP Addresses
aws/vpc/assign_private_ip_addresses · Action
Assign secondary private IPv4 addresses to a network interface.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Network Interface ID | string | Required | eni-0abc... |
| Private IP Addresses (optional) | string | Comma-separated, e.g. 10.0.1.10,10.0.1.11 | |
| Secondary IP Count (optional) | integer | e.g. 2 |
Returns: tool_result, assigned_private_ip_addresses, network_interface_id
05Associate
AWS VPC Associate Address
aws/vpc/associate_address · Action
Associate an Elastic IP with an instance or network interface.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Allocation ID | string | Required | eipalloc-0abc123 |
| Instance ID | string | i-0abc123 (instance or network interface required) | |
| Network Interface ID | string | eni-0abc123 (instance or network interface required) | |
| Private IP Address | string | Optional, when the interface has multiple private IPs |
Returns: tool_result, association_id
AWS VPC Associate Client VPN Target Network
aws/vpc/associate_client_vpn_target_network · Action
Associate a target subnet with an AWS Client VPN endpoint.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Client VPN Endpoint ID | string | Required | cvpn-endpoint-0abc123 |
| Subnet ID | string | Required | subnet-0abc123 |
Returns: tool_result, association_id, status
AWS VPC Associate DHCP Options
aws/vpc/associate_dhcp_options · Action
Associate a DHCP options set with a VPC, or 'default' to reset it.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| DHCP Options ID | string | Required | dopt-0abc (or 'default' to reset) |
| VPC ID | string | Required | vpc-0abc |
Returns: tool_result
AWS VPC Associate NAT Gateway Address
aws/vpc/associate_nat_gateway_address · Action
Associate Elastic IP allocations (secondary addresses) with a public NAT gateway.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| NAT Gateway ID | string | Required | nat-0abc123 |
| Elastic IP Allocation IDs | string | Required | Comma-separated, e.g. eipalloc-0abc,eipalloc-0def |
Returns: tool_result, nat_gateway, nat_gateway_id
AWS VPC Associate Route Table
aws/vpc/associate_route_table · Action
Associate a route table with a subnet or gateway.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Route Table ID | string | Required | rtb-0abc... |
| Subnet ID (optional) | string | subnet-0abc... | |
| Gateway ID (optional) | string | igw-0abc... |
Returns: tool_result, association_id
AWS VPC Associate Transit Gateway Route Table
aws/vpc/associate_transit_gateway_route_table · Action
Associate a transit gateway attachment with a route table.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Route Table ID | string | Required | tgw-rtb-0123456789abcdef0 |
| Transit Gateway Attachment ID | string | Required | tgw-attach-0123456789abcdef0 |
Returns: tool_result, association
AWS VPC Associate CIDR Block
aws/vpc/associate_vpc_cidr_block · Action
Associate a secondary IPv4 or IPv6 CIDR block with a VPC.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC ID | string | Required | vpc-0abc... |
| Secondary IPv4 CIDR Block (optional) | string | 10.1.0.0/16 | |
| Request Amazon-provided IPv6 CIDR | boolean | ||
| IPv6 CIDR Block (optional) | string | 2600:1f16:...::/56 |
Returns: tool_result, cidr_association
06Attach
AWS VPC Attach Internet Gateway
aws/vpc/attach_internet_gateway · Action
Attach an internet gateway to a VPC.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Internet Gateway ID | string | Required | igw-0abc123 |
| VPC ID | string | Required | vpc-0abc123 |
Returns: tool_result
AWS VPC Attach Network Interface
aws/vpc/attach_network_interface · Action
Attach an elastic network interface (ENI) to an EC2 instance.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Network Interface ID | string | Required | eni-0abc |
| Instance ID | string | Required | i-0abc |
| Device Index | integer | Required | e.g. 1 (0 is the primary interface) |
Returns: tool_result, attachment_id
AWS VPC Attach VPN Gateway
aws/vpc/attach_vpn_gateway · Action
Attach a virtual private gateway to a VPC.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPN Gateway ID | string | Required | vgw-0abc123 |
| VPC ID | string | Required | vpc-0abc123 |
Returns: tool_result, state
07Authorize
AWS VPC Authorize Client VPN Ingress
aws/vpc/authorize_client_vpn_ingress · Action
Add an ingress authorization rule to an AWS Client VPN endpoint.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Client VPN Endpoint ID | string | Required | cvpn-endpoint-0abc123 |
| Target Network CIDR | string | Required | 10.0.0.0/16 |
| Authorize All Groups (optional) | boolean | ||
| Access Group ID (optional) | string | Required unless authorizing all groups | |
| Description (optional) | string |
Returns: tool_result, status
08Create
AWS VPC Create Client VPN Endpoint
aws/vpc/create_client_vpn_endpoint · Action
Create an AWS Client VPN endpoint for remote users to connect via a VPN client.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Client CIDR Block | string | Required | 10.0.0.0/22 (min /22, max /12) |
| Server Certificate ARN | string | Required | arn:aws:acm:...:certificate/... |
| Authentication Type | string | Required | choices: Mutual (Certificate), Active Directory, Federated (SAML) |
| Client Root Certificate Chain ARN (for certificate auth) | string | arn:aws:acm:...:certificate/... | |
| Enable Connection Logging | boolean | Required | |
| CloudWatch Log Group (if logging enabled) | string | ||
| VPC ID (optional) | string | vpc-0abc123 | |
| Description (optional) | string | ||
| Tags | key_value_array |
Returns: tool_result, endpoint, client_vpn_endpoint_id
AWS VPC Create Client VPN Route
aws/vpc/create_client_vpn_route · Action
Add a route to an AWS Client VPN endpoint's route table.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Client VPN Endpoint ID | string | Required | cvpn-endpoint-0abc123 |
| Destination CIDR Block | string | Required | 0.0.0.0/0 |
| Target VPC Subnet ID | string | Required | subnet-0abc123 |
| Description (optional) | string |
Returns: tool_result, status
AWS VPC Create Customer Gateway
aws/vpc/create_customer_gateway · Action
Register a customer gateway (the on-premises end of a Site-to-Site VPN).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPN Type | string | Required | choices: ipsec.1 |
| BGP ASN (optional) | integer | 65000 | |
| Outside IP Address (optional) | string | 203.0.113.10 | |
| Certificate ARN (optional) | string | ||
| Device Name (optional) | string | ||
| Tags | key_value_array |
Returns: tool_result, customer_gateway, customer_gateway_id
AWS VPC Create DHCP Options
aws/vpc/create_dhcp_options · Action
Create a DHCP options set with domain name, DNS, and NTP servers.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Domain Name (optional) | string | example.internal | |
| DNS Servers (optional) | string | Comma-separated, e.g. 10.0.0.2,AmazonProvidedDNS | |
| NTP Servers (optional) | string | Comma-separated, e.g. 169.254.169.123 | |
| Tags | key_value_array |
Returns: tool_result, dhcp_options, dhcp_options_id
AWS VPC Create Egress-Only Internet Gateway
aws/vpc/create_egress_only_internet_gateway · Action
Create an egress-only internet gateway for outbound IPv6 traffic in a VPC.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC ID | string | Required | vpc-0abc |
| Tags | key_value_array |
Returns: tool_result, egress_only_internet_gateway, egress_only_internet_gateway_id
AWS VPC Create Flow Logs
aws/vpc/create_flow_logs · Action
Create flow logs capturing traffic for a VPC, subnet, or network interface.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Resource IDs | string | Required | Comma-separated, e.g. vpc-0abc,subnet-0def |
| Resource Type | string | Required | choices: VPC, Subnet, Network Interface |
| Traffic Type | string | Required | choices: Accept, Reject, All |
| Log Destination Type | string | choices: CloudWatch Logs, S3 | |
| CloudWatch Log Group Name | string | /vpc/flow-logs | |
| S3 Destination ARN | string | arn:aws:s3:::my-bucket/prefix/ | |
| IAM Role ARN (for CloudWatch Logs) | string | arn:aws:iam::<account>:role/flow-logs | |
| Tags | key_value_array |
Returns: tool_result, flow_logs, flow_log_id
AWS VPC Create Internet Gateway
aws/vpc/create_internet_gateway · Action
Create a new internet gateway, optionally with tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Tags | key_value_array | Optional tags to apply to the internet gateway |
Returns: tool_result, internet_gateway, internet_gateway_id
AWS IPAM Create IPAM
aws/vpc/create_ipam · Action
Create an AWS IPAM (IP Address Manager) with operating Regions and tier.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Description (optional) | string | ||
| Operating Regions | string | Required | eu-west-2,us-east-1 |
| Tier | string | choices: Free, Advanced | |
| Tags | key_value_array |
Returns: tool_result, ipam, ipam_id
AWS IPAM Create Pool
aws/vpc/create_ipam_pool · Action
Create an IPAM pool within a scope for allocating CIDRs.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| IPAM Scope ID | string | Required | |
| Address Family | string | Required | choices: IPv4, IPv6 |
| Source IPAM Pool ID (optional) | string | ||
| Description (optional) | string | ||
| Auto Import | boolean | ||
| Locale (optional) | string | eu-west-2 | |
| Tags | key_value_array |
Returns: tool_result, ipam_pool, ipam_pool_id
AWS IPAM Create Scope
aws/vpc/create_ipam_scope · Action
Create a private IPAM scope within an AWS IPAM.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| IPAM ID | string | Required | |
| Description (optional) | string | ||
| Tags | key_value_array |
Returns: tool_result, ipam_scope, ipam_scope_id
AWS VPC Create Managed Prefix List
aws/vpc/create_managed_prefix_list · Action
Create a customer-managed prefix list of CIDR entries.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Prefix List Name | string | Required | office-networks |
| Maximum Entries | integer | Required | The maximum number of CIDR entries the list can hold |
| Address Family | string | Required | choices: IPv4, IPv6 |
| Entries (optional) | text | JSON array e.g. [{"cidr":"10.0.0.0/16","description":"HQ"}] | |
| Tags | key_value_array |
Returns: tool_result, prefix_list, prefix_list_id
AWS VPC Create NAT Gateway
aws/vpc/create_nat_gateway · Action
Create a NAT gateway in a subnet (public with an EIP, or private).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Subnet ID | string | Required | subnet-0abc123 |
| Elastic IP Allocation ID | string | eipalloc-0abc (required for a public NAT gateway) | |
| Connectivity Type | string | choices: Public, Private | |
| Tags | key_value_array | Optional tags to apply to the NAT gateway |
Returns: tool_result, nat_gateway, nat_gateway_id
AWS VPC Create Network ACL
aws/vpc/create_network_acl · Action
Create a network ACL in a VPC. Rules are added separately via create entry.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC ID | string | Required | vpc-0abc |
| Tags | key_value_array |
Returns: tool_result, network_acl, network_acl_id
AWS VPC Create Network ACL Entry
aws/vpc/create_network_acl_entry · Action
Add an inbound or outbound rule to a network ACL.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Network ACL ID | string | Required | acl-0abc |
| Rule Number | integer | Required | 100 (1-32766, processed ascending) |
| Protocol Number | string | Required | 6 = TCP, 17 = UDP, -1 = all |
| Rule Action | string | Required | choices: Allow, Deny |
| Egress (outbound rule) | boolean | Required | |
| CIDR Block | string | Required | 0.0.0.0/0 |
| Port From (optional) | integer | For TCP/UDP, e.g. 80 | |
| Port To (optional) | integer | For TCP/UDP, e.g. 80 |
Returns: tool_result
AWS VPC Create Network Insights Path
aws/vpc/create_network_insights_path · Action
Create a Reachability Analyzer path between a source and destination resource.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Source | string | Required | Resource ID or ARN (e.g. igw-0abc... or an instance ID) |
| Destination (optional) | string | Resource ID or ARN | |
| Protocol | string | Required | choices: TCP, UDP |
| Destination Port (optional) | integer | ||
| Tags | key_value_array |
Returns: tool_result, path, network_insights_path_id
AWS VPC Create Network Interface
aws/vpc/create_network_interface · Action
Create an elastic network interface (ENI) in a subnet.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Subnet ID | string | Required | subnet-0abc |
| Description (optional) | string | e.g. App server ENI | |
| Private IP Address (optional) | string | e.g. 10.0.1.10 | |
| Security Group IDs (optional) | string | Comma-separated, e.g. sg-0abc,sg-0def | |
| Tags | key_value_array |
Returns: tool_result, network_interface, network_interface_id
AWS VPC Create Route
aws/vpc/create_route · Action
Add a route to a route table pointing at a gateway or other target.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Route Table ID | string | Required | rtb-0abc... |
| Destination CIDR Block | string | Required | 0.0.0.0/0 |
| Target Type | string | Required | choices: Internet Gateway, NAT Gateway, Network Interface, VPC Peering Connection, Transit Gateway, Egress-only Internet Gateway |
| Target ID | string | Required | igw-0abc... / nat-... / eni-... etc |
Returns: tool_result
AWS VPC Create Route Table
aws/vpc/create_route_table · Action
Create a route table within a VPC.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC ID | string | Required | vpc-0abc... |
| Tags | key_value_array |
Returns: tool_result, route_table, route_table_id
AWS VPC Create Subnet
aws/vpc/create_subnet · Action
Create a subnet within a VPC with a CIDR block and optional AZ.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC ID | string | Required | vpc-0abc... |
| CIDR Block | string | Required | 10.0.1.0/24 |
| Availability Zone (optional) | string | eu-west-2a | |
| Tags | key_value_array |
Returns: tool_result, subnet, subnet_id
AWS VPC Create Traffic Mirror Filter
aws/vpc/create_traffic_mirror_filter · Action
Create a VPC Traffic Mirror filter to hold ingress/egress mirroring rules.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Description (optional) | string | ||
| Tags | key_value_array |
Returns: tool_result, filter, traffic_mirror_filter_id
AWS VPC Create Traffic Mirror Filter Rule
aws/vpc/create_traffic_mirror_filter_rule · Action
Add an ingress or egress rule to a VPC Traffic Mirror filter.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Traffic Mirror Filter ID | string | Required | tmf-0abc |
| Traffic Direction | string | Required | choices: Ingress, Egress |
| Rule Number | integer | Required | e.g. 100 (unique per direction, evaluated ascending) |
| Rule Action | string | Required | choices: Accept, Reject |
| Protocol Number (optional) | integer | e.g. 6 (TCP), 17 (UDP) | |
| Destination CIDR Block | string | Required | 0.0.0.0/0 |
| Source CIDR Block | string | Required | 10.0.0.0/16 |
| Description (optional) | string |
Returns: tool_result, rule, traffic_mirror_filter_rule_id
AWS VPC Create Traffic Mirror Session
aws/vpc/create_traffic_mirror_session · Action
Create a VPC Traffic Mirror session from a source ENI to a target with a filter.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Source Network Interface ID | string | Required | eni-0abc |
| Traffic Mirror Target ID | string | Required | tmt-0abc |
| Traffic Mirror Filter ID | string | Required | tmf-0abc |
| Session Number | integer | Required | 1-32766 (evaluation order for the source ENI) |
| Packet Length (optional) | integer | Bytes to mirror after the VXLAN header | |
| Virtual Network ID (optional) | integer | VXLAN ID; random if left blank | |
| Description (optional) | string | ||
| Tags | key_value_array |
Returns: tool_result, session, traffic_mirror_session_id
AWS VPC Create Traffic Mirror Target
aws/vpc/create_traffic_mirror_target · Action
Create a VPC Traffic Mirror target (ENI, NLB, or Gateway LB endpoint).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Network Interface ID (optional) | string | eni-0abc | |
| Network Load Balancer ARN (optional) | string | arn:aws:elasticloadbalancing:... | |
| Gateway Load Balancer Endpoint ID (optional) | string | vpce-0abc | |
| Description (optional) | string | ||
| Tags | key_value_array |
Returns: tool_result, target, traffic_mirror_target_id
AWS VPC Create Transit Gateway
aws/vpc/create_transit_gateway · Action
Create a transit gateway to connect VPCs and on-premises networks.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Description (optional) | string | e.g. Production transit gateway | |
| Amazon Side ASN (optional) | integer | 64512–65534, or 4200000000–4294967294 | |
| Tags | key_value_array |
Returns: tool_result, transit_gateway, transit_gateway_id
AWS VPC Create Transit Gateway Connect
aws/vpc/create_transit_gateway_connect · Action
Create a Connect attachment over an existing VPC or Direct Connect attachment.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transport Attachment ID | string | Required | tgw-attach-0123456789abcdef0 |
| Protocol | string | Required | choices: GRE |
| Tags | key_value_array |
Returns: tool_result, connect, transit_gateway_attachment_id
AWS VPC Create Transit Gateway Multicast Domain
aws/vpc/create_transit_gateway_multicast_domain · Action
Create a multicast domain on a transit gateway.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway ID | string | Required | tgw-0123456789abcdef0 |
| Tags | key_value_array |
Returns: tool_result, multicast_domain, transit_gateway_multicast_domain_id
AWS VPC Create Transit Gateway Peering Attachment
aws/vpc/create_transit_gateway_peering_attachment · Action
Request a peering attachment between two transit gateways across accounts or Regions.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway ID | string | Required | tgw-0123456789abcdef0 |
| Peer Transit Gateway ID | string | Required | tgw-0123456789abcdef0 |
| Peer Account ID | string | Required | 123456789012 |
| Peer Region | string | Required | us-east-1 |
| Tags | key_value_array |
Returns: tool_result, attachment, transit_gateway_attachment_id
AWS VPC Create Transit Gateway Route
aws/vpc/create_transit_gateway_route · Action
Create a static route in a transit gateway route table.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Route Table ID | string | Required | tgw-rtb-0123456789abcdef0 |
| Destination CIDR Block | string | Required | 10.1.0.0/16 |
| Transit Gateway Attachment ID (optional) | string | Target attachment; omit for a blackhole route | |
| Blackhole | boolean | Drop traffic matching this route |
Returns: tool_result, route
AWS VPC Create Transit Gateway Route Table
aws/vpc/create_transit_gateway_route_table · Action
Create a transit gateway route table for custom routing domains.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway ID | string | Required | tgw-0123456789abcdef0 |
| Tags | key_value_array |
Returns: tool_result, route_table, transit_gateway_route_table_id
AWS VPC Create Transit Gateway VPC Attachment
aws/vpc/create_transit_gateway_vpc_attachment · Action
Attach a VPC to a transit gateway across one or more subnets.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway ID | string | Required | tgw-0123456789abcdef0 |
| VPC ID | string | Required | vpc-0123456789abcdef0 |
| Subnet IDs | string | Required | Comma-separated; one subnet per Availability Zone |
| Tags | key_value_array |
Returns: tool_result, attachment, transit_gateway_attachment_id
AWS VPC Create VPC
aws/vpc/create_vpc · Action
Create a new Amazon VPC with a CIDR block, tenancy, and optional IPv6.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| CIDR Block | string | Required | 10.0.0.0/16 |
| Instance Tenancy | string | choices: Default, Dedicated | |
| Request Amazon-provided IPv6 CIDR | boolean | ||
| Tags | key_value_array |
Returns: tool_result, vpc, vpc_id
AWS VPC Create VPC Endpoint
aws/vpc/create_vpc_endpoint · Action
Create a Gateway or Interface VPC endpoint to an AWS service.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC ID | string | Required | vpc-0abc |
| Service Name | string | Required | com.amazonaws.eu-west-2.s3 |
| Endpoint Type | string | choices: Gateway, Interface, Gateway Load Balancer | |
| Route Table IDs (Gateway) | string | Comma-separated, e.g. rtb-0abc,rtb-0def | |
| Subnet IDs (Interface) | string | Comma-separated, e.g. subnet-0abc | |
| Security Group IDs (Interface) | string | Comma-separated, e.g. sg-0abc | |
| Enable Private DNS (Interface) | boolean | ||
| Tags | key_value_array |
Returns: tool_result, vpc_endpoint, vpc_endpoint_id
AWS VPC Create Endpoint Service Configuration
aws/vpc/create_vpc_endpoint_service_configuration · Action
Create a VPC endpoint service (PrivateLink provider) fronted by load balancers.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Network Load Balancer ARNs (optional) | string | Comma-separated NLB ARNs | |
| Gateway Load Balancer ARNs (optional) | string | Comma-separated GWLB ARNs | |
| Require Acceptance (optional) | boolean | ||
| Private DNS Name (optional) | string | service.example.com | |
| Tags | key_value_array |
Returns: tool_result, service, service_id
AWS VPC Create Peering Connection
aws/vpc/create_vpc_peering_connection · Action
Request a VPC peering connection between two VPCs (same or cross account/region).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Requester VPC ID | string | Required | vpc-0abc |
| Peer (Accepter) VPC ID | string | Required | vpc-0def |
| Peer Owner Account ID (optional) | string | Leave blank for same account | |
| Peer Region (optional) | string | Leave blank for same region | |
| Tags | key_value_array |
Returns: tool_result, vpc_peering_connection, vpc_peering_connection_id
AWS VPC Create VPN Connection
aws/vpc/create_vpn_connection · Action
Create a Site-to-Site VPN connection between a customer gateway and an Amazon gateway.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPN Type | string | Required | choices: ipsec.1 |
| Customer Gateway ID | string | Required | cgw-0abc123 |
| VPN Gateway ID (optional) | string | vgw-0abc123 — provide this OR a transit gateway | |
| Transit Gateway ID (optional) | string | tgw-0abc123 — provide this OR a VPN gateway | |
| Static Routes Only | boolean | ||
| Tags | key_value_array |
Returns: tool_result, vpn_connection, vpn_connection_id
AWS VPC Create VPN Connection Route
aws/vpc/create_vpn_connection_route · Action
Create a static route for a Site-to-Site VPN connection (policy-based VPN).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPN Connection ID | string | Required | vpn-0abc123 |
| Destination CIDR Block | string | Required | 192.168.10.0/24 |
Returns: tool_result
AWS VPC Create VPN Gateway
aws/vpc/create_vpn_gateway · Action
Create a virtual private gateway (the Amazon end of a Site-to-Site VPN).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPN Type | string | Required | choices: ipsec.1 |
| Amazon Side ASN (optional) | integer | 64512 | |
| Availability Zone (optional) | string | eu-west-2a | |
| Tags | key_value_array |
Returns: tool_result, vpn_gateway, vpn_gateway_id
09Delete
AWS VPC Delete Client VPN Endpoint
aws/vpc/delete_client_vpn_endpoint · Action
Delete an AWS Client VPN endpoint by id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Client VPN Endpoint ID | string | Required | cvpn-endpoint-0abc123 |
Returns: tool_result, status
AWS VPC Delete Client VPN Route
aws/vpc/delete_client_vpn_route · Action
Remove a route from an AWS Client VPN endpoint's route table.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Client VPN Endpoint ID | string | Required | cvpn-endpoint-0abc123 |
| Destination CIDR Block | string | Required | 0.0.0.0/0 |
| Target VPC Subnet ID (optional) | string | subnet-0abc123 |
Returns: tool_result, status
AWS VPC Delete Customer Gateway
aws/vpc/delete_customer_gateway · Action
Delete a customer gateway.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Customer Gateway ID | string | Required | cgw-0abc123 |
Returns: tool_result
AWS VPC Delete DHCP Options
aws/vpc/delete_dhcp_options · Action
Delete a DHCP options set. It must not be associated with any VPC.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| DHCP Options ID | string | Required | dopt-0abc |
Returns: tool_result
AWS VPC Delete Egress-Only Internet Gateway
aws/vpc/delete_egress_only_internet_gateway · Action
Delete an egress-only internet gateway.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Egress-Only Internet Gateway ID | string | Required | eigw-0abc |
Returns: tool_result
AWS VPC Delete Flow Logs
aws/vpc/delete_flow_logs · Action
Delete one or more VPC flow logs by ID.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Flow Log IDs | string | Required | Comma-separated, e.g. fl-0abc,fl-0def |
Returns: tool_result
AWS VPC Delete Internet Gateway
aws/vpc/delete_internet_gateway · Action
Delete an internet gateway by ID.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Internet Gateway ID | string | Required | igw-0abc123 |
Returns: tool_result
AWS IPAM Delete IPAM
aws/vpc/delete_ipam · Action
Delete an AWS IPAM by id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| IPAM ID | string | Required |
Returns: tool_result, ipam
AWS IPAM Delete Pool
aws/vpc/delete_ipam_pool · Action
Delete an AWS IPAM pool by id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| IPAM Pool ID | string | Required |
Returns: tool_result, ipam_pool
AWS IPAM Delete Scope
aws/vpc/delete_ipam_scope · Action
Delete an AWS IPAM scope by id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| IPAM Scope ID | string | Required |
Returns: tool_result, ipam_scope
AWS VPC Delete Managed Prefix List
aws/vpc/delete_managed_prefix_list · Action
Delete a customer-managed prefix list.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Prefix List ID | string | Required | pl-0abc... |
Returns: tool_result, prefix_list
AWS VPC Delete NAT Gateway
aws/vpc/delete_nat_gateway · Action
Delete a NAT gateway by ID.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| NAT Gateway ID | string | Required | nat-0abc123 |
Returns: tool_result
AWS VPC Delete Network ACL
aws/vpc/delete_network_acl · Action
Delete a network ACL. The default network ACL cannot be deleted.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Network ACL ID | string | Required | acl-0abc |
Returns: tool_result
AWS VPC Delete Network ACL Entry
aws/vpc/delete_network_acl_entry · Action
Remove an inbound or outbound rule from a network ACL.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Network ACL ID | string | Required | acl-0abc |
| Rule Number | integer | Required | 100 |
| Egress (outbound rule) | boolean | Required |
Returns: tool_result
AWS VPC Delete Network Insights Analysis
aws/vpc/delete_network_insights_analysis · Action
Delete a Reachability Analyzer analysis by its ID.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Analysis ID | string | Required |
Returns: tool_result, network_insights_analysis_id
AWS VPC Delete Network Insights Path
aws/vpc/delete_network_insights_path · Action
Delete a Reachability Analyzer path by its ID.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Path ID | string | Required |
Returns: tool_result, network_insights_path_id
AWS VPC Delete Network Interface
aws/vpc/delete_network_interface · Action
Delete a detached elastic network interface (ENI).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Network Interface ID | string | Required | eni-0abc |
Returns: tool_result
AWS VPC Delete Route
aws/vpc/delete_route · Action
Remove a route from a route table by destination CIDR.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Route Table ID | string | Required | rtb-0abc... |
| Destination CIDR Block | string | Required | 0.0.0.0/0 |
Returns: tool_result
AWS VPC Delete Route Table
aws/vpc/delete_route_table · Action
Delete a route table by its id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Route Table ID | string | Required | rtb-0abc... |
Returns: tool_result
AWS VPC Delete Subnet
aws/vpc/delete_subnet · Action
Delete a subnet by its id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Subnet ID | string | Required | subnet-0abc... |
Returns: tool_result
AWS VPC Delete Traffic Mirror Filter
aws/vpc/delete_traffic_mirror_filter · Action
Delete a VPC Traffic Mirror filter by its id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Traffic Mirror Filter ID | string | Required | tmf-0abc |
Returns: tool_result, traffic_mirror_filter_id
AWS VPC Delete Traffic Mirror Filter Rule
aws/vpc/delete_traffic_mirror_filter_rule · Action
Delete a rule from a VPC Traffic Mirror filter by its rule id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Traffic Mirror Filter Rule ID | string | Required | tmfr-0abc |
Returns: tool_result, traffic_mirror_filter_rule_id
AWS VPC Delete Traffic Mirror Session
aws/vpc/delete_traffic_mirror_session · Action
Delete a VPC Traffic Mirror session by its id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Traffic Mirror Session ID | string | Required | tms-0abc |
Returns: tool_result, traffic_mirror_session_id
AWS VPC Delete Traffic Mirror Target
aws/vpc/delete_traffic_mirror_target · Action
Delete a VPC Traffic Mirror target by its id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Traffic Mirror Target ID | string | Required | tmt-0abc |
Returns: tool_result, traffic_mirror_target_id
AWS VPC Delete Transit Gateway
aws/vpc/delete_transit_gateway · Action
Delete a transit gateway.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway ID | string | Required | tgw-0abc |
Returns: tool_result, transit_gateway
AWS VPC Delete Transit Gateway Connect
aws/vpc/delete_transit_gateway_connect · Action
Delete a transit gateway Connect attachment.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Attachment ID | string | Required | tgw-attach-0123456789abcdef0 |
Returns: tool_result, connect
AWS VPC Delete Transit Gateway Multicast Domain
aws/vpc/delete_transit_gateway_multicast_domain · Action
Delete a transit gateway multicast domain.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Multicast Domain ID | string | Required | tgw-mcast-domain-0123456789abcdef0 |
Returns: tool_result, multicast_domain
AWS VPC Delete Transit Gateway Peering Attachment
aws/vpc/delete_transit_gateway_peering_attachment · Action
Delete a transit gateway peering attachment.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Attachment ID | string | Required | tgw-attach-0123456789abcdef0 |
Returns: tool_result, attachment
AWS VPC Delete Transit Gateway Route
aws/vpc/delete_transit_gateway_route · Action
Delete a static route from a transit gateway route table.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Route Table ID | string | Required | tgw-rtb-0123456789abcdef0 |
| Destination CIDR Block | string | Required | 10.1.0.0/16 |
Returns: tool_result, route
AWS VPC Delete Transit Gateway Route Table
aws/vpc/delete_transit_gateway_route_table · Action
Delete a transit gateway route table.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Route Table ID | string | Required | tgw-rtb-0123456789abcdef0 |
Returns: tool_result, route_table
AWS VPC Delete Transit Gateway VPC Attachment
aws/vpc/delete_transit_gateway_vpc_attachment · Action
Delete a transit gateway VPC attachment.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Attachment ID | string | Required | tgw-attach-0123456789abcdef0 |
Returns: tool_result, attachment
AWS VPC Delete VPC
aws/vpc/delete_vpc · Action
Delete an Amazon VPC by its id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC ID | string | Required | vpc-0abc... |
Returns: tool_result
AWS VPC Delete Endpoint Service Configurations
aws/vpc/delete_vpc_endpoint_service_configurations · Action
Delete one or more VPC endpoint services (PrivateLink provider side) you own.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Service IDs | string | Required | Comma-separated, e.g. vpce-svc-0abc,vpce-svc-0def |
Returns: tool_result, unsuccessful, success
AWS VPC Delete VPC Endpoints
aws/vpc/delete_vpc_endpoints · Action
Delete one or more VPC endpoints by ID.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC Endpoint IDs | string | Required | Comma-separated, e.g. vpce-0abc,vpce-0def |
Returns: tool_result
AWS VPC Delete Peering Connection
aws/vpc/delete_vpc_peering_connection · Action
Delete a VPC peering connection.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC Peering Connection ID | string | Required | pcx-0abc |
Returns: tool_result
AWS VPC Delete VPN Connection
aws/vpc/delete_vpn_connection · Action
Delete a Site-to-Site VPN connection.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPN Connection ID | string | Required | vpn-0abc123 |
Returns: tool_result
AWS VPC Delete VPN Connection Route
aws/vpc/delete_vpn_connection_route · Action
Delete a static route from a Site-to-Site VPN connection (policy-based VPN).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPN Connection ID | string | Required | vpn-0abc123 |
| Destination CIDR Block | string | Required | 192.168.10.0/24 |
Returns: tool_result
AWS VPC Delete VPN Gateway
aws/vpc/delete_vpn_gateway · Action
Delete a virtual private gateway.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPN Gateway ID | string | Required | vgw-0abc123 |
Returns: tool_result
10Describe
AWS VPC Describe Addresses
aws/vpc/describe_addresses · Action
List Elastic IP addresses, optionally filtered by allocation ID or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Allocation IDs | string | Comma-separated; blank for all (optional) | |
| Filter by Tags | key_value_array | Only return addresses with these tags (blank Value matches any value for that key) |
Returns: tool_result, addresses, count
AWS VPC Describe Client VPN Connections
aws/vpc/describe_client_vpn_connections · Action
List the client connections for an AWS Client VPN endpoint.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Client VPN Endpoint ID | string | Required | cvpn-endpoint-0abc123 |
Returns: tool_result, connections, count
AWS VPC Describe Client VPN Endpoints
aws/vpc/describe_client_vpn_endpoints · Action
List AWS Client VPN endpoints, optionally filtered by id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Client VPN Endpoint ID (optional) | string | Leave blank to list all | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, endpoints, count
AWS VPC Describe Client VPN Routes
aws/vpc/describe_client_vpn_routes · Action
List the routes for an AWS Client VPN endpoint.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Client VPN Endpoint ID | string | Required | cvpn-endpoint-0abc123 |
Returns: tool_result, routes, count
AWS VPC Describe Client VPN Target Networks
aws/vpc/describe_client_vpn_target_networks · Action
List the target networks associated with an AWS Client VPN endpoint.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Client VPN Endpoint ID | string | Required | cvpn-endpoint-0abc123 |
Returns: tool_result, target_networks, count
AWS VPC Describe Customer Gateways
aws/vpc/describe_customer_gateways · Action
List customer gateways, optionally filtered by id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Customer Gateway ID (optional) | string | Leave blank to list all | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, customer_gateways, count
AWS VPC Describe DHCP Options
aws/vpc/describe_dhcp_options · Action
List DHCP option sets, optionally filtered by ID or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| DHCP Options ID (optional) | string | Leave blank to list all | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, dhcp_option_sets, count
AWS VPC Describe Egress-Only Internet Gateways
aws/vpc/describe_egress_only_internet_gateways · Action
List egress-only internet gateways, optionally by id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Egress-Only Internet Gateway IDs (optional) | string | Comma-separated; blank lists all | |
| Filter by Tags | key_value_array | Only return gateways with these tags (blank Value matches any value for that key) |
Returns: tool_result, egress_only_internet_gateways, count
AWS VPC Describe Flow Logs
aws/vpc/describe_flow_logs · Action
List VPC flow logs, optionally filtered by ID or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Flow Log ID (optional) | string | Leave blank to list all | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, flow_logs, count
AWS VPC Describe Internet Gateways
aws/vpc/describe_internet_gateways · Action
List internet gateways, optionally filtered by ID or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Internet Gateway IDs | string | Comma-separated; blank for all (optional) | |
| Filter by Tags | key_value_array | Only return gateways with these tags (blank Value matches any value for that key) |
Returns: tool_result, internet_gateways, count
AWS IPAM Describe Pools
aws/vpc/describe_ipam_pools · Action
List AWS IPAM pools, optionally filtered by pool id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| IPAM Pool ID (optional) | string | Leave blank to list all |
Returns: tool_result, ipam_pools, count
AWS IPAM Describe Scopes
aws/vpc/describe_ipam_scopes · Action
List AWS IPAM scopes, optionally filtered by scope id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| IPAM Scope ID (optional) | string | Leave blank to list all |
Returns: tool_result, ipam_scopes, count
AWS IPAM Describe IPAMs
aws/vpc/describe_ipams · Action
List AWS IPAMs, optionally filtered by IPAM id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| IPAM ID (optional) | string | Leave blank to list all |
Returns: tool_result, ipams, count
AWS VPC Describe Managed Prefix Lists
aws/vpc/describe_managed_prefix_lists · Action
List managed prefix lists, optionally by id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Prefix List IDs (optional) | string | Comma-separated; blank lists all | |
| Filter by Tags | key_value_array | Only return prefix lists with these tags (blank Value matches any value for that key) |
Returns: tool_result, prefix_lists, count
AWS VPC Describe NAT Gateways
aws/vpc/describe_nat_gateways · Action
List NAT gateways, optionally filtered by ID or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| NAT Gateway IDs | string | Comma-separated; blank for all (optional) | |
| Filter by Tags | key_value_array | Only return gateways with these tags (blank Value matches any value for that key) |
Returns: tool_result, nat_gateways, count
AWS VPC Describe Network ACLs
aws/vpc/describe_network_acls · Action
List network ACLs, optionally filtered by ID, VPC, or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Network ACL ID (optional) | string | Leave blank to list all | |
| VPC ID (optional filter) | string | vpc-0abc | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, network_acls, count
AWS VPC Describe Network Insights Analyses
aws/vpc/describe_network_insights_analyses · Action
List Reachability Analyzer analyses, optionally filtered by analysis or path id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Analysis ID (optional) | string | Leave blank to list all | |
| Path ID (optional) | string | Filter analyses to one path |
Returns: tool_result, analyses, count
AWS VPC Describe Network Insights Paths
aws/vpc/describe_network_insights_paths · Action
List Reachability Analyzer paths, optionally filtered by path id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Path ID (optional) | string | Leave blank to list all |
Returns: tool_result, paths, count
AWS VPC Describe Network Interfaces
aws/vpc/describe_network_interfaces · Action
List elastic network interfaces (ENIs), optionally by id, subnet or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Network Interface IDs (optional) | string | Comma-separated; blank lists all | |
| Filter by Subnet ID (optional) | string | subnet-0abc | |
| Filter by Tags | key_value_array | Only return interfaces with these tags (blank Value matches any value for that key) |
Returns: tool_result, network_interfaces, count
AWS VPC Describe Route Tables
aws/vpc/describe_route_tables · Action
List route tables, optionally filtered by id, VPC id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Route Table ID (optional) | string | Leave blank to list all | |
| VPC ID (optional) | string | Filter by VPC | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, route_tables, count
AWS VPC Describe Subnets
aws/vpc/describe_subnets · Action
List subnets, optionally filtered by subnet id, VPC id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Subnet ID (optional) | string | Leave blank to list all | |
| VPC ID (optional) | string | Filter by VPC | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, subnets, count
AWS VPC Describe Traffic Mirror Filters
aws/vpc/describe_traffic_mirror_filters · Action
List VPC Traffic Mirror filters, optionally filtered by filter id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Traffic Mirror Filter ID (optional) | string | Leave blank to list all | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, filters, count
AWS VPC Describe Traffic Mirror Sessions
aws/vpc/describe_traffic_mirror_sessions · Action
List VPC Traffic Mirror sessions, optionally filtered by session id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Traffic Mirror Session ID (optional) | string | Leave blank to list all | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, sessions, count
AWS VPC Describe Traffic Mirror Targets
aws/vpc/describe_traffic_mirror_targets · Action
List VPC Traffic Mirror targets, optionally filtered by target id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Traffic Mirror Target ID (optional) | string | Leave blank to list all | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, targets, count
AWS VPC Describe Transit Gateway Multicast Domains
aws/vpc/describe_transit_gateway_multicast_domains · Action
List transit gateway multicast domains, optionally by id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Multicast Domain IDs (optional) | string | Comma-separated; blank lists all | |
| Filter by Tags | key_value_array | Only return domains with these tags (blank Value matches any value for that key) |
Returns: tool_result, multicast_domains, count
AWS VPC Describe Transit Gateway Peering Attachments
aws/vpc/describe_transit_gateway_peering_attachments · Action
List transit gateway peering attachments, optionally by id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Attachment IDs (optional) | string | Comma-separated; blank lists all | |
| Filter by Tags | key_value_array | Only return attachments with these tags (blank Value matches any value for that key) |
Returns: tool_result, attachments, count
AWS VPC Describe Transit Gateway Route Tables
aws/vpc/describe_transit_gateway_route_tables · Action
List transit gateway route tables, optionally by id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Route Table IDs (optional) | string | Comma-separated; blank lists all | |
| Filter by Tags | key_value_array | Only return route tables with these tags (blank Value matches any value for that key) |
Returns: tool_result, route_tables, count
AWS VPC Describe Transit Gateway VPC Attachments
aws/vpc/describe_transit_gateway_vpc_attachments · Action
List transit gateway VPC attachments, optionally by id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Attachment IDs (optional) | string | Comma-separated; blank lists all | |
| Filter by Tags | key_value_array | Only return attachments with these tags (blank Value matches any value for that key) |
Returns: tool_result, attachments, count
AWS VPC Describe Transit Gateways
aws/vpc/describe_transit_gateways · Action
List transit gateways, optionally by id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway IDs (optional) | string | Comma-separated; blank lists all | |
| Filter by Tags | key_value_array | Only return gateways with these tags (blank Value matches any value for that key) |
Returns: tool_result, transit_gateways, count
AWS VPC Describe Endpoint Connections
aws/vpc/describe_vpc_endpoint_connections · Action
List consumer connections to the VPC endpoint services you own.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Service ID (optional) | string | vpce-svc-0abc; blank lists all | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, connections, count
AWS VPC Describe Endpoint Service Configurations
aws/vpc/describe_vpc_endpoint_service_configurations · Action
List the VPC endpoint services you own, optionally filtered by ID or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Service IDs (optional) | string | Comma-separated; blank lists all | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, services, count
AWS VPC Describe Endpoint Service Permissions
aws/vpc/describe_vpc_endpoint_service_permissions · Action
List the principals allowed to connect to a VPC endpoint service you own.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Service ID | string | Required | vpce-svc-0abc |
Returns: tool_result, allowed_principals, count
AWS VPC Describe Endpoint Services
aws/vpc/describe_vpc_endpoint_services · Action
Discover VPC endpoint services you can consume (finds the service_name to connect to).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Service Names (optional) | string | Comma-separated, e.g. com.amazonaws.eu-west-2.s3 | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, service_names, services, count
AWS VPC Describe VPC Endpoints
aws/vpc/describe_vpc_endpoints · Action
List VPC endpoints, optionally filtered by ID or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC Endpoint ID (optional) | string | Leave blank to list all | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, vpc_endpoints, count
AWS VPC Describe Peering Connections
aws/vpc/describe_vpc_peering_connections · Action
List VPC peering connections, optionally by id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC Peering Connection IDs (optional) | string | Comma-separated; blank lists all | |
| Filter by Tags | key_value_array | Only return connections with these tags (blank Value matches any value for that key) |
Returns: tool_result, vpc_peering_connections, count
AWS VPC Describe VPCs
aws/vpc/describe_vpcs · Action
List Amazon VPCs, optionally filtered by VPC id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC ID (optional) | string | Leave blank to list all | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, vpcs, count
AWS VPC Describe VPN Connections
aws/vpc/describe_vpn_connections · Action
List Site-to-Site VPN connections, optionally filtered by id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPN Connection ID (optional) | string | Leave blank to list all | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, vpn_connections, count
AWS VPC Describe VPN Gateways
aws/vpc/describe_vpn_gateways · Action
List virtual private gateways, optionally filtered by id or tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPN Gateway ID (optional) | string | Leave blank to list all | |
| Filter by Tags (optional) | key_value_array |
Returns: tool_result, vpn_gateways, count
11Detach
AWS VPC Detach Internet Gateway
aws/vpc/detach_internet_gateway · Action
Detach an internet gateway from a VPC.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Internet Gateway ID | string | Required | igw-0abc123 |
| VPC ID | string | Required | vpc-0abc123 |
Returns: tool_result
AWS VPC Detach Network Interface
aws/vpc/detach_network_interface · Action
Detach an elastic network interface (ENI) from an instance by attachment id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Attachment ID | string | Required | eni-attach-0abc |
| Force Detach | boolean |
Returns: tool_result
AWS VPC Detach VPN Gateway
aws/vpc/detach_vpn_gateway · Action
Detach a virtual private gateway from a VPC.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPN Gateway ID | string | Required | vgw-0abc123 |
| VPC ID | string | Required | vpc-0abc123 |
Returns: tool_result
12Disable
AWS VPC Disable Transit Gateway Route Table Propagation
aws/vpc/disable_transit_gateway_route_table_propagation · Action
Disable route propagation from an attachment into a route table.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Route Table ID | string | Required | tgw-rtb-0123456789abcdef0 |
| Transit Gateway Attachment ID | string | Required | tgw-attach-0123456789abcdef0 |
Returns: tool_result, propagation
13Disassociate
AWS VPC Disassociate Address
aws/vpc/disassociate_address · Action
Disassociate an Elastic IP address by association ID.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Association ID | string | Required | eipassoc-0abc123 |
Returns: tool_result
AWS VPC Disassociate Client VPN Target Network
aws/vpc/disassociate_client_vpn_target_network · Action
Remove a target network association from an AWS Client VPN endpoint.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Client VPN Endpoint ID | string | Required | cvpn-endpoint-0abc123 |
| Association ID | string | Required | cvpn-assoc-0abc123 |
Returns: tool_result, status
AWS VPC Disassociate NAT Gateway Address
aws/vpc/disassociate_nat_gateway_address · Action
Disassociate secondary Elastic IP addresses from a public NAT gateway.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| NAT Gateway ID | string | Required | nat-0abc123 |
| Address Association IDs | string | Required | Comma-separated, e.g. eipassoc-0abc,eipassoc-0def |
Returns: tool_result
AWS VPC Disassociate Route Table
aws/vpc/disassociate_route_table · Action
Remove a route table association by its association id.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Association ID | string | Required | rtbassoc-0abc... |
Returns: tool_result
AWS VPC Disassociate Transit Gateway Route Table
aws/vpc/disassociate_transit_gateway_route_table · Action
Disassociate a transit gateway attachment from a route table.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Route Table ID | string | Required | tgw-rtb-0123456789abcdef0 |
| Transit Gateway Attachment ID | string | Required | tgw-attach-0123456789abcdef0 |
Returns: tool_result, association
AWS VPC Disassociate CIDR Block
aws/vpc/disassociate_vpc_cidr_block · Action
Remove a secondary IPv4 or IPv6 CIDR block association from a VPC.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| CIDR Association ID | string | Required | vpc-cidr-assoc-0abc... |
Returns: tool_result
14Enable
AWS VPC Enable Transit Gateway Route Table Propagation
aws/vpc/enable_transit_gateway_route_table_propagation · Action
Enable route propagation from an attachment into a route table.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Route Table ID | string | Required | tgw-rtb-0123456789abcdef0 |
| Transit Gateway Attachment ID | string | Required | tgw-attach-0123456789abcdef0 |
Returns: tool_result, propagation
15Export
AWS VPC Export Client VPN Client Configuration
aws/vpc/export_client_vpn_client_configuration · Action
Export the OpenVPN client configuration for an AWS Client VPN endpoint.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Client VPN Endpoint ID | string | Required | cvpn-endpoint-0abc123 |
Returns: tool_result, configuration
16Get
AWS IPAM Get Pool Allocations
aws/vpc/get_ipam_pool_allocations · Action
List the CIDR allocations within an IPAM pool.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| IPAM Pool ID | string | Required |
Returns: tool_result, allocations, count
AWS IPAM Get Pool CIDRs
aws/vpc/get_ipam_pool_cidrs · Action
List the CIDRs provisioned to an IPAM pool.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| IPAM Pool ID | string | Required |
Returns: tool_result, cidrs, count
AWS VPC Get Managed Prefix List Associations
aws/vpc/get_managed_prefix_list_associations · Action
List the resources that reference a managed prefix list.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Prefix List ID | string | Required | pl-0abc... |
Returns: tool_result, associations, count
AWS VPC Get Managed Prefix List Entries
aws/vpc/get_managed_prefix_list_entries · Action
List the CIDR entries of a managed prefix list.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Prefix List ID | string | Required | pl-0abc... |
Returns: tool_result, entries, count
17Modify
AWS VPC Modify Client VPN Endpoint
aws/vpc/modify_client_vpn_endpoint · Action
Update an AWS Client VPN endpoint's description or server certificate.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Client VPN Endpoint ID | string | Required | cvpn-endpoint-0abc123 |
| Description (optional) | string | ||
| Server Certificate ARN (optional) | string | arn:aws:acm:...:certificate/... |
Returns: tool_result, success
AWS IPAM Modify IPAM
aws/vpc/modify_ipam · Action
Modify an AWS IPAM's description or operating Regions.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| IPAM ID | string | Required | |
| Description (optional) | string | ||
| Add Operating Regions (optional) | string | us-east-1,eu-west-1 | |
| Remove Operating Regions (optional) | string | us-east-1 |
Returns: tool_result, ipam
AWS IPAM Modify Pool
aws/vpc/modify_ipam_pool · Action
Modify an AWS IPAM pool's description or auto-import setting.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| IPAM Pool ID | string | Required | |
| Description (optional) | string | ||
| Auto Import (leave unset to keep current) | boolean |
Returns: tool_result, ipam_pool
AWS VPC Modify Managed Prefix List
aws/vpc/modify_managed_prefix_list · Action
Rename a managed prefix list, or add/remove CIDR entries.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Prefix List ID | string | Required | pl-0abc... |
| New Name (optional) | string | Leave blank to keep current name | |
| Add Entries (optional) | text | JSON array e.g. [{"cidr":"10.0.0.0/16","description":"HQ"}] | |
| Remove Entries (optional) | text | JSON array e.g. [{"cidr":"10.0.0.0/16"}] | |
| Current Version (optional) | integer | Required when adding or removing entries |
Returns: tool_result, prefix_list
AWS VPC Modify Network Interface Attribute
aws/vpc/modify_network_interface_attribute · Action
Modify an ENI's description, source/dest check, or security groups.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Network Interface ID | string | Required | eni-0abc... |
| Description (optional) | string | e.g. App server ENI | |
| Source/Dest Check | string | choices: Leave unchanged, Enable, Disable | |
| Security Group IDs (optional) | string | Comma-separated, e.g. sg-0abc,sg-0def |
Returns: tool_result, network_interface_id
AWS VPC Modify Subnet Attribute
aws/vpc/modify_subnet_attribute · Action
Toggle auto-assign public IPv4 or IPv6 address on launch for a subnet.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Subnet ID | string | Required | subnet-0abc... |
| Auto-assign Public IPv4 on Launch | string | choices: Leave unchanged, Enable, Disable | |
| Auto-assign IPv6 on Creation | string | choices: Leave unchanged, Enable, Disable |
Returns: tool_result
AWS VPC Modify Traffic Mirror Session
aws/vpc/modify_traffic_mirror_session · Action
Update a VPC Traffic Mirror session's number, packet length, or description.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Traffic Mirror Session ID | string | Required | tms-0abc |
| Session Number (optional) | integer | 1-32766 | |
| Packet Length (optional) | integer | Bytes to mirror after the VXLAN header | |
| Description (optional) | string |
Returns: tool_result, session, traffic_mirror_session_id
AWS VPC Modify Transit Gateway
aws/vpc/modify_transit_gateway · Action
Update a transit gateway's description.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway ID | string | Required | tgw-0abc |
| Description (optional) | string | New description |
Returns: tool_result, transit_gateway
AWS VPC Modify Transit Gateway VPC Attachment
aws/vpc/modify_transit_gateway_vpc_attachment · Action
Add or remove subnets on a transit gateway VPC attachment.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Attachment ID | string | Required | tgw-attach-0123456789abcdef0 |
| Subnet IDs to Add (optional) | string | Comma-separated; one subnet per Availability Zone | |
| Subnet IDs to Remove (optional) | string | Comma-separated |
Returns: tool_result, attachment
AWS VPC Modify VPC Attribute
aws/vpc/modify_vpc_attribute · Action
Enable or disable DNS support and DNS hostnames on a VPC.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC ID | string | Required | vpc-0abc... |
| Enable DNS Support | string | choices: Leave unchanged, Enable, Disable | |
| Enable DNS Hostnames | string | choices: Leave unchanged, Enable, Disable |
Returns: tool_result
AWS VPC Modify VPC Endpoint
aws/vpc/modify_vpc_endpoint · Action
Modify a VPC endpoint's route tables, subnets, or private DNS setting.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC Endpoint ID | string | Required | vpce-0abc |
| Add Route Table IDs | string | Comma-separated, e.g. rtb-0abc | |
| Remove Route Table IDs | string | Comma-separated, e.g. rtb-0abc | |
| Add Subnet IDs | string | Comma-separated, e.g. subnet-0abc | |
| Remove Subnet IDs | string | Comma-separated, e.g. subnet-0abc | |
| Enable Private DNS (optional) | boolean |
Returns: tool_result
AWS VPC Modify Endpoint Service Configuration
aws/vpc/modify_vpc_endpoint_service_configuration · Action
Change a VPC endpoint service: acceptance, load balancers or private DNS name.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Service ID | string | Required | vpce-svc-0abc |
| Require Acceptance (optional) | boolean | ||
| Add Network Load Balancer ARNs (optional) | string | Comma-separated NLB ARNs | |
| Remove Network Load Balancer ARNs (optional) | string | Comma-separated NLB ARNs | |
| Private DNS Name (optional) | string | service.example.com |
Returns: tool_result, success
AWS VPC Modify Endpoint Service Permissions
aws/vpc/modify_vpc_endpoint_service_permissions · Action
Add or remove principals allowed to connect to a VPC endpoint service you own.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Service ID | string | Required | vpce-svc-0abc |
| Add Allowed Principals (optional) | string | Comma-separated ARNs, e.g. arn:aws:iam::123456789012:root | |
| Remove Allowed Principals (optional) | string | Comma-separated ARNs |
Returns: tool_result, success
AWS VPC Modify Peering Connection Options
aws/vpc/modify_vpc_peering_connection_options · Action
Change the DNS resolution options of a VPC peering connection (requester/accepter).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC Peering Connection ID | string | Required | pcx-0abc123 |
| Requester: Allow DNS Resolution from Remote VPC (optional) | boolean | ||
| Accepter: Allow DNS Resolution from Remote VPC (optional) | boolean |
Returns: tool_result
AWS VPC Modify Tenancy
aws/vpc/modify_vpc_tenancy · Action
Change a VPC's instance tenancy attribute back to default.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC ID | string | Required | vpc-0abc... |
| Instance Tenancy | string | Required | choices: Default |
Returns: tool_result
AWS VPC Modify VPN Connection
aws/vpc/modify_vpn_connection · Action
Change the target gateway (transit, VPN, or customer) of a Site-to-Site VPN connection.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPN Connection ID | string | Required | vpn-0abc123 |
| Transit Gateway ID (optional) | string | tgw-0abc123 | |
| VPN Gateway ID (optional) | string | vgw-0abc123 | |
| Customer Gateway ID (optional) | string | cgw-0abc123 |
Returns: tool_result, vpn_connection, vpn_connection_id
AWS VPC Modify VPN Connection Options
aws/vpc/modify_vpn_connection_options · Action
Change the local/remote IPv4 network CIDRs of a Site-to-Site VPN connection.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPN Connection ID | string | Required | vpn-0abc123 |
| Local IPv4 Network CIDR (optional) | string | 10.0.0.0/16 — customer gateway side | |
| Remote IPv4 Network CIDR (optional) | string | 172.16.0.0/16 — Amazon side |
Returns: tool_result, vpn_connection, vpn_connection_id
AWS VPC Modify VPN Tunnel Options
aws/vpc/modify_vpn_tunnel_options · Action
Modify the IPSec options of a single tunnel in a Site-to-Site VPN connection.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPN Connection ID | string | Required | vpn-0abc123 |
| Tunnel Outside IP Address | string | Required | 203.0.113.10 — external IP of the tunnel to modify |
| Tunnel Options | text | Required | JSON object e.g. {"pre_shared_key":"...","phase1_lifetime_seconds":28800,"phase2_lifetime_seconds":3600} |
Returns: tool_result, vpn_connection, vpn_connection_id
18Provision
AWS IPAM Provision Pool CIDR
aws/vpc/provision_ipam_pool_cidr · Action
Provision a CIDR to an IPAM pool by CIDR or netmask length.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| IPAM Pool ID | string | Required | |
| CIDR (optional) | string | 10.0.0.0/16 | |
| Netmask Length (optional) | integer | 16 |
Returns: tool_result, cidr
19Reject
AWS VPC Reject Transit Gateway Peering Attachment
aws/vpc/reject_transit_gateway_peering_attachment · Action
Reject a pending transit gateway peering attachment request.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Attachment ID | string | Required | tgw-attach-0123456789abcdef0 |
Returns: tool_result, attachment
AWS VPC Reject Transit Gateway VPC Attachment
aws/vpc/reject_transit_gateway_vpc_attachment · Action
Reject a pending cross-account transit gateway VPC attachment.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Attachment ID | string | Required | tgw-attach-0123456789abcdef0 |
Returns: tool_result, attachment
AWS VPC Reject Endpoint Connections
aws/vpc/reject_vpc_endpoint_connections · Action
Reject consumer connection requests to a VPC endpoint service you own.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Service ID | string | Required | vpce-svc-0abc |
| VPC Endpoint IDs | string | Required | Comma-separated, e.g. vpce-0abc,vpce-0def |
Returns: tool_result, unsuccessful, success
AWS VPC Reject Peering Connection
aws/vpc/reject_vpc_peering_connection · Action
Reject a pending VPC peering connection request.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| VPC Peering Connection ID | string | Required | pcx-0abc123 |
Returns: tool_result
20Release
AWS VPC Release Address
aws/vpc/release_address · Action
Release an Elastic IP address by allocation ID.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Allocation ID | string | Required | eipalloc-0abc123 |
Returns: tool_result
AWS IPAM Release Pool Allocation
aws/vpc/release_ipam_pool_allocation · Action
Release a CIDR allocation back to an IPAM pool.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| IPAM Pool ID | string | Required | |
| IPAM Pool Allocation ID | string | Required | |
| CIDR | string | Required | 10.0.0.0/24 |
Returns: tool_result, success
21Replace
AWS VPC Replace Network ACL Association
aws/vpc/replace_network_acl_association · Action
Associate a different network ACL with an existing subnet association.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Association ID | string | Required | aclassoc-0abc... |
| New Network ACL ID | string | Required | acl-0abc... |
Returns: tool_result, new_association_id
AWS VPC Replace Network ACL Entry
aws/vpc/replace_network_acl_entry · Action
Replace an existing inbound or outbound rule in a network ACL.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Network ACL ID | string | Required | acl-0abc |
| Rule Number | integer | Required | 100 (1-32766, processed ascending) |
| Protocol Number | string | Required | 6 = TCP, 17 = UDP, -1 = all |
| Rule Action | string | Required | choices: Allow, Deny |
| Egress (outbound rule) | boolean | Required | |
| CIDR Block | string | Required | 0.0.0.0/0 |
| Port From (optional) | integer | For TCP/UDP, e.g. 80 | |
| Port To (optional) | integer | For TCP/UDP, e.g. 80 |
Returns: tool_result
AWS VPC Replace Route
aws/vpc/replace_route · Action
Replace an existing route in a route table with a new target.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Route Table ID | string | Required | rtb-0abc... |
| Destination CIDR Block | string | Required | 0.0.0.0/0 |
| Target Type | string | Required | choices: Internet Gateway, NAT Gateway, Network Interface, VPC Peering Connection, Transit Gateway, Egress-only Internet Gateway |
| Target ID | string | Required | igw-0abc... / nat-... / eni-... etc |
Returns: tool_result
AWS VPC Replace Route Table Association
aws/vpc/replace_route_table_association · Action
Associate a different route table with an existing subnet association.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Association ID | string | Required | rtbassoc-0abc... |
| New Route Table ID | string | Required | rtb-0abc... |
Returns: tool_result, new_association_id
AWS VPC Replace Transit Gateway Route
aws/vpc/replace_transit_gateway_route · Action
Replace an existing route in a transit gateway route table.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Transit Gateway Route Table ID | string | Required | tgw-rtb-0123456789abcdef0 |
| Destination CIDR Block | string | Required | 10.1.0.0/16 |
| Transit Gateway Attachment ID (optional) | string | New target attachment; omit for a blackhole route | |
| Blackhole | boolean | Drop traffic matching this route |
Returns: tool_result, route
22Revoke
AWS VPC Revoke Client VPN Ingress
aws/vpc/revoke_client_vpn_ingress · Action
Remove an ingress authorization rule from an AWS Client VPN endpoint.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Client VPN Endpoint ID | string | Required | cvpn-endpoint-0abc123 |
| Target Network CIDR | string | Required | 10.0.0.0/16 |
| Access Group ID (optional) | string | ||
| Revoke All Groups (optional) | boolean |
Returns: tool_result, status
23Start
AWS VPC Start Network Insights Analysis
aws/vpc/start_network_insights_analysis · Action
Run a Reachability Analyzer analysis for a network insights path.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Path ID | string | Required | |
| Tags | key_value_array |
Returns: tool_result, analysis, network_insights_analysis_id
24Unassign
AWS VPC Unassign IPv6 Addresses
aws/vpc/unassign_ipv6_addresses · Action
Remove IPv6 addresses from a network interface.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Network Interface ID | string | Required | eni-0abc... |
| IPv6 Addresses | string | Required | Comma-separated, e.g. 2001:db8::1,2001:db8::2 |
Returns: tool_result, network_interface_id
AWS VPC Unassign Private IP Addresses
aws/vpc/unassign_private_ip_addresses · Action
Remove secondary private IPv4 addresses from a network interface.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Network Interface ID | string | Required | eni-0abc... |
| Private IP Addresses | string | Required | Comma-separated, e.g. 10.0.1.10,10.0.1.11 |
Returns: tool_result, network_interface_id
25Notes & Limitations
Behaviours and constraints worth knowing before you build with these nodes.
- NAT gateways, VPN connections, and interface VPC endpoints are provisioned asynchronously and initially report a lifecycle state of pending, whereas internet gateways are created and attached immediately.
- Each connection is scoped to a single AWS Region, which is a required setting, because VPC resources are Region-specific.
- AWS APIs are eventually consistent, so a newly created or modified resource may not appear immediately in subsequent reads.
- A resource cannot be deleted until all of its dependent resources have been removed first.
- A VPC peering connection must be accepted before it becomes active.