Skip to main content

allowed_images_settings

Creates, updates, deletes, gets or lists an allowed_images_settings resource.

Overview

Nameallowed_images_settings
TypeResource
Idaws.ec2.allowed_images_settings

Fields

The following fields are returned by SELECT queries:

NameDatatypeDescription
image_criteriastringThe list of criteria for images that are discoverable and usable in the account in the specified Amazon Web Services Region.
managed_bystringThe entity that manages the Allowed AMIs settings. Possible values include: account - The Allowed AMIs settings is managed by the account. declarative-policy - The Allowed AMIs settings is managed by a declarative policy and can't be modified by the account.
statestringThe current state of the Allowed AMIs setting at the account level in the specified Amazon Web Services Region. Possible values: disabled: All AMIs are allowed. audit-mode: All AMIs are allowed, but the ImageAllowed field is set to true if the AMI would be allowed with the current list of criteria if allowed AMIs was enabled. enabled: Only AMIs matching the image criteria are discoverable and available for use.

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
get_allowed_images_settingsselectregionDryRunGets the current state of the Allowed AMIs setting and the list of Allowed AMIs criteria at the account level in the specified Region. The Allowed AMIs feature does not restrict the AMIs owned by your account. Regardless of the criteria you set, the AMIs created by your account will always be discoverable and usable by users in your account. For more information, see Control the discovery and use of AMIs in Amazon EC2 with Allowed AMIs in Amazon EC2 User Guide.
replace_image_criteria_in_allowed_images_settingsreplaceregionImageCriterion, DryRunSets or replaces the criteria for Allowed AMIs. The ImageCriteria can include up to: 10 ImageCriterion The Allowed AMIs feature does not restrict the AMIs owned by your account. Regardless of the criteria you set, the AMIs created by your account will always be discoverable and usable by users in your account. For more information, see Control the discovery and use of AMIs in Amazon EC2 with Allowed AMIs in Amazon EC2 User Guide.
disable_allowed_images_settingsexecregionDryRunDisables Allowed AMIs for your account in the specified Amazon Web Services Region. When set to disabled, the image criteria in your Allowed AMIs settings do not apply, and no restrictions are placed on AMI discoverability or usage. Users in your account can launch instances using any public AMI or AMI shared with your account. The Allowed AMIs feature does not restrict the AMIs owned by your account. Regardless of the criteria you set, the AMIs created by your account will always be discoverable and usable by users in your account. For more information, see Control the discovery and use of AMIs in Amazon EC2 with Allowed AMIs in Amazon EC2 User Guide.
enable_allowed_images_settingsexecAllowedImagesSettingsState, regionDryRunEnables Allowed AMIs for your account in the specified Amazon Web Services Region. Two values are accepted: enabled: The image criteria in your Allowed AMIs settings are applied. As a result, only AMIs matching these criteria are discoverable and can be used by your account to launch instances. audit-mode: The image criteria in your Allowed AMIs settings are not applied. No restrictions are placed on AMI discoverability or usage. Users in your account can launch instances using any public AMI or AMI shared with your account. The purpose of audit-mode is to indicate which AMIs will be affected when Allowed AMIs is enabled. In audit-mode, each AMI displays either "ImageAllowed": true or "ImageAllowed": false to indicate whether the AMI will be discoverable and available to users in the account when Allowed AMIs is enabled. The Allowed AMIs feature does not restrict the AMIs owned by your account. Regardless of the criteria you set, the AMIs created by your account will always be discoverable and usable by users in your account. For more information, see Control the discovery and use of AMIs in Amazon EC2 with Allowed AMIs in Amazon EC2 User Guide.

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
AllowedImagesSettingsStatestringSpecify enabled to apply the image criteria specified by the Allowed AMIs settings. Specify audit-mode so that you can check which AMIs will be allowed or not allowed by the image criteria.
regionstringAWS region (default: us-east-1)
DryRunbooleanChecks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.
ImageCriterionarrayThe list of criteria that are evaluated to determine whether AMIs are discoverable and usable in the account in the specified Amazon Web Services Region.

SELECT examples

Gets the current state of the Allowed AMIs setting and the list of Allowed AMIs criteria at the account level in the specified Region. The Allowed AMIs feature does not restrict the AMIs owned by your account. Regardless of the criteria you set, the AMIs created by your account will always be discoverable and usable by users in your account. For more information, see Control the discovery and use of AMIs in Amazon EC2 with Allowed AMIs in Amazon EC2 User Guide.

SELECT
image_criteria,
managed_by,
state
FROM aws.ec2.allowed_images_settings
WHERE region = '{{ region }}' -- required
AND DryRun = '{{ DryRun }}'
;

REPLACE examples

Sets or replaces the criteria for Allowed AMIs. The ImageCriteria can include up to: 10 ImageCriterion The Allowed AMIs feature does not restrict the AMIs owned by your account. Regardless of the criteria you set, the AMIs created by your account will always be discoverable and usable by users in your account. For more information, see Control the discovery and use of AMIs in Amazon EC2 with Allowed AMIs in Amazon EC2 User Guide.

REPLACE aws.ec2.allowed_images_settings
SET
-- No updatable properties
WHERE
region = '{{ region }}' --required
AND ImageCriterion = '{{ ImageCriterion}}'
AND DryRun = {{ DryRun}}
RETURNING
return_value;

Lifecycle Methods

Disables Allowed AMIs for your account in the specified Amazon Web Services Region. When set to disabled, the image criteria in your Allowed AMIs settings do not apply, and no restrictions are placed on AMI discoverability or usage. Users in your account can launch instances using any public AMI or AMI shared with your account. The Allowed AMIs feature does not restrict the AMIs owned by your account. Regardless of the criteria you set, the AMIs created by your account will always be discoverable and usable by users in your account. For more information, see Control the discovery and use of AMIs in Amazon EC2 with Allowed AMIs in Amazon EC2 User Guide.

EXEC aws.ec2.allowed_images_settings.disable_allowed_images_settings
@region='{{ region }}' --required,
@DryRun={{ DryRun }}
;