CreateImagePipeline - EC2 Image Builder
Services or capabilities described in AWS documentation might vary by Region. To see the differences applicable to the AWS European Sovereign Cloud Region, see the AWS European Sovereign Cloud User Guide.

CreateImagePipeline

Creates a new image pipeline. Use image pipelines to automate the creation and distribution of images. You must specify exactly one recipe for the pipeline, using either a containerRecipeArn or an imageRecipeArn.

Request Syntax

PUT /CreateImagePipeline HTTP/1.1 Content-type: application/json { "clientToken": "string", "containerRecipeArn": "string", "description": "string", "distributionConfigurationArn": "string", "dryRun": boolean, "enhancedImageMetadataEnabled": boolean, "executionRole": "string", "imageRecipeArn": "string", "imageScanningConfiguration": { "ecrConfiguration": { "containerTags": [ "string" ], "repositoryName": "string" }, "imageScanningEnabled": boolean }, "imageTags": { "string" : "string" }, "imageTestsConfiguration": { "imageTestsEnabled": boolean, "timeoutMinutes": number }, "infrastructureConfigurationArn": "string", "loggingConfiguration": { "imageLogGroupName": "string", "pipelineLogGroupName": "string" }, "name": "string", "schedule": { "autoDisablePolicy": { "failureCount": number }, "pipelineExecutionStartCondition": "string", "scheduleExpression": "string", "timezone": "string" }, "status": "string", "tags": { "string" : "string" }, "workflows": [ { "onFailure": "string", "parallelGroup": "string", "parameters": [ { "name": "string", "value": [ "string" ] } ], "workflowArn": "string" } ] }

URI Request Parameters

The request does not use any URI parameters.

Request Body

The request accepts the following data in JSON format.

clientToken

A unique, case-sensitive identifier you provide to ensure that the operation runs no more than one time. If you retry a request with the same client token, Image Builder returns the original response without running the operation again. For more information, see Ensuring idempotency in the Amazon EC2 API Reference.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 64.

Required: Yes

containerRecipeArn

The Amazon Resource Name (ARN) of the container recipe that is used to configure images created by this container pipeline. You must specify either this property or imageRecipeArn, but not both.

Type: String

Pattern: ^arn:aws[^:]*:imagebuilder:[^:]+:(?:[0-9]{12}|aws):container-recipe/[a-z0-9-_]+/(?:[0-9]+|x)\.(?:[0-9]+|x)\.(?:[0-9]+|x)$

Required: No

description

The description of the image pipeline.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 1024.

Required: No

distributionConfigurationArn

The Amazon Resource Name (ARN) of the distribution configuration that configures and distributes images created by this image pipeline.

Type: String

Pattern: ^arn:aws[^:]*:imagebuilder:[^:]+:(?:[0-9]{12}|aws):distribution-configuration/[a-z0-9-_]+$

Required: No

dryRun

Validates the required permissions and request parameters without performing the operation. If validation succeeds, the operation returns a DryRunOperationException error response.

Type: Boolean

Required: No

enhancedImageMetadataEnabled

Specifies whether to collect additional information about the image being created, including the operating system (OS) version and package list. Defaults to true.

Type: Boolean

Required: No

executionRole

The name or Amazon Resource Name (ARN) for the IAM role you create that grants Image Builder access to perform workflow actions.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 2048.

Pattern: ^(?:arn:aws(?:-[a-z]+)*:iam::[0-9]{12}:role/)?[a-zA-Z_0-9+=,.@\-_/]+$

Required: No

imageRecipeArn

The Amazon Resource Name (ARN) of the image recipe that configures images created by this image pipeline. You must specify either this property or containerRecipeArn, but not both.

Type: String

Pattern: ^arn:aws[^:]*:imagebuilder:[^:]+:(?:[0-9]{12}|aws):image-recipe/[a-z0-9-_]+/(?:[0-9]+|x)\.(?:[0-9]+|x)\.(?:[0-9]+|x)$

Required: No

imageScanningConfiguration

Contains settings for vulnerability scans that Amazon Inspector runs against the test instance during image creation.

Type: ImageScanningConfiguration object

Required: No

imageTags

The tags that Image Builder applies to the Image Builder image resource that this pipeline's scheduled executions create. These tags don't apply to the output AMI. To tag output AMIs, use amiTags in the pipeline's distribution configuration.

Type: String to string map

Map Entries: Maximum number of 50 items.

Key Length Constraints: Minimum length of 1. Maximum length of 128.

Key Pattern: ^(?!aws:)[a-zA-Z0-9\s_.:/=+\-@]*$

Value Length Constraints: Maximum length of 256.

Required: No

imageTestsConfiguration

Specifies the test settings that Image Builder applies to images that this pipeline creates. If you don't provide test settings, Image Builder stores a default configuration with image tests enabled.

Type: ImageTestsConfiguration object

Required: No

infrastructureConfigurationArn

The Amazon Resource Name (ARN) of the infrastructure configuration that builds images created by this image pipeline.

Type: String

Pattern: ^arn:aws[^:]*:imagebuilder:[^:]+:(?:[0-9]{12}|aws):infrastructure-configuration/[a-z0-9-_]+$

Required: Yes

loggingConfiguration

Specifies the logging configuration for the image pipeline. Use this to define custom CloudWatch Logs log groups for your pipeline execution logs and image build logs. The service manages log groups with names starting with /aws/imagebuilder/ using the service-linked role. For custom log group names outside of this prefix, you must also provide an executionRole.

Type: PipelineLoggingConfiguration object

Required: No

name

The name of the image pipeline. Pipeline names must be unique to your account in each AWS Region. Image Builder generates the pipeline ARN from a normalized form of the name, so names that differ only in case, spaces, or underscores count as the same name.

Type: String

Pattern: ^[-_A-Za-z-0-9][-_A-Za-z0-9 ]{1,126}[-_A-Za-z-0-9]$

Required: Yes

schedule

The schedule of the image pipeline. If you don't provide a schedule, the pipeline runs only when you call StartImagePipelineExecution.

Type: Schedule object

Required: No

status

The status of the image pipeline. If you don't specify a status, it defaults to ENABLED. A disabled pipeline doesn't run on its schedule, but you can still start builds manually.

Type: String

Valid Values: DISABLED | ENABLED

Required: No

tags

The tags of the image pipeline.

Type: String to string map

Map Entries: Maximum number of 50 items.

Key Length Constraints: Minimum length of 1. Maximum length of 128.

Key Pattern: ^(?!aws:)[a-zA-Z0-9\s_.:/=+\-@]*$

Value Length Constraints: Maximum length of 256.

Required: No

workflows

The array of workflow configuration objects for builds that this pipeline starts. You must also specify executionRole when you provide workflows.

Type: Array of WorkflowConfiguration objects

Required: No

Response Syntax

HTTP/1.1 200 Content-type: application/json { "clientToken": "string", "imagePipelineArn": "string", "requestId": "string" }

Response Elements

If the action is successful, the service sends back an HTTP 200 response.

The following data is returned in JSON format by the service.

clientToken

The client token that uniquely identifies the request.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 64.

imagePipelineArn

The Amazon Resource Name (ARN) of the image pipeline that was created by this request.

Type: String

Pattern: ^arn:aws[^:]*:imagebuilder:[^:]+:(?:[0-9]{12}|aws):image-pipeline/[a-z0-9-_]+$

requestId

The request ID that uniquely identifies this request.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 1024.

Errors

For information about the errors that are common to all actions, see Common Error Types.

CallRateLimitExceededException

You have exceeded the permitted request rate for the Amazon EC2 APIs that Image Builder calls on your behalf. Retry with an increasing or variable delay between requests.

HTTP Status Code: 429

ClientException

A generic client error. This error usually indicates that the request failed a validation check, such as when a downstream service rejects a configured value.

HTTP Status Code: 400

DryRunOperationException

The dry run operation of the resource was successful, and no resources or mutations were actually performed due to the dry run flag in the request.

HTTP Status Code: 412

ForbiddenException

You are not authorized to perform the requested operation.

HTTP Status Code: 403

IdempotentParameterMismatchException

You have specified a client token for an operation using parameter values that differ from a previous request that used the same client token.

HTTP Status Code: 400

InvalidRequestException

The request is malformed or otherwise invalid. Verify the request and try again.

HTTP Status Code: 400

ResourceAlreadyExistsException

The resource that you are trying to create already exists.

HTTP Status Code: 400

ResourceInUseException

The resource that you are trying to operate on is currently in use. Review the message details and retry later.

HTTP Status Code: 400

ServiceException

An internal server error occurred while Image Builder processed the request. Retrying the request may succeed.

HTTP Status Code: 500

ServiceQuotaExceededException

You have exceeded the number of permitted resources or operations for this service. For service quotas, see EC2 Image Builder endpoints and quotas.

HTTP Status Code: 402

ServiceUnavailableException

The service is unable to process your request at this time.

HTTP Status Code: 503

Examples

Create an image pipeline

The following example creates a pipeline that builds a new image version every Sunday at 9:00 AM UTC, if the base image or components have updates.

Sample Request

PUT /CreateImagePipeline HTTP/1.1 Content-type: application/json { "name": "my-example-pipeline", "description": "Builds a new version of my image every Sunday", "imageRecipeArn": "arn:aws:imagebuilder:us-west-2:111122223333:image-recipe/my-example-recipe/1.0.0", "infrastructureConfigurationArn": "arn:aws:imagebuilder:us-west-2:111122223333:infrastructure-configuration/my-example-infrastructure", "distributionConfigurationArn": "arn:aws:imagebuilder:us-west-2:111122223333:distribution-configuration/my-example-distribution", "schedule": { "scheduleExpression": "cron(0 9 ? * SUN *)", "pipelineExecutionStartCondition": "EXPRESSION_MATCH_AND_DEPENDENCY_UPDATES_AVAILABLE" }, "status": "ENABLED", "clientToken": "a1b2c3d4-5678-90ab-cdef-EXAMPLE55555" }

Sample Response

HTTP/1.1 200 Content-type: application/json { "requestId": "db0a9329-35ef-4b53-98d0-a34385e44e28", "clientToken": "a1b2c3d4-5678-90ab-cdef-EXAMPLE55555", "imagePipelineArn": "arn:aws:imagebuilder:us-west-2:111122223333:image-pipeline/my-example-pipeline" }

Create an image pipeline with scanning, custom workflows, and an auto-disable policy

The following example creates a pipeline that uses your custom build workflow and enables image scanning. The schedule evaluates its cron expression in the America/Los_Angeles time zone. The auto-disable policy disables the pipeline after 3 consecutive failed scheduled builds.

Sample Request

PUT /CreateImagePipeline HTTP/1.1 Content-type: application/json { "name": "my-example-pipeline", "description": "Builds a scanned image with my custom build workflow on Sunday mornings when dependency updates are available", "imageRecipeArn": "arn:aws:imagebuilder:us-west-2:111122223333:image-recipe/my-example-recipe/1.1.0", "infrastructureConfigurationArn": "arn:aws:imagebuilder:us-west-2:111122223333:infrastructure-configuration/my-example-infrastructure", "distributionConfigurationArn": "arn:aws:imagebuilder:us-west-2:111122223333:distribution-configuration/my-example-distribution", "workflows": [ { "workflowArn": "arn:aws:imagebuilder:us-west-2:111122223333:workflow/build/my-example-workflow/1.0.0/1" } ], "executionRole": "arn:aws:iam::111122223333:role/aws-service-role/imagebuilder.amazonaws.com/AWSServiceRoleForImageBuilder", "imageScanningConfiguration": { "imageScanningEnabled": true }, "schedule": { "scheduleExpression": "cron(0 9 ? * SUN *)", "timezone": "America/Los_Angeles", "pipelineExecutionStartCondition": "EXPRESSION_MATCH_AND_DEPENDENCY_UPDATES_AVAILABLE", "autoDisablePolicy": { "failureCount": 3 } }, "status": "ENABLED", "clientToken": "a1b2c3d4-5678-90ab-cdef-EXAMPLE30303" }

Sample Response

HTTP/1.1 200 Content-type: application/json { "requestId": "f8da3ec9-4b76-4aa3-817a-c35a90f59dca", "clientToken": "a1b2c3d4-5678-90ab-cdef-EXAMPLE30303", "imagePipelineArn": "arn:aws:imagebuilder:us-west-2:111122223333:image-pipeline/my-example-pipeline" }

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following: