PutImagePolicy
Applies a policy to an image. The preferred way to share resources is with the RAM API CreateResourceShare. If you use the PutImagePolicy operation instead, you must also call the RAM API PromoteResourceShareCreatedFromPolicy. Otherwise, the resource isn't visible to the principals that it's shared with.
Request Syntax
PUT /PutImagePolicy HTTP/1.1
Content-type: application/json
{
"imageArn": "string",
"policy": "string"
}
URI Request Parameters
The request does not use any URI parameters.
Request Body
The request accepts the following data in JSON format.
- imageArn
-
The Amazon Resource Name (ARN) of the image that this policy should be applied to.
Type: String
Pattern:
^arn:aws[^:]*:imagebuilder:[^:]+:(?:[0-9]{12}|aws(?:-[a-z-]+)?):image/[a-z0-9-_]+/[0-9]+\.[0-9]+\.[0-9]+/[0-9]+$Required: Yes
- policy
-
The resource policy to apply to the image, as a JSON policy document. Image Builder validates the policy with Amazon RAM before applying it, and rejects invalid policies with
InvalidParameterValueException.Type: String
Length Constraints: Minimum length of 1. Maximum length of 30000.
Required: Yes
Response Syntax
HTTP/1.1 200
Content-type: application/json
{
"imageArn": "string",
"requestId": "string"
}
Response Elements
If the action is successful, the service sends back an HTTP 200 response.
The following data is returned in JSON format by the service.
- imageArn
-
The Amazon Resource Name (ARN) of the image that this policy was applied to.
Type: String
Pattern:
^arn:aws[^:]*:imagebuilder:[^:]+:(?:[0-9]{12}|aws(?:-[a-z-]+)?):image/[a-z0-9-_]+/[0-9]+\.[0-9]+\.[0-9]+/[0-9]+$ - requestId
-
The request ID that uniquely identifies this request.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 1024.
Errors
For information about the errors that are common to all actions, see Common Error Types.
- CallRateLimitExceededException
-
You have exceeded the permitted request rate for the Amazon EC2 APIs that Image Builder calls on your behalf. Retry with an increasing or variable delay between requests.
HTTP Status Code: 429
- ClientException
-
A generic client error. This error usually indicates that the request failed a validation check, such as when a downstream service rejects a configured value.
HTTP Status Code: 400
- ForbiddenException
-
You are not authorized to perform the requested operation.
HTTP Status Code: 403
- InvalidParameterValueException
-
The value that you provided for the specified parameter is invalid.
HTTP Status Code: 400
- InvalidRequestException
-
The request is malformed or otherwise invalid. Verify the request and try again.
HTTP Status Code: 400
- ResourceNotFoundException
-
At least one of the resources referenced by your request does not exist.
HTTP Status Code: 404
- ServiceException
-
An internal server error occurred while Image Builder processed the request. Retrying the request may succeed.
HTTP Status Code: 500
- ServiceUnavailableException
-
The service is unable to process your request at this time.
HTTP Status Code: 503
Examples
Share an image with another
The following example applies a resource policy to an image build version that grants another Amazon Web Services account permission to view the image.
Sample Request
PUT /PutImagePolicy HTTP/1.1
Content-type: application/json
{
"imageArn": "arn:aws:imagebuilder:us-west-2:111122223333:image/my-example-recipe/1.0.0/1",
"policy": "{\"Version\": \"2012-10-17\", \"Statement\": [{\"Effect\": \"Allow\", \"Principal\": {\"AWS\": \"arn:aws:iam::444455556666:root\"}, \"Action\": [\"imagebuilder:GetImage\", \"imagebuilder:ListImages\"], \"Resource\": [\"arn:aws:imagebuilder:us-west-2:111122223333:image/my-example-recipe/1.0.0/1\"]}]}"
}
Sample Response
HTTP/1.1 200
Content-type: application/json
{
"requestId": "7bbf7e76-0f08-430d-b77e-17c161725825",
"imageArn": "arn:aws:imagebuilder:us-west-2:111122223333:image/my-example-recipe/1.0.0/1"
}
See Also
For more information about using this API in one of the language-specific Amazon SDKs, see the following: