imagebuilder / Client / update_image_pipeline

update_image_pipeline

imagebuilder.Client.update_image_pipeline(**kwargs)

Updates an image pipeline. Use image pipelines to automate the creation and distribution of images. You must specify exactly one recipe for your image, using either a containerRecipeArn or an imageRecipeArn. The recipe must be the same type, image or container, as the pipeline’s current recipe.

Note

UpdateImagePipeline does not support selective updates. The request replaces the pipeline’s entire configuration, so include every setting that you want to keep. Any optional property that you omit is removed or reset to its default.

See also: AWS API Documentation

Request Syntax

response = client.update_image_pipeline(
    imagePipelineArn='string',
    description='string',
    imageRecipeArn='string',
    containerRecipeArn='string',
    infrastructureConfigurationArn='string',
    distributionConfigurationArn='string',
    imageTestsConfiguration={
        'imageTestsEnabled': True|False,
        'timeoutMinutes': 123
    },
    enhancedImageMetadataEnabled=True|False,
    schedule={
        'scheduleExpression': 'string',
        'timezone': 'string',
        'pipelineExecutionStartCondition': 'EXPRESSION_MATCH_ONLY'|'EXPRESSION_MATCH_AND_DEPENDENCY_UPDATES_AVAILABLE',
        'autoDisablePolicy': {
            'failureCount': 123
        }
    },
    status='DISABLED'|'ENABLED',
    clientToken='string',
    imageScanningConfiguration={
        'imageScanningEnabled': True|False,
        'ecrConfiguration': {
            'repositoryName': 'string',
            'containerTags': [
                'string',
            ]
        }
    },
    workflows=[
        {
            'workflowArn': 'string',
            'parameters': [
                {
                    'name': 'string',
                    'value': [
                        'string',
                    ]
                },
            ],
            'parallelGroup': 'string',
            'onFailure': 'CONTINUE'|'ABORT'
        },
    ],
    loggingConfiguration={
        'imageLogGroupName': 'string',
        'pipelineLogGroupName': 'string'
    },
    executionRole='string',
    imageTags={
        'string': 'string'
    }
)
Parameters:
  • imagePipelineArn (string) –

    [REQUIRED]

    The Amazon Resource Name (ARN) of the image pipeline that you want to update.

  • description (string) – The description of the image pipeline.

  • imageRecipeArn (string) – The Amazon Resource Name (ARN) of the image recipe that configures images created by this image pipeline. You must specify either this property or containerRecipeArn, but not both.

  • containerRecipeArn (string) – The Amazon Resource Name (ARN) of the container recipe that is used to configure images created by this container pipeline. You must specify either this property or imageRecipeArn, but not both.

  • infrastructureConfigurationArn (string) –

    [REQUIRED]

    The Amazon Resource Name (ARN) of the infrastructure configuration that Image Builder uses to build images created by this image pipeline.

  • distributionConfigurationArn (string) – The Amazon Resource Name (ARN) of the distribution configuration that Image Builder uses to configure and distribute images created by this image pipeline.

  • imageTestsConfiguration (dict) –

    Specifies the test settings that Image Builder applies to images that this pipeline creates. If you don’t provide test settings, Image Builder stores a default configuration with image tests enabled.

    • imageTestsEnabled (boolean) –

      Specifies whether tests run after building the image. When enabled, tests run after the image build and before image distribution. Defaults to true.

    • timeoutMinutes (integer) –

      The maximum time in minutes that tests are permitted to run. If you don’t specify a value, Image Builder stores and returns 720.

      Note

      The timeout property is not currently active. This value is ignored.

  • enhancedImageMetadataEnabled (boolean) – Specifies whether to collect additional information about the image being created, including the operating system (OS) version and package list. Defaults to true.

  • schedule (dict) –

    The schedule of the image pipeline. Because the update replaces the entire configuration, omitting this property removes any existing schedule. The pipeline then runs only when you call StartImagePipelineExecution.

    • scheduleExpression (string) –

      The expression determines how often EC2 Image Builder evaluates your pipelineExecutionStartCondition. You can specify a cron expression, or a rate expression such as rate(1 day).

      For information on how to format a cron expression in Image Builder, see Use cron expressions in EC2 Image Builder.

    • timezone (string) –

      The timezone that applies to the scheduling expression. Specify a value in IANA timezone format, for example Etc/UTC or America/Los_Angeles. If not specified, this defaults to UTC.

    • pipelineExecutionStartCondition (string) –

      The start condition configures when the pipeline should trigger a new image build, as follows. If no value is set Image Builder defaults to EXPRESSION_MATCH_AND_DEPENDENCY_UPDATES_AVAILABLE.

      • EXPRESSION_MATCH_AND_DEPENDENCY_UPDATES_AVAILABLE (default) – When you use semantic version filters on the base image or components in your image recipe, EC2 Image Builder builds a new image only when there are new versions of the base image or components in your recipe that match the filter.

      Note

      For semantic version syntax, see CreateComponent.

      • EXPRESSION_MATCH_ONLY – This condition builds a new image every time the CRON expression matches the current time.

      Note

      If the recipe references its base image through an Amazon Web Services Systems Manager Parameter Store parameter, a change in the parameter’s value also counts as an available dependency update.

    • autoDisablePolicy (dict) –

      The policy that configures when Image Builder should automatically disable a pipeline that is failing.

      • failureCount (integer) – [REQUIRED]

        The number of consecutive scheduled image pipeline executions that must fail before Image Builder automatically disables the pipeline.

  • status (string) – The status of the image pipeline. Defaults to ENABLED when omitted. To keep a pipeline disabled, include this property set to DISABLED in your update request.

  • clientToken (string) –

    [REQUIRED]

    A unique, case-sensitive identifier you provide to ensure that the operation runs no more than one time. If you retry a request with the same client token, Image Builder returns the original response without running the operation again. For more information, see Ensuring idempotency in the Amazon EC2 API Reference.

    This field is autopopulated if not provided.

  • imageScanningConfiguration (dict) –

    Contains settings for vulnerability scans that Amazon Inspector runs against the test instance during image creation.

    • imageScanningEnabled (boolean) –

      Specifies whether Amazon Inspector scans for vulnerabilities when you create a new image, and whether Image Builder saves the findings. Amazon Inspector must be enabled in the account. Image tests must also be enabled. For AMI output, Amazon Inspector scans the test instance. For container output, Amazon Inspector scans the container image that Image Builder pushes to the Amazon ECR repository from your ecrConfiguration settings.

    • ecrConfiguration (dict) –

      Contains Amazon ECR settings for vulnerability scans.

      • repositoryName (string) –

        The name of the container repository where Image Builder pushes the container image for the vulnerability scan. Provide the repository name only (a namespace path is allowed, but not the registry hostname); the repository must already exist in your account. If you don’t specify a repository name, Image Builder creates the default repository image-builder-image-scanning-repository in your account.

      • containerTags (list) –

        Tags for Image Builder to apply to the output container image that Amazon Inspector scans. Tags can help you identify and manage your scanned images.

        • (string) –

  • workflows (list) –

    The array of workflow configuration objects for builds that this pipeline starts. You must also specify executionRole when you provide workflows.

    • (dict) –

      Contains control settings and configurable inputs for a workflow resource.

      • workflowArn (string) – [REQUIRED]

        The Amazon Resource Name (ARN) of the workflow resource.

      • parameters (list) –

        Contains parameter values for each of the parameters that the workflow document defined for the workflow resource.

        • (dict) –

          Contains a key/value pair that sets the named workflow parameter.

          • name (string) – [REQUIRED]

            The name of the workflow parameter to set.

          • value (list) – [REQUIRED]

            Sets the value for the named workflow parameter.

            • (string) –

      • parallelGroup (string) –

        Test workflows are defined within named runtime groups called parallel groups. The parallel group is the named group that contains this test workflow. Test workflows within a parallel group can run at the same time. Image Builder starts up to five test workflows in the group at the same time, and starts additional workflows as others complete, until all workflows in the group have completed. This field only applies for test workflows.

      • onFailure (string) –

        The action to take if the workflow fails. With CONTINUE, a failed workflow is logged and image creation proceeds to the next workflow. If you don’t set a value, the image build fails when the workflow fails. You can only set this property for test workflows.

  • loggingConfiguration (dict) –

    Specifies the logging configuration for the image pipeline. Use this to define custom CloudWatch Logs log groups for your pipeline execution logs and image build logs. The service manages log groups with names starting with /aws/imagebuilder/ using the service-linked role. For custom log group names outside of this prefix, you must also provide an executionRole.

    • imageLogGroupName (string) –

      Specifies the CloudWatch Logs log group name for image build logs. The log group name can contain alphanumeric characters, hyphens, underscores, forward slashes, and periods, up to 512 characters. Log group names not starting with /aws/imagebuilder/ require an executionRole with CloudWatch Logs write permissions. If not specified, defaults to /aws/imagebuilder/image-name.

    • pipelineLogGroupName (string) –

      Specifies the CloudWatch Logs log group name for pipeline execution logs. The log group name can contain alphanumeric characters, hyphens, underscores, forward slashes, and periods, up to 512 characters. Log group names not starting with /aws/imagebuilder/ require an executionRole with CloudWatch Logs write permissions. If not specified, defaults to /aws/imagebuilder/pipeline/pipeline-name.

  • executionRole (string) – The name or Amazon Resource Name (ARN) for the IAM role you create that grants Image Builder access to perform workflow actions. If you omit this property, the pipeline reverts to the Image Builder service-linked role.

  • imageTags (dict) –

    The tags that Image Builder applies to the Image Builder image resource that this pipeline’s scheduled executions create. These tags don’t apply to the output AMI. To tag output AMIs, use amiTags in the pipeline’s distribution configuration.

    • (string) –

      • (string) –

Return type:

dict

Returns:

Response Syntax

{
    'requestId': 'string',
    'clientToken': 'string',
    'imagePipelineArn': 'string'
}

Response Structure

  • (dict) –

    • requestId (string) –

      The request ID that uniquely identifies this request.

    • clientToken (string) –

      The client token that uniquely identifies the request.

    • imagePipelineArn (string) –

      The Amazon Resource Name (ARN) of the image pipeline that was updated by this request.

Exceptions

  • imagebuilder.Client.exceptions.ServiceException

  • imagebuilder.Client.exceptions.ClientException

  • imagebuilder.Client.exceptions.ServiceUnavailableException

  • imagebuilder.Client.exceptions.InvalidRequestException

  • imagebuilder.Client.exceptions.IdempotentParameterMismatchException

  • imagebuilder.Client.exceptions.ForbiddenException

  • imagebuilder.Client.exceptions.CallRateLimitExceededException

  • imagebuilder.Client.exceptions.ResourceInUseException