EC2 / Client / create_ipam_internet_registry_association

create_ipam_internet_registry_association

EC2.Client.create_ipam_internet_registry_association(**kwargs)

Creates an association between an IPAM and a Regional Internet Registry (RIR) for Resource Public Key Infrastructure (RPKI) management. You can use this association to create Route Origin Authorizations (ROAs) for IP address prefixes registered with the internet registry. Your IPAM must be in the Advanced tier to use this feature.

See also: AWS API Documentation

Request Syntax

response = client.create_ipam_internet_registry_association(
    DryRun=True|False,
    IpamId='string',
    Rir='ripe'|'apnic'|'arin'|'lacnic',
    OrganizationHandle='string',
    Description='string',
    TagSpecifications=[
        {
            'ResourceType': 'capacity-reservation'|'client-vpn-endpoint'|'customer-gateway'|'carrier-gateway'|'coip-pool'|'declarative-policies-report'|'dedicated-host'|'dhcp-options'|'egress-only-internet-gateway'|'elastic-ip'|'elastic-gpu'|'export-image-task'|'export-instance-task'|'fleet'|'fpga-image'|'host-reservation'|'image'|'image-usage-report'|'import-image-task'|'import-snapshot-task'|'instance'|'instance-event-window'|'internet-gateway'|'ipam'|'ipam-pool'|'ipam-scope'|'ipv4pool-ec2'|'ipv6pool-ec2'|'key-pair'|'launch-template'|'local-gateway'|'local-gateway-route-table'|'local-gateway-virtual-interface'|'local-gateway-virtual-interface-group'|'local-gateway-route-table-vpc-association'|'local-gateway-route-table-virtual-interface-group-association'|'natgateway'|'network-acl'|'network-interface'|'network-insights-analysis'|'network-insights-path'|'network-insights-access-scope'|'network-insights-access-scope-analysis'|'outpost-lag'|'placement-group'|'prefix-list'|'replace-root-volume-task'|'reserved-instances'|'route-table'|'security-group'|'security-group-rule'|'service-link-virtual-interface'|'snapshot'|'spot-fleet-request'|'spot-instances-request'|'subnet'|'subnet-cidr-reservation'|'traffic-mirror-filter'|'traffic-mirror-session'|'traffic-mirror-target'|'transit-gateway'|'transit-gateway-attachment'|'transit-gateway-connect-peer'|'transit-gateway-multicast-domain'|'transit-gateway-policy-table'|'transit-gateway-metering-policy'|'transit-gateway-route-table'|'transit-gateway-route-table-announcement'|'volume'|'vpc'|'vpc-endpoint'|'vpc-endpoint-connection'|'vpc-endpoint-service'|'vpc-endpoint-service-permission'|'vpc-peering-connection'|'vpn-connection'|'vpn-gateway'|'vpc-flow-log'|'capacity-reservation-fleet'|'traffic-mirror-filter-rule'|'vpc-endpoint-connection-device-type'|'verified-access-instance'|'verified-access-group'|'verified-access-endpoint'|'verified-access-policy'|'verified-access-trust-provider'|'vpn-connection-device-type'|'vpc-block-public-access-exclusion'|'vpc-encryption-control'|'route-server'|'route-server-endpoint'|'route-server-peer'|'ipam-resource-discovery'|'ipam-resource-discovery-association'|'instance-connect-endpoint'|'verified-access-endpoint-target'|'ipam-external-resource-verification-token'|'capacity-block'|'mac-modification-task'|'ipam-prefix-list-resolver'|'ipam-policy'|'ipam-prefix-list-resolver-target'|'ipam-internet-registry-association'|'secondary-interface'|'secondary-network'|'secondary-subnet'|'capacity-manager-data-export'|'vpn-concentrator'|'ipam-pool-allocation'|'capacity-reservation-cancellation-quote'|'application-status-check',
            'Tags': [
                {
                    'Key': 'string',
                    'Value': 'string'
                },
            ]
        },
    ],
    ClientToken='string'
)
Parameters:
  • DryRun (boolean) – Checks whether you have the required permissions for the operation, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

  • IpamId (string) –

    [REQUIRED]

    The ID of the IPAM to associate with the internet registry.

  • Rir (string) –

    [REQUIRED]

    The Regional Internet Registry to associate with. Possible values:

    • ripe - RIPE NCC (Europe, the Middle East, and Central Asia).

    • apnic - APNIC (Asia Pacific).

    • arin - ARIN (North America).

    • lacnic - LACNIC (Latin America and the Caribbean).

  • OrganizationHandle (string) –

    [REQUIRED]

    The organization handle at the internet registry (for example, a RIPE NCC organization ID or ARIN Org ID).

  • Description (string) – A description for the internet registry association.

  • TagSpecifications (list) –

    The tags to assign to the internet registry association.

    • (dict) –

      The tags to apply to a resource when the resource is being created. When you specify a tag, you must specify the resource type to tag, otherwise the request will fail.

      Note

      The Valid Values lists all the resource types that can be tagged. However, the action you’re using might not support tagging all of these resource types. If you try to tag a resource type that is unsupported for the action you’re using, you’ll get an error.

      • ResourceType (string) –

        The type of resource to tag on creation.

      • Tags (list) –

        The tags to apply to the resource.

        • (dict) –

          Describes a tag.

          • Key (string) –

            The key of the tag.

            Constraints: Tag keys are case-sensitive and accept a maximum of 127 Unicode characters. May not begin with aws:.

          • Value (string) –

            The value of the tag.

            Constraints: Tag values are case-sensitive and accept a maximum of 256 Unicode characters.

  • ClientToken (string) –

    A unique, case-sensitive identifier to ensure that the operation completes no more than one time. If this token matches a previous request, the operation ignores the request, but does not return an error.

    This field is autopopulated if not provided.

Return type:

dict

Returns:

Response Syntax

{
    'IpamInternetRegistryAssociation': {
        'OwnerId': 'string',
        'IpamInternetRegistryAssociationId': 'string',
        'IpamInternetRegistryAssociationArn': 'string',
        'IpamId': 'string',
        'IpamRegion': 'string',
        'Rir': 'ripe'|'apnic'|'arin'|'lacnic',
        'OrganizationHandle': 'string',
        'Description': 'string',
        'State': 'pending-enable'|'create-in-progress'|'create-failed'|'enable-in-progress'|'enable-complete'|'enable-failed'|'delete-in-progress'|'delete-complete'|'delete-failed',
        'ChildRequestXml': 'string',
        'Tags': [
            {
                'Key': 'string',
                'Value': 'string'
            },
        ]
    }
}

Response Structure

  • (dict) –

    • IpamInternetRegistryAssociation (dict) –

      Information about the internet registry association.

      • OwnerId (string) –

        The ID of the Amazon Web Services account that owns the internet registry association.

      • IpamInternetRegistryAssociationId (string) –

        The ID of the internet registry association.

      • IpamInternetRegistryAssociationArn (string) –

        The Amazon Resource Name (ARN) of the internet registry association.

      • IpamId (string) –

        The ID of the associated IPAM.

      • IpamRegion (string) –

        The Amazon Web Services Region of the IPAM.

      • Rir (string) –

        The Regional Internet Registry. Possible values:

        • ripe - RIPE NCC (Europe, the Middle East, and Central Asia).

        • apnic - APNIC (Asia Pacific).

        • arin - ARIN (North America).

        • lacnic - LACNIC (Latin America and the Caribbean).

      • OrganizationHandle (string) –

        The organization handle at the internet registry.

      • Description (string) –

        The description of the internet registry association.

      • State (string) –

        The state of the internet registry association. Valid values: pending-activation | pending-enable | create-in-progress | create-failed | enable-in-progress | enable-complete | enable-failed | delete-in-progress | delete-complete | delete-failed.

      • ChildRequestXml (string) –

        The XML content for the child request to be submitted to the internet registry to complete the BPKI setup.

      • Tags (list) –

        The tags assigned to the internet registry association.

        • (dict) –

          Describes a tag.

          • Key (string) –

            The key of the tag.

            Constraints: Tag keys are case-sensitive and accept a maximum of 127 Unicode characters. May not begin with aws:.

          • Value (string) –

            The value of the tag.

            Constraints: Tag values are case-sensitive and accept a maximum of 256 Unicode characters.