Skip to main content

vpcs

Creates, updates, deletes or gets a vpc resource or lists vpcs in a region

Overview

Namevpcs
TypeResource
DescriptionSpecifies a virtual private cloud (VPC).
You can optionally request an IPv6 CIDR block for the VPC. You can request an Amazon-provided IPv6 CIDR block from Amazon's pool of IPv6 addresses, or an IPv6 CIDR block from an IPv6 address pool that you provisioned through bring your own IP addresses (BYOIP).
For more information, see [Virtual private clouds (VPC)](https://docs.aws.amazon.com/vpc/latest/userguide/configure-your-vpc.html) in the *Amazon VPC User Guide*.
Idaws.ec2.vpcs

Fields

NameDatatypeDescription
vpc_idstring
instance_tenancystringThe allowed tenancy of instances launched into the VPC.
+ default: An instance launched into the VPC runs on shared hardware by default, unless you explicitly specify a different tenancy during instance launch.
+ dedicated: An instance launched into the VPC runs on dedicated hardware by default, unless you explicitly specify a tenancy of host during instance launch. You cannot specify a tenancy of default during instance launch.

Updating InstanceTenancy requires no replacement only if you are updating its value from dedicated to default. Updating InstanceTenancy from default to dedicated requires replacement.
ipv4_netmask_lengthintegerThe netmask length of the IPv4 CIDR you want to allocate to this VPC from an Amazon VPC IP Address Manager (IPAM) pool. For more information about IPAM, see [What is IPAM?](https://docs.aws.amazon.com//vpc/latest/ipam/what-is-it-ipam.html) in the *Amazon VPC IPAM User Guide*.
cidr_block_associationsarray
cidr_blockstringThe IPv4 network range for the VPC, in CIDR notation. For example, 10.0.0.0/16. We modify the specified CIDR block to its canonical form; for example, if you specify 100.68.0.18/18, we modify it to 100.68.0.0/18.
You must specify eitherCidrBlock or Ipv4IpamPoolId.
ipv4_ipam_pool_idstringThe ID of an IPv4 IPAM pool you want to use for allocating this VPC's CIDR. For more information, see [What is IPAM?](https://docs.aws.amazon.com//vpc/latest/ipam/what-is-it-ipam.html) in the *Amazon VPC IPAM User Guide*.
You must specify eitherCidrBlock or Ipv4IpamPoolId.
default_network_aclstring
enable_dns_supportbooleanIndicates whether the DNS resolution is supported for the VPC. If enabled, queries to the Amazon provided DNS server at the 169.254.169.253 IP address, or the reserved IP address at the base of the VPC network range "plus two" succeed. If disabled, the Amazon provided DNS service in the VPC that resolves public DNS hostnames to IP addresses is not enabled. Enabled by default. For more information, see [DNS attributes in your VPC](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-dns.html#vpc-dns-support).
ipv6_cidr_blocksarray
default_security_groupstring
enable_dns_hostnamesbooleanIndicates whether the instances launched in the VPC get DNS hostnames. If enabled, instances in the VPC get DNS hostnames; otherwise, they do not. Disabled by default for nondefault VPCs. For more information, see [DNS attributes in your VPC](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-dns.html#vpc-dns-support).
You can only enable DNS hostnames if you've enabled DNS support.
tagsarrayThe tags for the VPC.
regionstringAWS region.

Methods

NameAccessible byRequired Params
create_resourceINSERTregion
delete_resourceDELETEdata__Identifier, region
update_resourceUPDATEdata__Identifier, data__PatchDocument, region
list_resourcesSELECTregion
get_resourceSELECTdata__Identifier, region

SELECT examples

Gets all vpcs in a region.

SELECT
region,
vpc_id,
instance_tenancy,
ipv4_netmask_length,
cidr_block_associations,
cidr_block,
ipv4_ipam_pool_id,
default_network_acl,
enable_dns_support,
ipv6_cidr_blocks,
default_security_group,
enable_dns_hostnames,
tags
FROM aws.ec2.vpcs
WHERE region = 'us-east-1';

Gets all properties from an individual vpc.

SELECT
region,
vpc_id,
instance_tenancy,
ipv4_netmask_length,
cidr_block_associations,
cidr_block,
ipv4_ipam_pool_id,
default_network_acl,
enable_dns_support,
ipv6_cidr_blocks,
default_security_group,
enable_dns_hostnames,
tags
FROM aws.ec2.vpcs
WHERE region = 'us-east-1' AND data__Identifier = '<VpcId>';

INSERT example

Use the following StackQL query and manifest file to create a new vpc resource, using stack-deploy.

/*+ create */
INSERT INTO aws.ec2.vpcs (
InstanceTenancy,
Ipv4NetmaskLength,
CidrBlock,
Ipv4IpamPoolId,
EnableDnsSupport,
EnableDnsHostnames,
Tags,
region
)
SELECT
'{{ InstanceTenancy }}',
'{{ Ipv4NetmaskLength }}',
'{{ CidrBlock }}',
'{{ Ipv4IpamPoolId }}',
'{{ EnableDnsSupport }}',
'{{ EnableDnsHostnames }}',
'{{ Tags }}',
'{{ region }}';

DELETE example

/*+ delete */
DELETE FROM aws.ec2.vpcs
WHERE data__Identifier = '<VpcId>'
AND region = 'us-east-1';

Permissions

To operate on the vpcs resource, the following permissions are required:

Read

ec2:DescribeVpcs,
ec2:DescribeSecurityGroups,
ec2:DescribeNetworkAcls,
ec2:DescribeVpcAttribute

Create

ec2:CreateVpc,
ec2:DescribeVpcs,
ec2:ModifyVpcAttribute,
ec2:CreateTags

Update

ec2:CreateTags,
ec2:ModifyVpcAttribute,
ec2:DeleteTags,
ec2:ModifyVpcTenancy

List

ec2:DescribeVpcs

Delete

ec2:DeleteVpc,
ec2:DescribeVpcs