Removes an endpoint from a security group by calling the DetachSecurityGroupFromVpcEndpoint operation.
Operation description
-
DetachSecurityGroupFromVpcEndpoint is an asynchronous operation. After a request is sent, the system returns a request ID, but the endpoint has not yet been removed from the security group. The removal task continues in the background. You can call ListVpcEndpoints to query the removal status of the endpoint:
If the endpoint is in the Pending state, the endpoint is being removed.
If the endpoint cannot be found in the security group, the endpoint has been removed.
-
DetachSecurityGroupFromVpcEndpoint does not support concurrently removing the same endpoint instance from a security group.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
privatelink:DetachSecurityGroupFromVpcEndpoint |
update |
*VpcEndpoint
*SecurityGroup
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| RegionId |
string |
Yes |
The region ID of the endpoint that you want to remove from the security group. You can call DescribeRegions to query the most recent region list. |
eu-west-1 |
| SecurityGroupId |
string |
Yes |
The ID of the security group from which you want to remove the endpoint. |
sg-hp3c8qj1tyct90ej**** |
| EndpointId |
string |
Yes |
The ID of the endpoint that you want to remove from the security group. |
ep-hp33b2e43fays7s8**** |
| DryRun |
boolean |
No |
Specifies whether to perform a dry run. Valid values:
|
false |
| ClientToken |
string |
No |
The client token that is used to ensure the idempotence of the request. You can use the client to generate the token, but you must make sure that the token is unique among different requests. The ClientToken value can contain only ASCII characters. |
0c593ea1-3bea-11e9-b96b-88e9fe637760 |
| RegionId |
string |
Yes |
The region ID of the endpoint that you want to disassociate from the security group. You can call the DescribeRegions operation to query the most recent region list. |
eu-west-1 |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
The request ID. |
8D778FF9-7640-4C13-BCD6-9265CA9A2F81 |
Examples
Success response
JSON format
{
"RequestId": "8D778FF9-7640-4C13-BCD6-9265CA9A2F81"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | SecurityGroupNotFound | The specified security group does not exist. | The specified security group does not exist. |
| 400 | EndpointMustContainSecurityGroup | The specified endpoint must have at least one security group. | The specified endpoint must have at least one security group. |
| 400 | EndpointNotFound | The specified Endpoint does not exist. | The specified Endpoint does not exist. |
| 400 | EndpointOperationDenied | The specified operation of endpoint is not allowed. | The specified operation of endpoint is not allowed. |
| 400 | EndpointLocked | The specified Endpoint is locked. | The specified Endpoint is locked. |
| 400 | EndpointConnectionOperationDenied | The endpoint is being connected. | The endpoint is being connected. |
| 400 | EndpointServiceDeleted | The specified Service is already deleted. | The specified Service is already deleted. |
| 400 | GatewayLoadBalancerNotSupportSecurityGroup | The gateway load balancer not support security group. | The gateway load balancer type does not support setting a security group. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.