OrchestrAI Live

AWS · Cloud service

EC2 Image Builder with OrchestrAI

Catalog exported 2026-09-02

Set up EC2 Image Builder from chat: image recipes, infrastructure configurations, and AMI pipelines.

OrchestrAI exposes 3 Image Builder operations: 2 are low-risk (read-only or low-impact), and 1 create or modify resources and run only after you confirm the plan.

3operations
2low risk
1create or modify
0destructive
0step-level approval

What teams use it for

Teams that maintain golden AMIs use OrchestrAI to define an image recipe from a parent image and components, create the infrastructure configuration that says which instance type and subnet builds run on, and create a pipeline that produces new AMIs on a schedule. Recipe and infrastructure configuration creation are low risk; pipeline creation is medium risk. There is no operation to create components, start a pipeline execution, or list built images, so triggering a build and finding the resulting AMI happens in the console.

Every Image Builder operation, with its risk level

EC2 Image Builder operations available through OrchestrAI
Operation What it does Risk Step-level approval
Create Image Builder Infrastructure Config Create AWS Image Builder infrastructure configuration for building images Low risk No
Create Image Builder Recipe Create an AWS Image Builder image recipe for building custom AMIs Low risk No
Create Image Builder Pipeline Create an AWS Image Builder image pipeline for automated AMI builds Creates resources No

Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.

Prompts that work

  • Create an Image Builder recipe named hardened-al2023 based on Amazon Linux 2023 with the update-linux and stig-build components
  • Create an infrastructure configuration that builds on t3.large in the build-subnet with the imagebuilder-role instance profile
  • Create an image pipeline that builds hardened-al2023 every Sunday at 02:00

Before anything runs

Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.

Frequently asked questions

Can OrchestrAI trigger an Image Builder pipeline run?
No, it creates the recipe, infrastructure configuration, and pipeline, but starting an execution is done in the console.
Does OrchestrAI create Image Builder components?
Not currently; recipes reference existing components, either AWS-managed or ones you have already published.
Which Image Builder operations need an extra approval step?
None of the Image Builder operations currently carries a step-level approval gate; they are read-only or run after plan confirmation like any other change.

Other AWS services

Related integrations

Try it on your own account

Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.

Start for $5

Unused credits refunded in your first 14 days.