Skip to content

aws.ssm.get_parameter_history

Example SQL Queries

SELECT * FROM
aws.ssm.get_parameter_history
WHERE
"name" = 'VALUE';

Description

Retrieves the history of all changes to a parameter.

If you change the KMS key alias for the KMS key used to encrypt a parameter, then you must also update the key alias the parameter uses to reference KMS. Otherwise, GetParameterHistory retrieves whatever the original key alias was referencing.

Table Definition

Column NameColumn Data Type
name Required Input Column

The name of the parameter.

VARCHAR
with_decryption Input Column

Return decrypted values for secure string parameters. This flag is ignored for String and StringList parameter types.

BOOLEAN
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
allowed_pattern

Parameter names can include the following letters and symbols.

a-zA-Z0-9_.-

VARCHAR
data_type

The data type of the parameter, such as text or aws:ec2:image. The default is text.

VARCHAR
description

Information about the parameter.

VARCHAR
key_id

The alias of the Key Management Service (KMS) key used to encrypt the parameter. Applies to SecureString parameters only

VARCHAR
labels

Labels assigned to the parameter version.

VARCHAR[]
Show child fields
labels[]
last_modified_date

Date the parameter was last changed or updated.

TIMESTAMP_S
last_modified_user

Amazon Resource Name (ARN) of the Amazon Web Services user who last changed the parameter.

VARCHAR
policies

Information about the policies assigned to a parameter.

Assigning parameter policies in the Amazon Web Services Systems Manager User Guide.

STRUCT(
"policy_text" VARCHAR,
"policy_type" VARCHAR,
"policy_status" VARCHAR
)[]
Show child fields
policies[]
Show child fields
policies[].policy_status

The status of the policy. Policies report the following statuses: Pending (the policy hasn't been enforced or applied yet), Finished (the policy was applied), Failed (the policy wasn't applied), or InProgress (the policy is being applied now).

policies[].policy_text

The JSON text of the policy.

policies[].policy_type

The type of policy. Parameter Store, a capability of Amazon Web Services Systems Manager, supports the following policy types: Expiration, ExpirationNotification, and NoChangeNotification.

tier

The parameter tier.

VARCHAR
type

The type of parameter used.

VARCHAR
value

The parameter value.

VARCHAR
version

The parameter version.

BIGINT