# AWS: Start or Stop EC2 Instances

Start one or more stopped EC2 instances, or stop one or more running EC2 instances, as part of an incident runbook.


> **Availability:** See the [Incident Workflow Actions Overview table](/workflow-actions) for the plans this workflow is available on.

> **Premium Workflow:** This is a Premium Workflow billed separately from your PagerDuty plan. In the workflow action picker, this action appears as **EC2: Start Instances**.

> **Premium Workflow:** This is a Premium Workflow billed separately from your PagerDuty plan. In the workflow action picker, this action appears as **EC2: Stop Instances**.

## Description

Start one or more stopped EC2 instances, or stop one or more running EC2 instances, as part of an incident runbook.

These actions are useful for:

- Restarting a stopped instance as a first remediation step for an unresponsive service.
- Stopping an instance suspected of causing issues (for example, a runaway process or resource exhaustion) without losing its EBS volumes or instance state.
- Power-cycling an instance by stopping and then starting it as a troubleshooting step.
- Recording instance state transitions for incident notes or audits.

## Instructions

1. If you have not done so, follow the instructions to [Create an Incident Workflow](/ai-automation/automation/incident-workflows#create-an-incident-workflow).
2. When the instructions prompt you to [add actions](/ai-automation/automation/incident-workflows#add-actions), select **this action**.
3. Enter the following **Inputs** and click **Save**.
4. Continue following instructions to **Publish** the Workflow.
5. When the action runs, you will see the **Outputs** listed below.

## Inputs

> **Field References:** Fields with the **\{+\}** icon accept [Field References](/ai-automation/automation/incident-workflows#field-references), which can be useful for referencing incident data or outputs created in prior workflow steps. To add Field References, click **\{+\}**, or enter `{{`, and select relevant fields. Refer to the [Field References](/ai-automation/automation/incident-workflows#field-references) article for more information.

### EC2: Start Instances

| Name                    | Description                                                                                                            |
| :------------------------ | :------------------------------------------------------------------------------------------------------------------------ |
| Integration (Required)  | Select a [Workflow Integration](/ai-automation/automation/incident-workflows/workflow-integrations) or click **New AWS Connection** to establish a new one. |
| AWS Region              | The AWS region where the instances are located (for example, `us-west-2`). If left blank, the action uses `us-east-1`. |
| Instance IDs (Required) | One or more EC2 instance IDs to start, separated by commas.                                                            |

### EC2: Stop Instances

| Name                    | Description                                                                                                            |
| :------------------------ | :------------------------------------------------------------------------------------------------------------------------ |
| Integration (Required)  | Select a [Workflow Integration](/ai-automation/automation/incident-workflows/workflow-integrations) or click **New AWS Connection** to establish a new one. |
| AWS Region              | The AWS region where the instances are located (for example, `us-west-2`). If left blank, the action uses `us-east-1`. |
| Instance IDs (Required) | One or more EC2 instance IDs to stop, separated by commas.                                                             |

## Outputs

### EC2: Start Instances

| Name               | Description                                                                              |
| :------------------- | :------------------------------------------------------------------------------------------ |
| Starting Instances | A JSON array of instance state transition objects, from previous state to current state. |
| Result             | Value that shows if the action was successful or not. Either "Success" or "Failed."      |
| Result Summary     | Brief description of what the action did or if it failed.                                |
| Error              | Brief description that is populated if the action failed.                                |

### EC2: Stop Instances

| Name               | Description                                                                              |
| :------------------- | :------------------------------------------------------------------------------------------ |
| Stopping Instances | A JSON array of instance state transition objects, from previous state to current state. |
| Result             | Value that shows if the action was successful or not. Either "Success" or "Failed."      |
| Result Summary     | Brief description of what the action did or if it failed.                                |
| Error              | Brief description that is populated if the action failed.                                |

> **Tips:** - **Stopping is not terminating**: Stopping an instance preserves its instance state and EBS volumes, so you can start it again later. To permanently remove an instance, use **EC2: Terminate Instances** instead.
> - **Public IP changes on start**: Unless the instance uses an Elastic IP, it can receive a new public IP address each time it starts. Update any downstream steps or DNS records that reference the old IP address.
> - **Power-cycle pattern**: Chain **EC2: Stop Instances**, a [Logic: Delay](/workflow-actions/logic/delay) step, and **EC2: Start Instances** in one workflow to restart an unresponsive instance without terminating and recreating it.
> - **Field references**: Reference **Instance IDs** from **EC2: Describe Instances**, [AWS: Fetch ASG Membership and Lifecycle Details](/workflow-actions/aws/aws-describe-autoscaling-instances), or the incident's custom details so the workflow can run unattended when an alert triggers it.
