AWS StartImportJob

AWS StartImportJob

Certified

Start an Amazon HealthLake FHIR bulk import job

Submits a bulk FHIR import job from an S3 URI into a HealthLake data store and returns the job ID. Use DescribeImportJob to poll for completion, or use the Trigger task to react when it finishes.

yaml
type: io.kestra.plugin.aws.healthlake.StartImportJob

Start a FHIR bulk import from S3.

yaml
id: healthlake_start_import
namespace: company.team

inputs:
  - id: datastore_id
    type: STRING
  - id: s3_input_uri
    type: STRING

tasks:
  - id: start_import
    type: io.kestra.plugin.aws.healthlake.StartImportJob
    region: "{{ secret('AWS_REGION') }}"
    accessKeyId: "{{ secret('AWS_ACCESS_KEY_ID') }}"
    secretKeyId: "{{ secret('AWS_SECRET_ACCESS_KEY') }}"
    datastoreId: "{{ inputs.datastore_id }}"
    inputS3Uri: "{{ inputs.s3_input_uri }}"
    outputS3Uri: "s3://my-bucket/healthlake-output/"
    dataAccessRoleArn: "{{ secret('HEALTHLAKE_ROLE_ARN') }}"

  - id: log_job
    type: io.kestra.plugin.core.log.Log
    message: "Import job started: {{ outputs.start_import.jobId }}"
Properties

Data access role ARN

IAM role ARN that HealthLake assumes to read from the input S3 bucket and write to the output bucket.

Data store ID

The ID of the target FHIR data store.

Input S3 URI

S3 URI of the FHIR bundle(s) to import, e.g. s3://my-bucket/fhir/.

Output S3 URI

S3 URI prefix where import job output and error files are written.

Access Key Id in order to connect to AWS

If no credentials are defined, we will use the default credentials provider chain to fetch credentials.

Enable compatibility mode

Use it to connect to S3 bucket with S3 compatible services that don't support the new transport client.

The endpoint with which the SDK should communicate

This property allows you to use a different S3 compatible storage backend.

Force path style access

Must only be used when compatibilityMode is enabled.

Job name

Optional human-readable name for the import job.

Reference (ref) of the pluginDefaults to apply to this task.

AWS region with which the SDK should communicate

Secret Key Id in order to connect to AWS

If no credentials are defined, we will use the default credentials provider chain to fetch credentials.

AWS session token, retrieved from an AWS token service, used for authenticating that this user has received temporary permissions to access a given resource

If no credentials are defined, we will use the default credentials provider chain to fetch credentials.

The AWS STS endpoint with which the SDKClient should communicate

AWS STS Role

The Amazon Resource Name (ARN) of the role to assume. If set the task will use the StsAssumeRoleCredentialsProvider. If no credentials are defined, we will use the default credentials provider chain to fetch credentials.

AWS STS External Id

A unique identifier that might be required when you assume a role in another account. This property is only used when an stsRoleArn is defined.

DefaultPT15M

AWS STS Session duration

The duration of the role session (default: 15 minutes, i.e., PT15M). This property is only used when an stsRoleArn is defined.

AWS STS Session name

This property is only used when an stsRoleArn is defined.

Data store ID

The data store the job was submitted to.

Job ID

The ID of the submitted import job.

Job status

Initial job status, typically SUBMITTED.