Build Transfer Family SFTP/FTP/FTPS server configurations with VPC endpoints, identity providers, and upload workflows.
Build Transfer Family SFTP/FTP/FTPS server configurations with VPC endpoints, identity providers, and upload workflows.
Required Fields
ProtocolsEndpointTypeIdentityProviderTypeOutput will appear here...Build an AWS Transfer Family server supporting SFTP/FTPS/FTP protocols with VPC-scoped endpoint access and a pluggable IdentityProviderType (SERVICE_MANAGED, AWS_DIRECTORY_SERVICE, or a custom API_GATEWAY-backed identity provider), plus WorkflowDetails.OnUpload for triggering post-upload processing automatically. Choosing plain FTP in Protocols is a real security decision, not just a compatibility option, FTP transmits credentials and data unencrypted, and AWS Transfer Family itself documents that FTP should only be used within a VPC over a trusted, non-internet-routable network path, never exposed publicly, unlike SFTP/FTPS which encrypt the session.
Never include FTP in Protocols for an internet-facing server, this isn't a minor best-practice suggestion, it's transmitting plaintext credentials and file content over a network you don't control, reserve FTP support strictly for VPC-internal legacy system compatibility.
AWS_DIRECTORY_SERVICE integration is worth the setup effort for any organization already running Active Directory, since it avoids the ongoing operational burden of maintaining a separate user store just for file-transfer access, with the security benefit of centralized deprovisioning when an employee leaves.
OnUpload workflows are a genuinely underused feature for automating file-intake pipelines (validation, scanning, transformation) without a separate polling Lambda watching the destination bucket, consider it whenever a Transfer Family server exists specifically to receive files that need processing.
The builder validates that Protocols, EndpointType, and IdentityProviderType all resolve before accepting the JSON as a valid CreateServer request, the fields Transfer Family needs to know which protocols the server accepts, how it's network-exposed, and how users authenticate; it can't verify the referenced DirectoryId, VPC/subnet IDs, or certificate ARN actually exist and are correctly configured, those checks happen only against the live account.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.