aws.config-recorder
Filters
cross-account
Check a resource’s embedded iam policy for cross account access.
Supports a whitelist_patterns option to skip principals whose identifier
matches any of the provided fnmatch patterns. This is
useful for ignoring unique identifiers left behind by deleted IAM principals
(e.g. AIDA* for deleted IAM users, AROA* for deleted IAM roles)
which AWS substitutes into resource policies when the original principal is
removed. See IAM unique identifiers
for the full list of prefixes.
- type: cross-account
whitelist_patterns:
- "AIDA*"
- "AROA*"
Supports a whitelist_org_units option for trusting principals via
aws:PrincipalOrgPaths conditions. Each entry must be a full OU path
starting with the org ID and ending with the OU ID to trust:
- type: cross-account
whitelist_org_units:
- "o-abc1234567/r-ab12/ou-ab12-prod"
Wildcards (*, ?) are not permitted in whitelist entries. The org
ID prefix is required because OU IDs are only unique within an
organization. A whitelist matches a policy path when the path’s leading
segment equals the whitelist’s org ID and the whitelist’s leaf OU ID
appears as a literal segment in the path; this means a parent-OU whitelist
will not implicitly cover policies that only name a descendant OU. List
each OU level you actually want to trust. aws:PrincipalOrgPaths matching
also respects whitelist_orgids. Any policy path whose leading segment
matches a whitelisted org ID is accepted regardless of the OU whitelist.
properties:
allowed_regions:
items:
type: string
type: array
type:
enum:
- cross-account
whitelist:
items:
type: string
type: array
whitelist_from:
additionalProperties: 'False'
properties:
expr:
oneOf:
- type: integer
- type: string
format:
enum:
- csv
- json
- txt
- csv2dict
headers:
patternProperties:
? ''
: type: string
type: object
query:
type: string
url:
type: string
required:
- url
type: object
required:
- type
Permissions - config:DescribeAggregationAuthorizations
json-diff
Compute the diff from the current resource to a previous version.
A resource matches the filter if a diff exists between the current resource and the selected revision.
Utilizes config as a resource revision database.
Revisions can be selected by date, against the previous version, and against a locked version (requires use of is-locked filter).
properties:
selector:
enum:
- previous
- date
- locked
selector_value:
type: string
type:
enum:
- json-diff
required:
- type
Permissions - config:GetResourceConfigHistory
retention
Filter to look for config retention configurations
AWS Config supports only one retention configuration per region in a particular account.
RetentionPeriodInDays value should be an integer ranging from 30 to 2557
- example:
policies:
- name: config-recorder-verify-retention
resource: config-recorder
filters:
- type: retention
key: RetentionPeriodInDays
value: 30
Also retrieves the retention configuration if no key/value is provided:
- example:
policies:
- name: config-recorder
resource: config-recorder
filters:
- type: retention
properties:
default:
type: object
key:
type: string
op:
enum:
- eq
- equal
- ne
- not-equal
- gt
- greater-than
- ge
- gte
- le
- lte
- lt
- less-than
- glob
- regex
- regex-case
- in
- ni
- not-in
- contains
- difference
- intersect
- mod
tag_key_transforms:
items:
type: string
type: array
type:
enum:
- retention
value:
oneOf:
- type: array
- type: string
- type: boolean
- type: number
- type: 'null'
value_from:
additionalProperties: 'False'
properties:
expr:
oneOf:
- type: integer
- type: string
format:
enum:
- csv
- json
- txt
- csv2dict
headers:
patternProperties:
? ''
: type: string
type: object
query:
type: string
url:
type: string
required:
- url
type: object
value_path:
type: string
value_regex:
type: string
value_type:
enum:
- age
- integer
- expiration
- normalize
- size
- cidr
- cidr_size
- swap
- resource_count
- expr
- unique_size
- date
- version
- float
required:
- type
Permissions - config:DescribeRetentionConfigurations
Actions
toggle-recording
Start or stop the AWS Config configuration recorder.
- example:
policies:
- name: stop-config-recording
resource: config-recorder
filters:
- type: value
key: status.recording
value: true
actions:
- type: toggle-recording
enabled: false
properties:
enabled:
default: true
type: boolean
type:
enum:
- toggle-recording
required:
- type
Permissions - config:StartConfigurationRecorder, config:StopConfigurationRecorder