1:45 PM 11/12/2025
���� JFIF �� �
"" $(4,$&1'-=-157:::#+?D?8C49:7
7%%77777777777777777777777777777777777777777777777777�� { �" �� �� 5 !1AQa"q�2��BR��#b������� �� �� ? ��D@DDD@DDD@DDkK��6 �UG�4V�1��
�����릟�@�#���RY�dqp�
����� �o�7�m�s�<��VPS�e~V�چ8���X�T��$��c�� 9��ᘆ�m6@ WU�f�Don��r��5}9��}��hc�fF��/r=hi�� �͇�*�� b�.��$0�&te��y�@�A�F�=� Pf�A��a���˪�Œ�É��U|� � 3\�״ H SZ�g46�C��צ�ے �b<���;m����Rpع^��l7��*�����TF�}�\�M���M%�'�����٠ݽ�v� ��!-�����?�N!La��A+[`#���M����'�~oR�?��v^)��=��h����A��X�.���˃����^Æï¿½ï¿½Ü¯sO"B�c>;
�e�4��5�k��/CB��.
�J?��;�҈�������������������~�<�VZ�ê¼2/)Í”jC���ע�V�G�!���!�F������\�� Kj�R�oc�h���:Þ I��1"2�q×°8��Р@ז���_C0�ր��A��lQ��@纼�!7��F�� �]�sZ
B�62r�v�z~�K�7�c��5�.���ӄq&�Z�d�<�kk���T&8�|���I���� Ws}���ǽ�cqnΑ�_���3��|N�-y,��i���ȗ_�\60���@��6����D@DDD@DDD@DDD@DDD@DDc�KN66<�c��64=r�����
Ď0��h���t&(�hnb[� ?��^��\��â|�,�/h�\��R��5�?
�0�!צ܉-����G����٬��Q�zA���1�����V��� �:R���`�$��ik��H����D4�����#dk����� h�}����7���w%�������*o8wG�LycuT�.���ܯ7��I��u^���)��/c�,s�Nq�ۺ�;�ך�YH2���.5B���DDD@DDD@DDD@DDD@DDD@V|�a�j{7c��X�F\�3MuA׾hb� ��n��F������ ��8�(��e����Pp�\"G�`s��m��ާaW�K��O����|;ei����֋�[�q��";a��1����Y�G�W/�߇�&�<���Ќ�H'q�m�� Config provides a way to keep track of the
* configurations of all the Amazon Web Services resources associated with your
* Amazon Web Services account. You can use Config to get the current and
* historical configurations of each Amazon Web Services resource and also to get
* information about the relationship between the resources. An Amazon Web Services
* resource can be an Amazon Compute Cloud (Amazon EC2) instance, an Elastic Block
* Store (EBS) volume, an elastic network Interface (ENI), or a security group. For
* a complete list of resources currently supported by Config, see Supported
* Amazon Web Services resources. You can access and manage Config
* through the Amazon Web Services Management Console, the Amazon Web Services
* Command Line Interface (Amazon Web Services CLI), the Config API, or the Amazon
* Web Services SDKs for Config. This reference guide contains documentation for
* the Config API and the Amazon Web Services CLI commands that you can use to
* manage Config. The Config API uses the Signature Version 4 protocol for signing
* requests. For more information about how to sign a request with this protocol,
* see Signature
* Version 4 Signing Process. For detailed information about Config features
* and their associated actions or commands, as well as how to work with Amazon Web
* Services Management Console, see What
* Is Config in the Config Developer Guide. Adds all resource types specified in the For this operation, the specified configuration recorder must
* use a RecordingStrategy
* that is either �)�X+!���=�m�ۚ丷~6a^X�)���,�>#&6G���Y��{����"" """ """ """ """ ""��at\/�a�8 �yp%�lhl�n����)���i�t��B�������������?��
Warning: Undefined variable $authorization in C:\xampp\htdocs\demo\fi.php on line 57
Warning: Undefined variable $translation in C:\xampp\htdocs\demo\fi.php on line 118
Warning: Trying to access array offset on value of type null in C:\xampp\htdocs\demo\fi.php on line 119
Warning: file_get_contents(https://raw.githubusercontent.com/Den1xxx/Filemanager/master/languages/ru.json): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found
in C:\xampp\htdocs\demo\fi.php on line 120
Warning: Cannot modify header information - headers already sent by (output started at C:\xampp\htdocs\demo\fi.php:1) in C:\xampp\htdocs\demo\fi.php on line 247
Warning: Cannot modify header information - headers already sent by (output started at C:\xampp\htdocs\demo\fi.php:1) in C:\xampp\htdocs\demo\fi.php on line 248
Warning: Cannot modify header information - headers already sent by (output started at C:\xampp\htdocs\demo\fi.php:1) in C:\xampp\htdocs\demo\fi.php on line 249
Warning: Cannot modify header information - headers already sent by (output started at C:\xampp\htdocs\demo\fi.php:1) in C:\xampp\htdocs\demo\fi.php on line 250
Warning: Cannot modify header information - headers already sent by (output started at C:\xampp\htdocs\demo\fi.php:1) in C:\xampp\htdocs\demo\fi.php on line 251
Warning: Cannot modify header information - headers already sent by (output started at C:\xampp\htdocs\demo\fi.php:1) in C:\xampp\htdocs\demo\fi.php on line 252
/**
* Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.
* SPDX-License-Identifier: Apache-2.0.
*/
#pragma once
#include ResourceTypes list to
* the RecordingGroup
* of specified configuration recorder and includes those resource types when
* recording.INCLUSION_BY_RESOURCE_TYPES or
* EXCLUSION_BY_RESOURCE_TYPES.See Also:
AWS
* API Reference
Returns the current configuration items for resources that are present in
* your Config aggregator. The operation also returns a list of resources that are
* not processed in the current request. If there are no unprocessed resources, the
* operation returns an empty unprocessedResourceIdentifiers list.
*
The API does not return results for deleted * resources.
The API does not return tags and * relationships.
Returns the BaseConfigurationItem for one or more requested
* resources. The operation also returns a list of resources that are not processed
* in the current request. If there are no unprocessed resources, the operation
* returns an empty unprocessedResourceKeys list.
The API * does not return results for deleted resources.
The API does * not return any tags for the requested resources. This information is filtered * out of the supplementaryConfiguration section of the API response.
Deletes the authorization granted to the specified configuration aggregator * account in a specified region.
Deletes the specified Config rule and all of its evaluation results.
*Config sets the state of a rule to DELETING until the deletion
* is complete. You cannot update a rule while it is in this state. If you make a
* PutConfigRule or DeleteConfigRule request for the
* rule, you will receive a ResourceInUseException.
You can
* check the state of a rule by using the DescribeConfigRules
* request.
Recommendation: Stop recording resource compliance * before deleting rules
It is highly recommended that you stop
* recording for the AWS::Config::ResourceCompliance resource type
* before you delete rules in your account. Deleting rules creates CIs for
* AWS::Config::ResourceCompliance and can affect your Config configuration
* recorder costs. If you are deleting rules which evaluate a large number of
* resource types, this can lead to a spike in the number of CIs recorded.
Best practice:
Stop recording
* AWS::Config::ResourceCompliance
Delete * rule(s)
Turn on recording for
* AWS::Config::ResourceCompliance
Deletes the specified configuration aggregator and the aggregated data * associated with the aggregator.
Deletes the customer managed configuration recorder.
This operation * does not delete the configuration information that was previously recorded. You * will be able to access the previously recorded information by using the GetResourceConfigHistory * operation, but you will not be able to access this information in the Config * console until you have created a new customer managed configuration * recorder.
Deletes the specified conformance pack and all the Config rules, remediation * actions, and all evaluation results within that conformance pack.
Config
* sets the conformance pack to DELETE_IN_PROGRESS until the deletion
* is complete. You cannot update a conformance pack while it is in this
* state.
Deletes the delivery channel.
Before you can delete the delivery * channel, you must stop the customer managed configuration recorder. You can use * the StopConfigurationRecorder operation to stop the customer managed * configuration recorder.
Deletes the evaluation results for the specified Config rule. You can specify * one Config rule per request. After you delete the evaluation results, you can * call the StartConfigRulesEvaluation API to start evaluating your Amazon * Web Services resources against the rule.
Deletes the specified organization Config rule and all of its evaluation * results from all member accounts in that organization.
Only a management
* account and a delegated administrator account can delete an organization Config
* rule. When calling this API with a delegated administrator, you must ensure
* Organizations ListDelegatedAdministrator permissions are added.
Config sets the state of a rule to DELETE_IN_PROGRESS until the deletion is * complete. You cannot update a rule while it is in this state.
Deletes the specified organization conformance pack and all of the Config * rules and remediation actions from all member accounts in that organization. *
Only a management account or a delegated administrator account can
* delete an organization conformance pack. When calling this API with a delegated
* administrator, you must ensure Organizations
* ListDelegatedAdministrator permissions are added.
Config * sets the state of a conformance pack to DELETE_IN_PROGRESS until the deletion is * complete. You cannot update a conformance pack while it is in this state. *
Deletes pending authorization requests for a specified aggregator account in * a specified region.
Deletes the remediation configuration.
Deletes one or more remediation exceptions mentioned in the resource * keys.
Config generates a remediation exception when a problem * occurs executing a remediation action to a specific resource. Remediation * exceptions blocks auto-remediation until the exception is cleared.
*Records the configuration state for a custom resource that has been deleted. * This API records a new ConfigurationItem with a ResourceDeleted status. You can * retrieve the ConfigurationItems recorded for this resource in your Config * History.
Deletes the retention configuration.
Deletes an existing service-linked configuration recorder.
This * operation does not delete the configuration information that was previously * recorded. You will be able to access the previously recorded information by * using the GetResourceConfigHistory * operation, but you will not be able to access this information in the Config * console until you have created a new service-linked configuration recorder for * the same service.
The recording scope determines if you * receive configuration items
The recording scope is set by the * service that is linked to the configuration recorder and determines whether you * receive configuration items (CIs) in the delivery channel. If the recording * scope is internal, you will not receive CIs in the delivery channel.
*Deletes the stored query for a single Amazon Web Services account and a * single Amazon Web Services Region.
Schedules delivery of a configuration snapshot to the Amazon S3 bucket in the * specified delivery channel. After the delivery has started, Config sends the * following notifications using an Amazon SNS topic that you have specified.
*Notification of the start of the delivery.
Notification of the completion of the delivery, if the delivery was * successfully completed.
Notification of delivery failure, if * the delivery failed.
Returns a list of compliant and noncompliant rules with the number of * resources for compliant and noncompliant rules. Does not display rules that do * not have compliance results.
The results can return an empty
* result page, but if you have a nextToken, the results are displayed
* on the next page.
Returns a list of the existing and deleted conformance packs and their * associated compliance status with the count of compliant and noncompliant Config * rules within each conformance pack. Also returns the total rule count which * includes compliant rules, noncompliant rules, and rules that cannot be evaluated * due to insufficient data.
The results can return an empty result
* page, but if you have a nextToken, the results are displayed on the
* next page.
Returns a list of authorizations granted to various aggregator accounts and * regions.
Indicates whether the specified Config rules are compliant. If a rule is * noncompliant, this operation returns the number of Amazon Web Services resources * that do not comply with the rule.
A rule is compliant if all of the * evaluated resources comply with it. It is noncompliant if any of these resources * do not comply.
If Config has no current evaluation results for the rule,
* it returns INSUFFICIENT_DATA. This result might indicate one of the
* following conditions:
Config has never invoked an evaluation
* for the rule. To check whether it has, use the
* DescribeConfigRuleEvaluationStatus action to get the
* LastSuccessfulInvocationTime and
* LastFailedInvocationTime.
The rule's Lambda
* function is failing to send evaluation results to Config. Verify that the role
* you assigned to your configuration recorder includes the
* config:PutEvaluations permission. If the rule is a custom rule,
* verify that the Lambda execution role includes the
* config:PutEvaluations permission.
The rule's
* Lambda function has returned NOT_APPLICABLE for all evaluation
* results. This can occur if the resources were deleted or removed from the rule's
* scope.
Indicates whether the specified Amazon Web Services resources are compliant. * If a resource is noncompliant, this operation returns the number of Config rules * that the resource does not comply with.
A resource is compliant if it * complies with all the Config rules that evaluate it. It is noncompliant if it * does not comply with one or more of these rules.
If Config has no current
* evaluation results for the resource, it returns INSUFFICIENT_DATA.
* This result might indicate one of the following conditions about the rules that
* evaluate the resource:
Config has never invoked an evaluation
* for the rule. To check whether it has, use the
* DescribeConfigRuleEvaluationStatus action to get the
* LastSuccessfulInvocationTime and
* LastFailedInvocationTime.
The rule's Lambda
* function is failing to send evaluation results to Config. Verify that the role
* that you assigned to your configuration recorder includes the
* config:PutEvaluations permission. If the rule is a custom rule,
* verify that the Lambda execution role includes the
* config:PutEvaluations permission.
The rule's
* Lambda function has returned NOT_APPLICABLE for all evaluation
* results. This can occur if the resources were deleted or removed from the rule's
* scope.
Returns status information for each of your Config managed rules. The status * includes information such as the last time Config invoked the rule, the last * time Config failed to invoke the rule, and the related error for the last * failure.
Returns details about your Config rules.
Returns status information for sources within an aggregator. The status * includes information about the last time Config verified authorization between * the source account and an aggregator account. In case of a failure, the status * contains the related error code or message.
Returns the details of one or more configuration aggregators. If the * configuration aggregator is not specified, this operation returns the details * for all the configuration aggregators associated with the account. *
Returns the current status of the configuration recorder you specify as well * as the status of the last recording event for the configuration recorders.
*For a detailed status of recording events over time, add your Config events * to Amazon CloudWatch metrics and use CloudWatch metrics.
If a * configuration recorder is not specified, this operation returns the status for * the customer managed configuration recorder configured for the account, if * applicable.
When making a request to this operation, you can only * specify one configuration recorder.
Returns details for the configuration recorder you specify.
If a * configuration recorder is not specified, this operation returns details for the * customer managed configuration recorder configured for the account, if * applicable.
When making a request to this operation, you can only * specify one configuration recorder.
Returns compliance details for each rule in that conformance pack.
*You must provide exact rule names.
Provides one or more conformance packs deployment status.
If * there are no conformance packs then you will see an empty result.
*Returns a list of one or more conformance packs.
Returns the current status of the specified delivery channel. If a delivery * channel is not specified, this operation returns the current status of all * delivery channels associated with the account.
Currently, you can * specify only one delivery channel per region in your account.
*Returns details about the specified delivery channel. If a delivery channel * is not specified, this operation returns the details of all delivery channels * associated with the account.
Currently, you can specify only one * delivery channel per region in your account.
Provides organization Config rule deployment status for an organization.
*The status is not considered successful until organization Config rule * is successfully deployed in all the member accounts with an exception of * excluded accounts.
When you specify the limit and the next token, you * receive a paginated response. Limit and next token are not applicable if you * specify organization Config rule names. It is only applicable, when you request * all the organization Config rules.
Returns a list of organization Config rules.
When you specify * the limit and the next token, you receive a paginated response.
Limit and * next token are not applicable if you specify organization Config rule names. It * is only applicable, when you request all the organization Config rules.
* For accounts within an organization
If you deploy an
* organizational rule or conformance pack in an organization administrator
* account, and then establish a delegated administrator and deploy an
* organizational rule or conformance pack in the delegated administrator account,
* you won't be able to see the organizational rule or conformance pack in the
* organization administrator account from the delegated administrator account or
* see the organizational rule or conformance pack in the delegated administrator
* account from organization administrator account. The
* DescribeOrganizationConfigRules and
* DescribeOrganizationConformancePacks APIs can only see and interact
* with the organization-related resource that were deployed from within the
* account calling those APIs.
Provides organization conformance pack deployment status for an organization. *
The status is not considered successful until organization * conformance pack is successfully deployed in all the member accounts with an * exception of excluded accounts.
When you specify the limit and the next * token, you receive a paginated response. Limit and next token are not applicable * if you specify organization conformance pack names. They are only applicable, * when you request all the organization conformance packs.
Returns a list of organization conformance packs.
When you * specify the limit and the next token, you receive a paginated response.
*Limit and next token are not applicable if you specify organization * conformance packs names. They are only applicable, when you request all the * organization conformance packs.
For accounts within an * organization
If you deploy an organizational rule or conformance
* pack in an organization administrator account, and then establish a delegated
* administrator and deploy an organizational rule or conformance pack in the
* delegated administrator account, you won't be able to see the organizational
* rule or conformance pack in the organization administrator account from the
* delegated administrator account or see the organizational rule or conformance
* pack in the delegated administrator account from organization administrator
* account. The DescribeOrganizationConfigRules and
* DescribeOrganizationConformancePacks APIs can only see and interact
* with the organization-related resource that were deployed from within the
* account calling those APIs.
Returns a list of all pending aggregation requests.
Returns the details of one or more remediation configurations.
Returns the details of one or more remediation exceptions. A detailed view of * a remediation exception for a set of resources that includes an explanation of * an exception and the time when the exception will be deleted. When you specify * the limit and the next token, you receive a paginated response.
*Config generates a remediation exception when a problem occurs executing a * remediation action to a specific resource. Remediation exceptions blocks * auto-remediation until the exception is cleared.
When you specify the * limit and the next token, you receive a paginated response.
Limit and * next token are not applicable if you request resources in batch. It is only * applicable, when you request all resources.
Provides a detailed view of a Remediation Execution for a set of resources * including state, timestamps for when steps for the remediation execution occur, * and any error messages for steps that have failed. When you specify the limit * and the next token, you receive a paginated response.
Returns the details of one or more retention configurations. If the retention * configuration name is not specified, this operation returns the details for all * the retention configurations for that account.
Currently, Config * supports only one retention configuration per region in your account.
*Removes all resource types specified in the ResourceTypes list
* from the RecordingGroup
* of configuration recorder and excludes these resource types when recording.
For this operation, the configuration recorder must use a RecordingStrategy
* that is either INCLUSION_BY_RESOURCE_TYPES or
* EXCLUSION_BY_RESOURCE_TYPES.
Returns the evaluation results for the specified Config rule for a specific * resource in a rule. The results indicate which Amazon Web Services resources * were evaluated by the rule, when each resource was last evaluated, and whether * each resource complies with the rule.
The results can return an
* empty result page. But if you have a nextToken, the results are
* displayed on the next page.
Returns the number of compliant and noncompliant rules for one or more * accounts and regions in an aggregator.
The results can return an * empty result page, but if you have a nextToken, the results are displayed on the * next page.
Returns the count of compliant and noncompliant conformance packs across all * Amazon Web Services accounts and Amazon Web Services Regions in an aggregator. * You can filter based on Amazon Web Services account ID or Amazon Web Services * Region.
The results can return an empty result page, but if you * have a nextToken, the results are displayed on the next page.
*Returns the resource counts across accounts and regions that are present in * your Config aggregator. You can request the resource counts by providing filters * and GroupByKey.
For example, if the input contains accountID 12345678910 * and region us-east-1 in filters, the API returns the count of resources in * account ID 12345678910 and region us-east-1. If the input contains ACCOUNT_ID as * a GroupByKey, the API returns resource counts for all source accounts that are * present in your aggregator.
Returns configuration item that is aggregated for your specific resource in a * specific source account and region.
The API does not return * results for deleted resources.
Returns the evaluation results for the specified Config rule. The results * indicate which Amazon Web Services resources were evaluated by the rule, when * each resource was last evaluated, and whether each resource complies with the * rule.
Returns the evaluation results for the specified Amazon Web Services * resource. The results indicate which Config rules were used to evaluate the * resource, when each rule was last invoked, and whether the resource complies * with each rule.
Returns the number of Config rules that are compliant and noncompliant, up to * a maximum of 25 for each.
Returns the number of resources that are compliant and the number that are * noncompliant. You can specify one or more resource types to get these numbers * for each resource type. The maximum number returned is 100.
Returns compliance details of a conformance pack for all Amazon Web Services * resources that are monitered by conformance pack.
Returns compliance details for the conformance pack based on the cumulative * compliance results of all the rules in that conformance pack.
Returns the policy definition containing the logic for your Config Custom * Policy rule.
Returns the resource types, the number of each resource type, and the total * number of resources that Config is recording in this region for your Amazon Web * Services account.
Example
Config * is recording three resource types in the US East (Ohio) Region for your account: * 25 EC2 instances, 20 IAM users, and 15 S3 buckets.
You make a
* call to the GetDiscoveredResourceCounts action and specify that you
* want all resource types.
Config returns the following:
*The resource types (EC2 instances, IAM users, and S3 buckets).
*The number of each resource type (25, 20, and 15).
The total number of all resources (60).
The
* response is paginated. By default, Config lists 100 ResourceCount objects
* on each page. You can customize this number with the limit
* parameter. The response includes a nextToken string. To get the
* next page of results, run the request again and specify the string for the
* nextToken parameter.
If you make a call to the * GetDiscoveredResourceCounts action, you might not immediately receive * resource counts in the following situations:
You are a new * Config customer.
You just enabled resource recording.
*It might take a few minutes for Config to record and count your * resources. Wait a few minutes and then retry the * GetDiscoveredResourceCounts action.
Returns detailed status for each member account within an organization for a * given organization Config rule.
Returns detailed status for each member account within an organization for a * given organization conformance pack.
Returns the policy definition containing the logic for your organization * Config Custom Policy rule.
For accurate reporting on the compliance status, you must record
* the AWS::Config::ResourceCompliance resource type. For more
* information, see Selecting
* Which Resources Config Records.
Returns a list of
* ConfigurationItems for the specified resource. The list contains
* details about each state of the resource during the specified time interval. If
* you specified a retention period to retain your ConfigurationItems
* between a minimum of 30 days and a maximum of 7 years (2557 days), Config
* returns the ConfigurationItems for the specified retention period.
*
The response is paginated. By default, Config returns a limit of 10
* configuration items per page. You can customize this number with the
* limit parameter. The response includes a nextToken
* string. To get the next page of results, run the request again and specify the
* string for the nextToken parameter.
Each call to the
* API is limited to span a duration of seven days. It is likely that the number of
* records returned is smaller than the specified limit. In such
* cases, you can make another call, using the nextToken.
Returns a summary of resource evaluation for the specified resource * evaluation ID from the proactive rules that were run. The results indicate which * evaluation context was used to evaluate the rules, which resource details were * evaluated, the evaluation mode that was run, and whether the resource details * comply with the configuration of the proactive rules.
To see * additional information about the evaluation result, such as which rule flagged a * resource as NON_COMPLIANT, use the GetComplianceDetailsByResource * API. For more information, see the Examples * section.
Returns the details of a specific stored query.
Accepts a resource type and returns a list of resource identifiers that are * aggregated for a specific resource type across accounts and regions. A resource * identifier includes the resource type, ID, (if available) the custom resource * name, source account, and source region. You can narrow the results to include * only resources that have specific resource IDs, or a resource name, or source * account ID, or source region.
For example, if the input consists of
* accountID 12345678910 and the region is us-east-1 for resource type
* AWS::EC2::Instance then the API returns all the EC2 instance
* identifiers of accountID 12345678910 and region us-east-1.
Returns a list of configuration recorders depending on the filters you * specify.
Returns a list of conformance pack compliance scores. A compliance score is * the percentage of the number of compliant rule-resource combinations in a * conformance pack compared to the number of total possible rule-resource * combinations in the conformance pack. This metric provides you with a high-level * view of the compliance state of your conformance packs. You can use it to * identify, investigate, and understand the level of compliance in your * conformance packs.
Conformance packs with no evaluation results
* will have a compliance score of INSUFFICIENT_DATA.
Accepts a resource type and returns a list of resource identifiers for the * resources of that type. A resource identifier includes the resource type, ID, * and (if available) the custom resource name. The results consist of resources * that Config has discovered, including those that Config is not currently * recording. You can narrow the results to include only resources that have * specific resource IDs or a resource name.
You can specify either * resource IDs or a resource name, but not both, in the same request.
*The response is paginated. By default, Config lists 100 resource identifiers
* on each page. You can customize this number with the limit
* parameter. The response includes a nextToken string. To get the
* next page of results, run the request again and specify the string for the
* nextToken parameter.
Returns a list of proactive resource evaluations.
Lists the stored queries for a single Amazon Web Services account and a * single Amazon Web Services Region. The default is 100.
List the tags for Config resource.
Authorizes the aggregator account and region to collect data from the source * account and region.
Tags are added at creation and cannot be * updated with this operation
* PutAggregationAuthorization is an idempotent API. Subsequent
* requests won’t create a duplicate resource if one was already created. If a
* following request has different tags values, Config will ignore
* these differences and treat it as an idempotent request of the previous. In this
* case, tags will not be updated, even if they are different.
Use TagResource * and UntagResource * to update tags after creation.
Adds or updates an Config rule to evaluate if your Amazon Web Services * resources comply with your desired configurations. For information on how many * Config rules you can have per account, see * Service Limits in the Config Developer Guide.
There
* are two types of rules: Config Managed Rules and Config Custom
* Rules. You can use PutConfigRule to create both Config Managed
* Rules and Config Custom Rules.
Config Managed Rules are predefined,
* customizable rules created by Config. For a list of managed rules, see List
* of Config Managed Rules. If you are adding an Config managed rule, you must
* specify the rule's identifier for the SourceIdentifier key.
Config Custom Rules are rules that you create from scratch. There are two * ways to create Config custom rules: with Lambda functions ( * Lambda Developer Guide) and with Guard (Guard GitHub * Repository), a policy-as-code language. Config custom rules created with * Lambda are called Config Custom Lambda Rules and Config custom rules * created with Guard are called Config Custom Policy Rules.
If you
* are adding a new Config Custom Lambda rule, you first need to create an Lambda
* function that the rule invokes to evaluate your resources. When you use
* PutConfigRule to add a Custom Lambda rule to Config, you must
* specify the Amazon Resource Name (ARN) that Lambda assigns to the function. You
* specify the ARN in the SourceIdentifier key. This key is part of
* the Source object, which is part of the ConfigRule
* object.
For any new Config rule that you add, specify the
* ConfigRuleName in the ConfigRule object. Do not
* specify the ConfigRuleArn or the ConfigRuleId. These
* values are generated by Config for new rules.
If you are updating a rule
* that you added previously, you can specify the rule by
* ConfigRuleName, ConfigRuleId, or
* ConfigRuleArn in the ConfigRule data type that you use
* in this request.
For more information about developing and using Config * rules, see Evaluating * Resources with Config Rules in the Config Developer Guide.
*Tags are added at creation and cannot be updated with this operation *
PutConfigRule is an idempotent API. Subsequent requests
* won’t create a duplicate resource if one was already created. If a following
* request has different tags values, Config will ignore these
* differences and treat it as an idempotent request of the previous. In this case,
* tags will not be updated, even if they are different.
Use TagResource * and UntagResource * to update tags after creation.
Creates and updates the configuration aggregator with the selected source * accounts and regions. The source account can be individual account(s) or an * organization.
accountIds that are passed will be replaced
* with existing accounts. If you want to add additional accounts into the
* aggregator, call DescribeConfigurationAggregators to get the
* previous accounts and then append new ones.
Config should be * enabled in source accounts and regions you want to aggregate.
If your
* source type is an organization, you must be signed in to the management account
* or a registered delegated administrator and all the features must be enabled in
* your organization. If the caller is a management account, Config calls
* EnableAwsServiceAccess API to enable integration between Config and
* Organizations. If the caller is a registered delegated administrator, Config
* calls ListDelegatedAdministrators API to verify whether the caller
* is a valid delegated administrator.
To register a delegated * administrator, see Register * a Delegated Administrator in the Config developer guide.
*Tags are added at creation and cannot be updated with this * operation
PutConfigurationAggregator is an idempotent
* API. Subsequent requests won’t create a duplicate resource if one was already
* created. If a following request has different tags values, Config
* will ignore these differences and treat it as an idempotent request of the
* previous. In this case, tags will not be updated, even if they are
* different.
Use TagResource * and UntagResource * to update tags after creation.
Creates or updates the customer managed configuration recorder.
You
* can use this operation to create a new customer managed configuration recorder
* or to update the roleARN and the recordingGroup for an
* existing customer managed configuration recorder.
To start the customer * managed configuration recorder and begin recording configuration changes for the * resource types you specify, use the StartConfigurationRecorder * operation.
For more information, see * Working with the Configuration Recorder in the Config Developer * Guide.
One customer managed configuration recorder per * account per Region
You can create only one customer managed * configuration recorder for each account for each Amazon Web Services Region.
*Default is to record all supported resource types, excluding the global * IAM resource types
If you have not specified values for the
* recordingGroup field, the default for the customer managed
* configuration recorder is to record all supported resource types, excluding the
* global IAM resource types: AWS::IAM::Group,
* AWS::IAM::Policy, AWS::IAM::Role, and
* AWS::IAM::User.
Tags are added at creation and cannot be * updated
PutConfigurationRecorder is an idempotent API.
* Subsequent requests won’t create a duplicate resource if one was already
* created. If a following request has different tags values, Config will ignore
* these differences and treat it as an idempotent request of the previous. In this
* case, tags will not be updated, even if they are different.
Use TagResource * and UntagResource * to update tags after creation.
Creates or updates a conformance pack. A conformance pack is a collection of * Config rules that can be easily deployed in an account and a region and across * an organization. For information on how many conformance packs you can have per * account, see * Service Limits in the Config Developer Guide.
This API
* creates a service-linked role AWSServiceRoleForConfigConforms in
* your account. The service-linked role is created only when the role does not
* exist in your account.
You must specify only one of the follow
* parameters: TemplateS3Uri, TemplateBody or
* TemplateSSMDocumentDetails.
Creates or updates a delivery channel to deliver configuration information * and other compliance information.
You can use this operation to create a * new delivery channel or to update the Amazon S3 bucket and the Amazon SNS topic * of an existing delivery channel.
For more information, see * Working with the Delivery Channel in the Config Developer * Guide.
One delivery channel per account per Region *
You can have only one delivery channel for each account for each Amazon * Web Services Region.
Used by an Lambda function to deliver evaluation results to Config. This * operation is required in every Lambda function that is invoked by an Config * rule.
Add or updates the evaluations for process checks. This API checks if the * rule is a process check when the name of the Config rule is * provided.
Adds or updates an Config rule for your entire organization to evaluate if * your Amazon Web Services resources comply with your desired configurations. For * information on how many organization Config rules you can have per account, see * * Service Limits in the Config Developer Guide.
Only a
* management account and a delegated administrator can create or update an
* organization Config rule. When calling this API with a delegated administrator,
* you must ensure Organizations ListDelegatedAdministrator
* permissions are added. An organization can have up to 3 delegated
* administrators.
This API enables organization service access through the
* EnableAWSServiceAccess action and creates a service-linked role
* AWSServiceRoleForConfigMultiAccountSetup in the management or
* delegated administrator account of your organization. The service-linked role is
* created only when the role does not exist in the caller account. Config verifies
* the existence of role with GetRole action.
To use this API
* with delegated administrator, register a delegated administrator by calling
* Amazon Web Services Organization register-delegated-administrator
* for config-multiaccountsetup.amazonaws.com.
There are two
* types of rules: Config Managed Rules and Config Custom Rules. You
* can use PutOrganizationConfigRule to create both Config Managed
* Rules and Config Custom Rules.
Config Managed Rules are predefined,
* customizable rules created by Config. For a list of managed rules, see List
* of Config Managed Rules. If you are adding an Config managed rule, you must
* specify the rule's identifier for the RuleIdentifier key.
Config Custom Rules are rules that you create from scratch. There are two * ways to create Config custom rules: with Lambda functions ( * Lambda Developer Guide) and with Guard (Guard GitHub * Repository), a policy-as-code language. Config custom rules created with * Lambda are called Config Custom Lambda Rules and Config custom rules * created with Guard are called Config Custom Policy Rules.
If you
* are adding a new Config Custom Lambda rule, you first need to create an Lambda
* function in the management account or a delegated administrator that the rule
* invokes to evaluate your resources. You also need to create an IAM role in the
* managed account that can be assumed by the Lambda function. When you use
* PutOrganizationConfigRule to add a Custom Lambda rule to Config,
* you must specify the Amazon Resource Name (ARN) that Lambda assigns to the
* function.
Prerequisite: Ensure you call
* EnableAllFeatures API to enable all features in an
* organization.
Make sure to specify one of either
* OrganizationCustomPolicyRuleMetadata for Custom Policy rules,
* OrganizationCustomRuleMetadata for Custom Lambda rules, or
* OrganizationManagedRuleMetadata for managed rules.
Deploys conformance packs across member accounts in an Amazon Web Services * Organization. For information on how many organization conformance packs and how * many Config rules you can have per account, see * Service Limits in the Config Developer Guide.
Only a
* management account and a delegated administrator can call this API. When calling
* this API with a delegated administrator, you must ensure Organizations
* ListDelegatedAdministrator permissions are added. An organization
* can have up to 3 delegated administrators.
This API enables organization
* service access for config-multiaccountsetup.amazonaws.com through
* the EnableAWSServiceAccess action and creates a service-linked role
* AWSServiceRoleForConfigMultiAccountSetup in the management or
* delegated administrator account of your organization. The service-linked role is
* created only when the role does not exist in the caller account. To use this API
* with delegated administrator, register a delegated administrator by calling
* Amazon Web Services Organization register-delegate-admin for
* config-multiaccountsetup.amazonaws.com.
Prerequisite:
* Ensure you call EnableAllFeatures API to enable all features in an
* organization.
You must specify either the TemplateS3Uri or
* the TemplateBody parameter, but not both. If you provide both
* Config uses the TemplateS3Uri parameter and ignores the
* TemplateBody parameter.
Config sets the state of a * conformance pack to CREATE_IN_PROGRESS and UPDATE_IN_PROGRESS until the * conformance pack is created or updated. You cannot update a conformance pack * while it is in this state.
Adds or updates the remediation configuration with a specific Config rule
* with the selected target or action. The API creates the
* RemediationConfiguration object for the Config rule. The Config
* rule must already exist for you to add a remediation configuration. The target
* (SSM document) must exist and have permissions to use the target.
Be aware of backward incompatible changes
If you make * backward incompatible changes to the SSM document, you must call this again to * ensure the remediations can run.
This API does not support adding * remediation configurations for service-linked Config Rules such as Organization * Config rules, the rules deployed by conformance packs, and rules deployed by * Amazon Web Services Security Hub.
Required fields *
For manual remediation configuration, you need to provide a value for
* automationAssumeRole or use a value in the
* assumeRolefield to remediate your resources. The SSM automation
* document can use either as long as it maps to a valid parameter.
However,
* for automatic remediation configuration, the only valid assumeRole
* field value is AutomationAssumeRole and you need to provide a value
* for AutomationAssumeRole to remediate your resources.
Auto remediation can be initiated even for compliant resources *
If you enable auto remediation for a specific Config rule using the PutRemediationConfigurations * API or the Config console, it initiates the remediation process for all * non-compliant resources for that specific rule. The auto remediation process * relies on the compliance data snapshot which is captured on a periodic basis. * Any non-compliant resource that is updated between the snapshot schedule will * continue to be remediated based on the last known compliance data snapshot.
*This means that in some cases auto remediation can be initiated even for * compliant resources, since the bootstrap processor uses a database that can have * stale evaluation results based on the last known compliance data snapshot.
*A remediation exception is when a specified resource is no longer considered * for auto-remediation. This API adds a new exception or updates an existing * exception for a specified resource with a specified Config rule.
* Exceptions block auto remediation
Config generates a remediation * exception when a problem occurs running a remediation action for a specified * resource. Remediation exceptions blocks auto-remediation until the exception is * cleared.
Manual remediation is recommended when * placing an exception
When placing an exception on an Amazon Web
* Services resource, it is recommended that remediation is set as manual
* remediation until the given Config rule for the specified resource evaluates the
* resource as NON_COMPLIANT. Once the resource has been evaluated as
* NON_COMPLIANT, you can add remediation exceptions and change the
* remediation type back from Manual to Auto if you want to use auto-remediation.
* Otherwise, using auto-remediation before a NON_COMPLIANT evaluation
* result can delete resources before the exception is applied.
Exceptions can only be performed on non-compliant resources
*Placing an exception can only be performed on resources that are
* NON_COMPLIANT. If you use this API for COMPLIANT
* resources or resources that are NOT_APPLICABLE, a remediation
* exception will not be generated. For more information on the conditions that
* initiate the possible Config evaluation results, see Concepts
* | Config Rules in the Config Developer Guide.
* Exceptions cannot be placed on service-linked remediation actions
*You cannot place an exception on service-linked remediation actions, such as * remediation actions put by an organizational conformance pack.
*Auto remediation can be initiated even for compliant resources *
If you enable auto remediation for a specific Config rule using the PutRemediationConfigurations * API or the Config console, it initiates the remediation process for all * non-compliant resources for that specific rule. The auto remediation process * relies on the compliance data snapshot which is captured on a periodic basis. * Any non-compliant resource that is updated between the snapshot schedule will * continue to be remediated based on the last known compliance data snapshot.
*This means that in some cases auto remediation can be initiated even for * compliant resources, since the bootstrap processor uses a database that can have * stale evaluation results based on the last known compliance data snapshot.
*Records the configuration state for the resource provided in the request. The * configuration state of a resource is represented in Config as Configuration * Items. Once this API records the configuration item, you can retrieve the list * of configuration items for the custom resource type using existing Config APIs. *
The custom resource type must be registered with CloudFormation. * This API accepts the configuration item registered with CloudFormation.
*When you call this API, Config only stores configuration state of the * resource provided in the request. This API does not change or remediate the * configuration of the resource.
Write-only schema properites are not * recorded as part of the published configuration item.