Articles → AWS → AWS Config

AWS Config






Purpose




  1. Configuration based → This type of trigger runs the evaluation when a resource is created, changed, or deleted. For example, s3-bucket-replication-enabled (Checks if the replication is enabled for S3 bucket or not)
  2. Periodic → This type of trigger runs the evaluation on a certain interval of time. For example, ec2-stopped-instance (Checks if the ec2 is stopped more than allowed number of times)

Steps




  1. Create a S3 bucket
  2. Create a new role
  3. Create a rule
  4. Reevaluate rules
  5. Remediation
  6. Output



Create A S3 Bucket




Picture showing the S3 bucket created in AWS console



Create A New Role




Picture showing the use case as Systems Manager while creating the role




Picture showing adding the permission AmazonS3FullAccess while creating the role




Picture showing specifying the role name



Create A Rule




Picture showing the Rules menu in AWS config for creating the new rule




Picture showing the Add rule button for creating the new rule




Picture showing the section of rule screen to specify rule type




Picture showing the section of screen to select the predefined rule




Picture showing the section of Configure rule screen to enter the rule name




Picture showing the section of Configure rule screen to specify the trigger




Picture showing the review and create screen of rule in AWS config





Reevaluate Rules




Picture showing the Re-evaluate menu option to reevaluate the AWS config rule




Picture showing the non-compliance message when the rule is evaluated



Remediation




Picture showing the Manage remediation menu for non-compliance remediation




Picture showing the Edit Remediation screen for selecting the remediation method




Picture showing setting the Resource ID parameter as BucketName




Picture showing setting the other parameters while editing the remediation




Picture showing the confirmation message when remediation is updated




Picture showing the list of non-compliance resources




Picture showing the status of resource when remediation is run on non-compliance resources



Output




Picture showing the encryption enabled on S3 bucket



Posted By  -  Karan Gupta
 
Posted On  -  Monday, September 20, 2021
 
Updated On  -  Monday, September 19, 2022

Query/Feedback


Your Email Id
 
Subject
 
Query/FeedbackCharacters remaining 250