Optional ReadonlyaggregationConfig Recorder Aggregation configuration
Optional Readonlydeployment(OPTIONAL) AWS Config deployment target.
Leaving deploymentTargets undefined will enable AWS Config across all accounts and enabled regions.
We highly recommend enabling AWS Config across all accounts and enabled regions within your organization.
deploymentTargets should only be used when more granular control is required, not as a default configuration.
To enable AWS Config into Infrastructure organizational unit, you need to provide below value for this parameter.
Note: The delegated admin account defined in centralSecurityServices will always have AwsConfig enabled
ReadonlyenableIndicates whether AWS Config recorder enabled.
To enable AWS Config, you must create a configuration recorder
ConfigurationRecorder resource describes the AWS resource types for which AWS Config records configuration changes. The configuration recorder stores the configurations of the supported resources in your account as configuration items.
Optional ReadonlyenableIndicates whether delivery channel enabled.
AWS Config uses the delivery channel to deliver the configuration changes to your Amazon S3 bucket. DEPRECATED
Optional ReadonlyoverrideIndicates whether or not to override existing config recorder settings Must be enabled if any account and region combination has an existing config recorder, even if config recording is turned off The Landing Zone Accelerator will override the settings in all configured accounts and regions ** Do not enable this setting if you have deployed LZA ** successfully with enableConfigurationRecorder set to true ** and overrideExisting either unset or set to false ** Doing so will cause a resource conflict When the overrideExisting property is enabled ensure that any scp's are not blocking the passRole iam permission for the iam role name {acceleratorPrefix}Config
Optional ReadonlyruleAWS Config rule sets
Optional ReadonlyuseIndicates whether to create the Configuration Recorder with a service linked role. If not specified, AWS Config will use a custom IAM role created by LZA. For new deployments, it is recommended to set this setting to true. For more information, see https://docs.aws.amazon.com/config/latest/developerguide/using-service-linked-roles.html
SecurityConfig / AwsConfig
Description
AWS Config Recorder and Rules
Example