Feature | Description |
Manage the monitoring scope | Cloud Config monitors the changes of resources within your account, tracks configuration changes, and evaluates configuration compliance in real time. You can configure the scope of resources to monitor in the Cloud Config console. If you select All Supported Resource Types, new resource types that are supported by Cloud Config are automatically added to the monitoring scope. If you select Custom Resource Types, new resource types are not automatically added to the monitoring scope. |
Manage resources | After you activate Cloud Config, you can view your resources in different regions. You can filter resources. This allows you to query the configuration details of a specified resource. You can also go to the corresponding cloud service console from the Cloud Config console to manage the resource. |
View the compliance timeline of a resource | Cloud Config records each configuration change of a monitored resource and displays the configuration changes over time in a configuration timeline. You can view the configuration changes and the details of related events. |
Evaluate resource compliance | Cloud Config allows you to create custom rules, or create rules based on templates. After you create rules, you can view the compliance results and compliance timeline of each resource. You can also re-evaluate the non-compliant resources. You can edit, disable, or delete the rules that do not meet your business requirements. |
Remediate non-compliant resources | You can configure template remediation or custom remediation when you create a rule. If a rule detects non-compliant resources, you can execute remediation to quickly correct non-compliant configurations. This ensures that your cloud IT system achieves autonomous and continuous compliance. |
Resource delivery | Cloud Config continuously delivers resource data to Simple Log Service Logstores, Object Storage Service (OSS) buckets, or Simple Message Queue (formerly MNS) topics. This allows you to manage resource data. |
Compliance packages | A compliance package contains a set of managed rules that are created by Cloud Config based on various compliance scenarios. Compliance packages help you dynamically and continuously monitor the compliance of your resources and notify you of non-compliant resource at the earliest opportunity. |
Account groups | You can use the management account or delegated administrator account of a resource directory to create an account group in the Cloud Config console. This way, you can manage the resources, compliance packages, and rules of multiple members in the account group in a centralized manner. |
Compliance library | The compliance library of Cloud Config provides a wide range of compliance package templates and rule templates. You can enable compliance items to continuously detect resources. You can also use the public templates provided by Operation Orchestration Service (OOS) to quickly correct non-compliant resources. |