1. Registry
  2. Packages
  3. AWS Cloud Control
  4. API Docs
  5. configuration
  6. ConfigurationRecorder

We recommend new projects start with resources from the AWS provider.

Viewing docs for AWS Cloud Control v1.81.0
published on Monday, Sep 28, 2026 by Pulumi
aws-native logo aws-native logo

We recommend new projects start with resources from the AWS provider.

Viewing docs for AWS Cloud Control v1.81.0
published on Monday, Sep 28, 2026 by Pulumi

    Resource type definition for AWS::Config::ConfigurationRecorder

    Create ConfigurationRecorder Resource

    Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.

    Constructor syntax

    new ConfigurationRecorder(name: string, args: ConfigurationRecorderArgs, opts?: CustomResourceOptions);
    @overload
    def ConfigurationRecorder(resource_name: str,
                              args: ConfigurationRecorderArgs,
                              opts: Optional[ResourceOptions] = None)
    
    @overload
    def ConfigurationRecorder(resource_name: str,
                              opts: Optional[ResourceOptions] = None,
                              role_arn: Optional[str] = None,
                              name: Optional[str] = None,
                              recording_group: Optional[ConfigurationRecorderRecordingGroupArgs] = None,
                              recording_mode: Optional[ConfigurationRecorderRecordingModeArgs] = None,
                              started_on_create: Optional[bool] = None)
    func NewConfigurationRecorder(ctx *Context, name string, args ConfigurationRecorderArgs, opts ...ResourceOption) (*ConfigurationRecorder, error)
    public ConfigurationRecorder(string name, ConfigurationRecorderArgs args, CustomResourceOptions? opts = null)
    public ConfigurationRecorder(String name, ConfigurationRecorderArgs args)
    public ConfigurationRecorder(String name, ConfigurationRecorderArgs args, CustomResourceOptions options)
    
    type: aws-native:configuration:ConfigurationRecorder
    properties: # The arguments to resource properties.
    options: # Bag of options to control resource's behavior.
    
    
    resource "aws-native_configuration_configuration_recorder" "name" {
        # resource properties
    }

    Parameters

    name string
    The unique name of the resource.
    args ConfigurationRecorderArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    resource_name str
    The unique name of the resource.
    args ConfigurationRecorderArgs
    The arguments to resource properties.
    opts ResourceOptions
    Bag of options to control resource's behavior.
    ctx Context
    Context object for the current deployment.
    name string
    The unique name of the resource.
    args ConfigurationRecorderArgs
    The arguments to resource properties.
    opts ResourceOption
    Bag of options to control resource's behavior.
    name string
    The unique name of the resource.
    args ConfigurationRecorderArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    name String
    The unique name of the resource.
    args ConfigurationRecorderArgs
    The arguments to resource properties.
    options CustomResourceOptions
    Bag of options to control resource's behavior.

    ConfigurationRecorder Resource Properties

    To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.

    Inputs

    In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.

    The ConfigurationRecorder resource accepts the following input properties:

    RoleArn string
    The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
    Name string
    The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
    RecordingGroup Pulumi.AwsNative.Configuration.Inputs.ConfigurationRecorderRecordingGroup
    Specifies which resource types are in scope for the configuration recorder to record.
    RecordingMode Pulumi.AwsNative.Configuration.Inputs.ConfigurationRecorderRecordingMode
    Specifies the default recording frequency for the configuration recorder.
    StartedOnCreate bool
    Defaults to 'true'. Controls whether the recorder starts recording after the create operation. Set this to 'false' for development and testing purposes.
    RoleArn string
    The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
    Name string
    The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
    RecordingGroup ConfigurationRecorderRecordingGroupArgs
    Specifies which resource types are in scope for the configuration recorder to record.
    RecordingMode ConfigurationRecorderRecordingModeArgs
    Specifies the default recording frequency for the configuration recorder.
    StartedOnCreate bool
    Defaults to 'true'. Controls whether the recorder starts recording after the create operation. Set this to 'false' for development and testing purposes.
    role_arn string
    The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
    name string
    The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
    recording_group object
    Specifies which resource types are in scope for the configuration recorder to record.
    recording_mode object
    Specifies the default recording frequency for the configuration recorder.
    started_on_create bool
    Defaults to 'true'. Controls whether the recorder starts recording after the create operation. Set this to 'false' for development and testing purposes.
    roleArn String
    The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
    name String
    The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
    recordingGroup ConfigurationRecorderRecordingGroup
    Specifies which resource types are in scope for the configuration recorder to record.
    recordingMode ConfigurationRecorderRecordingMode
    Specifies the default recording frequency for the configuration recorder.
    startedOnCreate Boolean
    Defaults to 'true'. Controls whether the recorder starts recording after the create operation. Set this to 'false' for development and testing purposes.
    roleArn string
    The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
    name string
    The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
    recordingGroup ConfigurationRecorderRecordingGroup
    Specifies which resource types are in scope for the configuration recorder to record.
    recordingMode ConfigurationRecorderRecordingMode
    Specifies the default recording frequency for the configuration recorder.
    startedOnCreate boolean
    Defaults to 'true'. Controls whether the recorder starts recording after the create operation. Set this to 'false' for development and testing purposes.
    role_arn str
    The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
    name str
    The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
    recording_group ConfigurationRecorderRecordingGroupArgs
    Specifies which resource types are in scope for the configuration recorder to record.
    recording_mode ConfigurationRecorderRecordingModeArgs
    Specifies the default recording frequency for the configuration recorder.
    started_on_create bool
    Defaults to 'true'. Controls whether the recorder starts recording after the create operation. Set this to 'false' for development and testing purposes.
    roleArn String
    The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
    name String
    The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
    recordingGroup Property Map
    Specifies which resource types are in scope for the configuration recorder to record.
    recordingMode Property Map
    Specifies the default recording frequency for the configuration recorder.
    startedOnCreate Boolean
    Defaults to 'true'. Controls whether the recorder starts recording after the create operation. Set this to 'false' for development and testing purposes.

    Outputs

    All input properties are implicitly available as output properties. Additionally, the ConfigurationRecorder resource produces the following output properties:

    Id string
    The provider-assigned unique ID for this managed resource.
    ResourceArn string
    Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
    Id string
    The provider-assigned unique ID for this managed resource.
    ResourceArn string
    Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
    id string
    The provider-assigned unique ID for this managed resource.
    resource_arn string
    Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
    id String
    The provider-assigned unique ID for this managed resource.
    resourceArn String
    Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
    id string
    The provider-assigned unique ID for this managed resource.
    resourceArn string
    Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
    id str
    The provider-assigned unique ID for this managed resource.
    resource_arn str
    Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
    id String
    The provider-assigned unique ID for this managed resource.
    resourceArn String
    Returns the Amazon Resource Name (ARN) for the Configuration Recorder.

    Supporting Types

    ConfigurationRecorderExclusionByResourceTypes, ConfigurationRecorderExclusionByResourceTypesArgs

    Specifies whether the configuration recorder excludes certain resource types from being recorded.
    ResourceTypes List<string>
    A comma-separated list of resource types to exclude from recording by the configuration recorder.
    ResourceTypes []string
    A comma-separated list of resource types to exclude from recording by the configuration recorder.
    resource_types list(string)
    A comma-separated list of resource types to exclude from recording by the configuration recorder.
    resourceTypes List<String>
    A comma-separated list of resource types to exclude from recording by the configuration recorder.
    resourceTypes string[]
    A comma-separated list of resource types to exclude from recording by the configuration recorder.
    resource_types Sequence[str]
    A comma-separated list of resource types to exclude from recording by the configuration recorder.
    resourceTypes List<String>
    A comma-separated list of resource types to exclude from recording by the configuration recorder.

    ConfigurationRecorderRecordingGroup, ConfigurationRecorderRecordingGroupArgs

    Specifies which resource types AWS Config records for configuration changes.
    AllSupported bool
    Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
    ExclusionByResourceTypes Pulumi.AwsNative.Configuration.Inputs.ConfigurationRecorderExclusionByResourceTypes
    An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
    IncludeGlobalResourceTypes bool
    This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
    RecordingStrategy Pulumi.AwsNative.Configuration.Inputs.ConfigurationRecorderRecordingStrategy
    An object that specifies the recording strategy for the configuration recorder.
    ResourceTypes List<string>
    A comma-separated list that specifies which resource types AWS Config records.
    AllSupported bool
    Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
    ExclusionByResourceTypes ConfigurationRecorderExclusionByResourceTypes
    An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
    IncludeGlobalResourceTypes bool
    This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
    RecordingStrategy ConfigurationRecorderRecordingStrategy
    An object that specifies the recording strategy for the configuration recorder.
    ResourceTypes []string
    A comma-separated list that specifies which resource types AWS Config records.
    all_supported bool
    Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
    exclusion_by_resource_types object
    An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
    include_global_resource_types bool
    This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
    recording_strategy object
    An object that specifies the recording strategy for the configuration recorder.
    resource_types list(string)
    A comma-separated list that specifies which resource types AWS Config records.
    allSupported Boolean
    Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
    exclusionByResourceTypes ConfigurationRecorderExclusionByResourceTypes
    An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
    includeGlobalResourceTypes Boolean
    This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
    recordingStrategy ConfigurationRecorderRecordingStrategy
    An object that specifies the recording strategy for the configuration recorder.
    resourceTypes List<String>
    A comma-separated list that specifies which resource types AWS Config records.
    allSupported boolean
    Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
    exclusionByResourceTypes ConfigurationRecorderExclusionByResourceTypes
    An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
    includeGlobalResourceTypes boolean
    This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
    recordingStrategy ConfigurationRecorderRecordingStrategy
    An object that specifies the recording strategy for the configuration recorder.
    resourceTypes string[]
    A comma-separated list that specifies which resource types AWS Config records.
    all_supported bool
    Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
    exclusion_by_resource_types ConfigurationRecorderExclusionByResourceTypes
    An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
    include_global_resource_types bool
    This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
    recording_strategy ConfigurationRecorderRecordingStrategy
    An object that specifies the recording strategy for the configuration recorder.
    resource_types Sequence[str]
    A comma-separated list that specifies which resource types AWS Config records.
    allSupported Boolean
    Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
    exclusionByResourceTypes Property Map
    An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
    includeGlobalResourceTypes Boolean
    This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
    recordingStrategy Property Map
    An object that specifies the recording strategy for the configuration recorder.
    resourceTypes List<String>
    A comma-separated list that specifies which resource types AWS Config records.

    ConfigurationRecorderRecordingMode, ConfigurationRecorderRecordingModeArgs

    Specifies the default recording frequency for the configuration recorder.
    RecordingFrequency string
    The default recording frequency that AWS Config uses to record configuration changes.
    RecordingModeOverrides List<Pulumi.AwsNative.Configuration.Inputs.ConfigurationRecorderRecordingModeOverride>
    An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
    RecordingFrequency string
    The default recording frequency that AWS Config uses to record configuration changes.
    RecordingModeOverrides []ConfigurationRecorderRecordingModeOverride
    An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
    recording_frequency string
    The default recording frequency that AWS Config uses to record configuration changes.
    recording_mode_overrides list(object)
    An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
    recordingFrequency String
    The default recording frequency that AWS Config uses to record configuration changes.
    recordingModeOverrides List<ConfigurationRecorderRecordingModeOverride>
    An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
    recordingFrequency string
    The default recording frequency that AWS Config uses to record configuration changes.
    recordingModeOverrides ConfigurationRecorderRecordingModeOverride[]
    An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
    recording_frequency str
    The default recording frequency that AWS Config uses to record configuration changes.
    recording_mode_overrides Sequence[ConfigurationRecorderRecordingModeOverride]
    An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
    recordingFrequency String
    The default recording frequency that AWS Config uses to record configuration changes.
    recordingModeOverrides List<Property Map>
    An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.

    ConfigurationRecorderRecordingModeOverride, ConfigurationRecorderRecordingModeOverrideArgs

    Specifies your overrides for the recording mode
    RecordingFrequency string
    The recording frequency that will be applied to all the resource types specified in the override.
    ResourceTypes List<string>
    A comma-separated list that specifies which resource types AWS Config includes in the override.
    Description string
    A description that you provide for the override.
    RecordingFrequency string
    The recording frequency that will be applied to all the resource types specified in the override.
    ResourceTypes []string
    A comma-separated list that specifies which resource types AWS Config includes in the override.
    Description string
    A description that you provide for the override.
    recording_frequency string
    The recording frequency that will be applied to all the resource types specified in the override.
    resource_types list(string)
    A comma-separated list that specifies which resource types AWS Config includes in the override.
    description string
    A description that you provide for the override.
    recordingFrequency String
    The recording frequency that will be applied to all the resource types specified in the override.
    resourceTypes List<String>
    A comma-separated list that specifies which resource types AWS Config includes in the override.
    description String
    A description that you provide for the override.
    recordingFrequency string
    The recording frequency that will be applied to all the resource types specified in the override.
    resourceTypes string[]
    A comma-separated list that specifies which resource types AWS Config includes in the override.
    description string
    A description that you provide for the override.
    recording_frequency str
    The recording frequency that will be applied to all the resource types specified in the override.
    resource_types Sequence[str]
    A comma-separated list that specifies which resource types AWS Config includes in the override.
    description str
    A description that you provide for the override.
    recordingFrequency String
    The recording frequency that will be applied to all the resource types specified in the override.
    resourceTypes List<String>
    A comma-separated list that specifies which resource types AWS Config includes in the override.
    description String
    A description that you provide for the override.

    ConfigurationRecorderRecordingStrategy, ConfigurationRecorderRecordingStrategyArgs

    Specifies the recording strategy of the configuration recorder.
    UseOnly string

    The recording strategy for the configuration recorder.

    • If you set this option to ALL_SUPPORTED_RESOURCE_TYPES , AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set the AllSupported field of RecordingGroup to true . When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide .
    • If you set this option to INCLUSION_BY_RESOURCE_TYPES , AWS Config records configuration changes for only the resource types that you specify in the ResourceTypes field of RecordingGroup .
    • If you set this option to EXCLUSION_BY_RESOURCE_TYPES , AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in the ResourceTypes field of ExclusionByResourceTypes .

    Required and optional fields

    The recordingStrategy field is optional when you set the AllSupported field of RecordingGroup to true .

    The recordingStrategy field is optional when you list resource types in the ResourceTypes field of RecordingGroup .

    The recordingStrategy field is required if you list resource types to exclude from recording in the ResourceTypes field of ExclusionByResourceTypes . > Overriding fields

    If you choose EXCLUSION_BY_RESOURCE_TYPES for the recording strategy, the ExclusionByResourceTypes field will override other properties in the request.

    For example, even if you set IncludeGlobalResourceTypes to false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in the ResourceTypes field of ExclusionByResourceTypes . > Global resource types and the exclusion recording strategy

    By default, if you choose the EXCLUSION_BY_RESOURCE_TYPES recording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.

    Unless specifically listed as exclusions, AWS::RDS::GlobalCluster will be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.

    IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:

    • Asia Pacific (Hyderabad)
    • Asia Pacific (Melbourne)
    • Canada West (Calgary)
    • Europe (Spain)
    • Europe (Zurich)
    • Israel (Tel Aviv)
    • Middle East (UAE)
    UseOnly string

    The recording strategy for the configuration recorder.

    • If you set this option to ALL_SUPPORTED_RESOURCE_TYPES , AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set the AllSupported field of RecordingGroup to true . When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide .
    • If you set this option to INCLUSION_BY_RESOURCE_TYPES , AWS Config records configuration changes for only the resource types that you specify in the ResourceTypes field of RecordingGroup .
    • If you set this option to EXCLUSION_BY_RESOURCE_TYPES , AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in the ResourceTypes field of ExclusionByResourceTypes .

    Required and optional fields

    The recordingStrategy field is optional when you set the AllSupported field of RecordingGroup to true .

    The recordingStrategy field is optional when you list resource types in the ResourceTypes field of RecordingGroup .

    The recordingStrategy field is required if you list resource types to exclude from recording in the ResourceTypes field of ExclusionByResourceTypes . > Overriding fields

    If you choose EXCLUSION_BY_RESOURCE_TYPES for the recording strategy, the ExclusionByResourceTypes field will override other properties in the request.

    For example, even if you set IncludeGlobalResourceTypes to false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in the ResourceTypes field of ExclusionByResourceTypes . > Global resource types and the exclusion recording strategy

    By default, if you choose the EXCLUSION_BY_RESOURCE_TYPES recording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.

    Unless specifically listed as exclusions, AWS::RDS::GlobalCluster will be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.

    IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:

    • Asia Pacific (Hyderabad)
    • Asia Pacific (Melbourne)
    • Canada West (Calgary)
    • Europe (Spain)
    • Europe (Zurich)
    • Israel (Tel Aviv)
    • Middle East (UAE)
    use_only string

    The recording strategy for the configuration recorder.

    • If you set this option to ALL_SUPPORTED_RESOURCE_TYPES , AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set the AllSupported field of RecordingGroup to true . When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide .
    • If you set this option to INCLUSION_BY_RESOURCE_TYPES , AWS Config records configuration changes for only the resource types that you specify in the ResourceTypes field of RecordingGroup .
    • If you set this option to EXCLUSION_BY_RESOURCE_TYPES , AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in the ResourceTypes field of ExclusionByResourceTypes .

    Required and optional fields

    The recordingStrategy field is optional when you set the AllSupported field of RecordingGroup to true .

    The recordingStrategy field is optional when you list resource types in the ResourceTypes field of RecordingGroup .

    The recordingStrategy field is required if you list resource types to exclude from recording in the ResourceTypes field of ExclusionByResourceTypes . > Overriding fields

    If you choose EXCLUSION_BY_RESOURCE_TYPES for the recording strategy, the ExclusionByResourceTypes field will override other properties in the request.

    For example, even if you set IncludeGlobalResourceTypes to false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in the ResourceTypes field of ExclusionByResourceTypes . > Global resource types and the exclusion recording strategy

    By default, if you choose the EXCLUSION_BY_RESOURCE_TYPES recording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.

    Unless specifically listed as exclusions, AWS::RDS::GlobalCluster will be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.

    IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:

    • Asia Pacific (Hyderabad)
    • Asia Pacific (Melbourne)
    • Canada West (Calgary)
    • Europe (Spain)
    • Europe (Zurich)
    • Israel (Tel Aviv)
    • Middle East (UAE)
    useOnly String

    The recording strategy for the configuration recorder.

    • If you set this option to ALL_SUPPORTED_RESOURCE_TYPES , AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set the AllSupported field of RecordingGroup to true . When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide .
    • If you set this option to INCLUSION_BY_RESOURCE_TYPES , AWS Config records configuration changes for only the resource types that you specify in the ResourceTypes field of RecordingGroup .
    • If you set this option to EXCLUSION_BY_RESOURCE_TYPES , AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in the ResourceTypes field of ExclusionByResourceTypes .

    Required and optional fields

    The recordingStrategy field is optional when you set the AllSupported field of RecordingGroup to true .

    The recordingStrategy field is optional when you list resource types in the ResourceTypes field of RecordingGroup .

    The recordingStrategy field is required if you list resource types to exclude from recording in the ResourceTypes field of ExclusionByResourceTypes . > Overriding fields

    If you choose EXCLUSION_BY_RESOURCE_TYPES for the recording strategy, the ExclusionByResourceTypes field will override other properties in the request.

    For example, even if you set IncludeGlobalResourceTypes to false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in the ResourceTypes field of ExclusionByResourceTypes . > Global resource types and the exclusion recording strategy

    By default, if you choose the EXCLUSION_BY_RESOURCE_TYPES recording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.

    Unless specifically listed as exclusions, AWS::RDS::GlobalCluster will be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.

    IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:

    • Asia Pacific (Hyderabad)
    • Asia Pacific (Melbourne)
    • Canada West (Calgary)
    • Europe (Spain)
    • Europe (Zurich)
    • Israel (Tel Aviv)
    • Middle East (UAE)
    useOnly string

    The recording strategy for the configuration recorder.

    • If you set this option to ALL_SUPPORTED_RESOURCE_TYPES , AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set the AllSupported field of RecordingGroup to true . When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide .
    • If you set this option to INCLUSION_BY_RESOURCE_TYPES , AWS Config records configuration changes for only the resource types that you specify in the ResourceTypes field of RecordingGroup .
    • If you set this option to EXCLUSION_BY_RESOURCE_TYPES , AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in the ResourceTypes field of ExclusionByResourceTypes .

    Required and optional fields

    The recordingStrategy field is optional when you set the AllSupported field of RecordingGroup to true .

    The recordingStrategy field is optional when you list resource types in the ResourceTypes field of RecordingGroup .

    The recordingStrategy field is required if you list resource types to exclude from recording in the ResourceTypes field of ExclusionByResourceTypes . > Overriding fields

    If you choose EXCLUSION_BY_RESOURCE_TYPES for the recording strategy, the ExclusionByResourceTypes field will override other properties in the request.

    For example, even if you set IncludeGlobalResourceTypes to false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in the ResourceTypes field of ExclusionByResourceTypes . > Global resource types and the exclusion recording strategy

    By default, if you choose the EXCLUSION_BY_RESOURCE_TYPES recording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.

    Unless specifically listed as exclusions, AWS::RDS::GlobalCluster will be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.

    IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:

    • Asia Pacific (Hyderabad)
    • Asia Pacific (Melbourne)
    • Canada West (Calgary)
    • Europe (Spain)
    • Europe (Zurich)
    • Israel (Tel Aviv)
    • Middle East (UAE)
    use_only str

    The recording strategy for the configuration recorder.

    • If you set this option to ALL_SUPPORTED_RESOURCE_TYPES , AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set the AllSupported field of RecordingGroup to true . When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide .
    • If you set this option to INCLUSION_BY_RESOURCE_TYPES , AWS Config records configuration changes for only the resource types that you specify in the ResourceTypes field of RecordingGroup .
    • If you set this option to EXCLUSION_BY_RESOURCE_TYPES , AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in the ResourceTypes field of ExclusionByResourceTypes .

    Required and optional fields

    The recordingStrategy field is optional when you set the AllSupported field of RecordingGroup to true .

    The recordingStrategy field is optional when you list resource types in the ResourceTypes field of RecordingGroup .

    The recordingStrategy field is required if you list resource types to exclude from recording in the ResourceTypes field of ExclusionByResourceTypes . > Overriding fields

    If you choose EXCLUSION_BY_RESOURCE_TYPES for the recording strategy, the ExclusionByResourceTypes field will override other properties in the request.

    For example, even if you set IncludeGlobalResourceTypes to false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in the ResourceTypes field of ExclusionByResourceTypes . > Global resource types and the exclusion recording strategy

    By default, if you choose the EXCLUSION_BY_RESOURCE_TYPES recording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.

    Unless specifically listed as exclusions, AWS::RDS::GlobalCluster will be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.

    IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:

    • Asia Pacific (Hyderabad)
    • Asia Pacific (Melbourne)
    • Canada West (Calgary)
    • Europe (Spain)
    • Europe (Zurich)
    • Israel (Tel Aviv)
    • Middle East (UAE)
    useOnly String

    The recording strategy for the configuration recorder.

    • If you set this option to ALL_SUPPORTED_RESOURCE_TYPES , AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set the AllSupported field of RecordingGroup to true . When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide .
    • If you set this option to INCLUSION_BY_RESOURCE_TYPES , AWS Config records configuration changes for only the resource types that you specify in the ResourceTypes field of RecordingGroup .
    • If you set this option to EXCLUSION_BY_RESOURCE_TYPES , AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in the ResourceTypes field of ExclusionByResourceTypes .

    Required and optional fields

    The recordingStrategy field is optional when you set the AllSupported field of RecordingGroup to true .

    The recordingStrategy field is optional when you list resource types in the ResourceTypes field of RecordingGroup .

    The recordingStrategy field is required if you list resource types to exclude from recording in the ResourceTypes field of ExclusionByResourceTypes . > Overriding fields

    If you choose EXCLUSION_BY_RESOURCE_TYPES for the recording strategy, the ExclusionByResourceTypes field will override other properties in the request.

    For example, even if you set IncludeGlobalResourceTypes to false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in the ResourceTypes field of ExclusionByResourceTypes . > Global resource types and the exclusion recording strategy

    By default, if you choose the EXCLUSION_BY_RESOURCE_TYPES recording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.

    Unless specifically listed as exclusions, AWS::RDS::GlobalCluster will be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.

    IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:

    • Asia Pacific (Hyderabad)
    • Asia Pacific (Melbourne)
    • Canada West (Calgary)
    • Europe (Spain)
    • Europe (Zurich)
    • Israel (Tel Aviv)
    • Middle East (UAE)

    Package Details

    Repository
    AWS Native pulumi/pulumi-aws-native
    License
    Apache-2.0
    aws-native logo aws-native logo

    We recommend new projects start with resources from the AWS provider.

    Viewing docs for AWS Cloud Control v1.81.0
    published on Monday, Sep 28, 2026 by Pulumi

      Try Pulumi Cloud free.
      Your team will thank you.

      Start free trial