We recommend new projects start with resources from the AWS provider.
published on Monday, Sep 28, 2026 by Pulumi
We recommend new projects start with resources from the AWS provider.
published on Monday, Sep 28, 2026 by Pulumi
Resource type definition for AWS::Config::ConfigurationRecorder
Create ConfigurationRecorder Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new ConfigurationRecorder(name: string, args: ConfigurationRecorderArgs, opts?: CustomResourceOptions);@overload
def ConfigurationRecorder(resource_name: str,
args: ConfigurationRecorderArgs,
opts: Optional[ResourceOptions] = None)
@overload
def ConfigurationRecorder(resource_name: str,
opts: Optional[ResourceOptions] = None,
role_arn: Optional[str] = None,
name: Optional[str] = None,
recording_group: Optional[ConfigurationRecorderRecordingGroupArgs] = None,
recording_mode: Optional[ConfigurationRecorderRecordingModeArgs] = None,
started_on_create: Optional[bool] = None)func NewConfigurationRecorder(ctx *Context, name string, args ConfigurationRecorderArgs, opts ...ResourceOption) (*ConfigurationRecorder, error)public ConfigurationRecorder(string name, ConfigurationRecorderArgs args, CustomResourceOptions? opts = null)
public ConfigurationRecorder(String name, ConfigurationRecorderArgs args)
public ConfigurationRecorder(String name, ConfigurationRecorderArgs args, CustomResourceOptions options)
type: aws-native:configuration:ConfigurationRecorder
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "aws-native_configuration_configuration_recorder" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args ConfigurationRecorderArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args ConfigurationRecorderArgs
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args ConfigurationRecorderArgs
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args ConfigurationRecorderArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args ConfigurationRecorderArgs
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
ConfigurationRecorder Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The ConfigurationRecorder resource accepts the following input properties:
- Role
Arn string - The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
- Name string
- The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
- Recording
Group Pulumi.Aws Native. Configuration. Inputs. Configuration Recorder Recording Group - Specifies which resource types are in scope for the configuration recorder to record.
- Recording
Mode Pulumi.Aws Native. Configuration. Inputs. Configuration Recorder Recording Mode - Specifies the default recording frequency for the configuration recorder.
- Started
On boolCreate - Defaults to 'true'. Controls whether the recorder starts recording after the create operation. Set this to 'false' for development and testing purposes.
- Role
Arn string - The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
- Name string
- The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
- Recording
Group ConfigurationRecorder Recording Group Args - Specifies which resource types are in scope for the configuration recorder to record.
- Recording
Mode ConfigurationRecorder Recording Mode Args - Specifies the default recording frequency for the configuration recorder.
- Started
On boolCreate - Defaults to 'true'. Controls whether the recorder starts recording after the create operation. Set this to 'false' for development and testing purposes.
- role_
arn string - The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
- name string
- The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
- recording_
group object - Specifies which resource types are in scope for the configuration recorder to record.
- recording_
mode object - Specifies the default recording frequency for the configuration recorder.
- started_
on_ boolcreate - Defaults to 'true'. Controls whether the recorder starts recording after the create operation. Set this to 'false' for development and testing purposes.
- role
Arn String - The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
- name String
- The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
- recording
Group ConfigurationRecorder Recording Group - Specifies which resource types are in scope for the configuration recorder to record.
- recording
Mode ConfigurationRecorder Recording Mode - Specifies the default recording frequency for the configuration recorder.
- started
On BooleanCreate - Defaults to 'true'. Controls whether the recorder starts recording after the create operation. Set this to 'false' for development and testing purposes.
- role
Arn string - The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
- name string
- The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
- recording
Group ConfigurationRecorder Recording Group - Specifies which resource types are in scope for the configuration recorder to record.
- recording
Mode ConfigurationRecorder Recording Mode - Specifies the default recording frequency for the configuration recorder.
- started
On booleanCreate - Defaults to 'true'. Controls whether the recorder starts recording after the create operation. Set this to 'false' for development and testing purposes.
- role_
arn str - The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
- name str
- The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
- recording_
group ConfigurationRecorder Recording Group Args - Specifies which resource types are in scope for the configuration recorder to record.
- recording_
mode ConfigurationRecorder Recording Mode Args - Specifies the default recording frequency for the configuration recorder.
- started_
on_ boolcreate - Defaults to 'true'. Controls whether the recorder starts recording after the create operation. Set this to 'false' for development and testing purposes.
- role
Arn String - The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
- name String
- The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
- recording
Group Property Map - Specifies which resource types are in scope for the configuration recorder to record.
- recording
Mode Property Map - Specifies the default recording frequency for the configuration recorder.
- started
On BooleanCreate - Defaults to 'true'. Controls whether the recorder starts recording after the create operation. Set this to 'false' for development and testing purposes.
Outputs
All input properties are implicitly available as output properties. Additionally, the ConfigurationRecorder resource produces the following output properties:
- Id string
- The provider-assigned unique ID for this managed resource.
- Resource
Arn string - Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
- Id string
- The provider-assigned unique ID for this managed resource.
- Resource
Arn string - Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
- id string
- The provider-assigned unique ID for this managed resource.
- resource_
arn string - Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
- id String
- The provider-assigned unique ID for this managed resource.
- resource
Arn String - Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
- id string
- The provider-assigned unique ID for this managed resource.
- resource
Arn string - Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
- id str
- The provider-assigned unique ID for this managed resource.
- resource_
arn str - Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
- id String
- The provider-assigned unique ID for this managed resource.
- resource
Arn String - Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
Supporting Types
ConfigurationRecorderExclusionByResourceTypes, ConfigurationRecorderExclusionByResourceTypesArgs
Specifies whether the configuration recorder excludes certain resource types from being recorded.- Resource
Types List<string> - A comma-separated list of resource types to exclude from recording by the configuration recorder.
- Resource
Types []string - A comma-separated list of resource types to exclude from recording by the configuration recorder.
- resource_
types list(string) - A comma-separated list of resource types to exclude from recording by the configuration recorder.
- resource
Types List<String> - A comma-separated list of resource types to exclude from recording by the configuration recorder.
- resource
Types string[] - A comma-separated list of resource types to exclude from recording by the configuration recorder.
- resource_
types Sequence[str] - A comma-separated list of resource types to exclude from recording by the configuration recorder.
- resource
Types List<String> - A comma-separated list of resource types to exclude from recording by the configuration recorder.
ConfigurationRecorderRecordingGroup, ConfigurationRecorderRecordingGroupArgs
Specifies which resource types AWS Config records for configuration changes.- All
Supported bool - Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
- Exclusion
By Pulumi.Resource Types Aws Native. Configuration. Inputs. Configuration Recorder Exclusion By Resource Types - An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
- Include
Global boolResource Types - This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
- Recording
Strategy Pulumi.Aws Native. Configuration. Inputs. Configuration Recorder Recording Strategy - An object that specifies the recording strategy for the configuration recorder.
- Resource
Types List<string> - A comma-separated list that specifies which resource types AWS Config records.
- All
Supported bool - Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
- Exclusion
By ConfigurationResource Types Recorder Exclusion By Resource Types - An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
- Include
Global boolResource Types - This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
- Recording
Strategy ConfigurationRecorder Recording Strategy - An object that specifies the recording strategy for the configuration recorder.
- Resource
Types []string - A comma-separated list that specifies which resource types AWS Config records.
- all_
supported bool - Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
- exclusion_
by_ objectresource_ types - An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
- include_
global_ boolresource_ types - This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
- recording_
strategy object - An object that specifies the recording strategy for the configuration recorder.
- resource_
types list(string) - A comma-separated list that specifies which resource types AWS Config records.
- all
Supported Boolean - Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
- exclusion
By ConfigurationResource Types Recorder Exclusion By Resource Types - An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
- include
Global BooleanResource Types - This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
- recording
Strategy ConfigurationRecorder Recording Strategy - An object that specifies the recording strategy for the configuration recorder.
- resource
Types List<String> - A comma-separated list that specifies which resource types AWS Config records.
- all
Supported boolean - Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
- exclusion
By ConfigurationResource Types Recorder Exclusion By Resource Types - An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
- include
Global booleanResource Types - This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
- recording
Strategy ConfigurationRecorder Recording Strategy - An object that specifies the recording strategy for the configuration recorder.
- resource
Types string[] - A comma-separated list that specifies which resource types AWS Config records.
- all_
supported bool - Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
- exclusion_
by_ Configurationresource_ types Recorder Exclusion By Resource Types - An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
- include_
global_ boolresource_ types - This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
- recording_
strategy ConfigurationRecorder Recording Strategy - An object that specifies the recording strategy for the configuration recorder.
- resource_
types Sequence[str] - A comma-separated list that specifies which resource types AWS Config records.
- all
Supported Boolean - Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
- exclusion
By Property MapResource Types - An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
- include
Global BooleanResource Types - This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
- recording
Strategy Property Map - An object that specifies the recording strategy for the configuration recorder.
- resource
Types List<String> - A comma-separated list that specifies which resource types AWS Config records.
ConfigurationRecorderRecordingMode, ConfigurationRecorderRecordingModeArgs
Specifies the default recording frequency for the configuration recorder.- Recording
Frequency string - The default recording frequency that AWS Config uses to record configuration changes.
- Recording
Mode List<Pulumi.Overrides Aws Native. Configuration. Inputs. Configuration Recorder Recording Mode Override> - An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
- Recording
Frequency string - The default recording frequency that AWS Config uses to record configuration changes.
- Recording
Mode []ConfigurationOverrides Recorder Recording Mode Override - An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
- recording_
frequency string - The default recording frequency that AWS Config uses to record configuration changes.
- recording_
mode_ list(object)overrides - An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
- recording
Frequency String - The default recording frequency that AWS Config uses to record configuration changes.
- recording
Mode List<ConfigurationOverrides Recorder Recording Mode Override> - An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
- recording
Frequency string - The default recording frequency that AWS Config uses to record configuration changes.
- recording
Mode ConfigurationOverrides Recorder Recording Mode Override[] - An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
- recording_
frequency str - The default recording frequency that AWS Config uses to record configuration changes.
- recording_
mode_ Sequence[Configurationoverrides Recorder Recording Mode Override] - An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
- recording
Frequency String - The default recording frequency that AWS Config uses to record configuration changes.
- recording
Mode List<Property Map>Overrides - An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
ConfigurationRecorderRecordingModeOverride, ConfigurationRecorderRecordingModeOverrideArgs
Specifies your overrides for the recording mode- Recording
Frequency string - The recording frequency that will be applied to all the resource types specified in the override.
- Resource
Types List<string> - A comma-separated list that specifies which resource types AWS Config includes in the override.
- Description string
- A description that you provide for the override.
- Recording
Frequency string - The recording frequency that will be applied to all the resource types specified in the override.
- Resource
Types []string - A comma-separated list that specifies which resource types AWS Config includes in the override.
- Description string
- A description that you provide for the override.
- recording_
frequency string - The recording frequency that will be applied to all the resource types specified in the override.
- resource_
types list(string) - A comma-separated list that specifies which resource types AWS Config includes in the override.
- description string
- A description that you provide for the override.
- recording
Frequency String - The recording frequency that will be applied to all the resource types specified in the override.
- resource
Types List<String> - A comma-separated list that specifies which resource types AWS Config includes in the override.
- description String
- A description that you provide for the override.
- recording
Frequency string - The recording frequency that will be applied to all the resource types specified in the override.
- resource
Types string[] - A comma-separated list that specifies which resource types AWS Config includes in the override.
- description string
- A description that you provide for the override.
- recording_
frequency str - The recording frequency that will be applied to all the resource types specified in the override.
- resource_
types Sequence[str] - A comma-separated list that specifies which resource types AWS Config includes in the override.
- description str
- A description that you provide for the override.
- recording
Frequency String - The recording frequency that will be applied to all the resource types specified in the override.
- resource
Types List<String> - A comma-separated list that specifies which resource types AWS Config includes in the override.
- description String
- A description that you provide for the override.
ConfigurationRecorderRecordingStrategy, ConfigurationRecorderRecordingStrategyArgs
Specifies the recording strategy of the configuration recorder.- Use
Only string The recording strategy for the configuration recorder.
- If you set this option to
ALL_SUPPORTED_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set theAllSupportedfield of RecordingGroup totrue. When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide . - If you set this option to
INCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for only the resource types that you specify in theResourceTypesfield of RecordingGroup . - If you set this option to
EXCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in theResourceTypesfield of ExclusionByResourceTypes .
Required and optional fields
The
recordingStrategyfield is optional when you set theAllSupportedfield of RecordingGroup totrue.The
recordingStrategyfield is optional when you list resource types in theResourceTypesfield of RecordingGroup .The
recordingStrategyfield is required if you list resource types to exclude from recording in theResourceTypesfield of ExclusionByResourceTypes . > Overriding fieldsIf you choose
EXCLUSION_BY_RESOURCE_TYPESfor the recording strategy, theExclusionByResourceTypesfield will override other properties in the request.For example, even if you set
IncludeGlobalResourceTypesto false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in theResourceTypesfield ofExclusionByResourceTypes. > Global resource types and the exclusion recording strategyBy default, if you choose the
EXCLUSION_BY_RESOURCE_TYPESrecording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.Unless specifically listed as exclusions,
AWS::RDS::GlobalClusterwill be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:
- Asia Pacific (Hyderabad)
- Asia Pacific (Melbourne)
- Canada West (Calgary)
- Europe (Spain)
- Europe (Zurich)
- Israel (Tel Aviv)
- Middle East (UAE)
- If you set this option to
- Use
Only string The recording strategy for the configuration recorder.
- If you set this option to
ALL_SUPPORTED_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set theAllSupportedfield of RecordingGroup totrue. When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide . - If you set this option to
INCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for only the resource types that you specify in theResourceTypesfield of RecordingGroup . - If you set this option to
EXCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in theResourceTypesfield of ExclusionByResourceTypes .
Required and optional fields
The
recordingStrategyfield is optional when you set theAllSupportedfield of RecordingGroup totrue.The
recordingStrategyfield is optional when you list resource types in theResourceTypesfield of RecordingGroup .The
recordingStrategyfield is required if you list resource types to exclude from recording in theResourceTypesfield of ExclusionByResourceTypes . > Overriding fieldsIf you choose
EXCLUSION_BY_RESOURCE_TYPESfor the recording strategy, theExclusionByResourceTypesfield will override other properties in the request.For example, even if you set
IncludeGlobalResourceTypesto false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in theResourceTypesfield ofExclusionByResourceTypes. > Global resource types and the exclusion recording strategyBy default, if you choose the
EXCLUSION_BY_RESOURCE_TYPESrecording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.Unless specifically listed as exclusions,
AWS::RDS::GlobalClusterwill be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:
- Asia Pacific (Hyderabad)
- Asia Pacific (Melbourne)
- Canada West (Calgary)
- Europe (Spain)
- Europe (Zurich)
- Israel (Tel Aviv)
- Middle East (UAE)
- If you set this option to
- use_
only string The recording strategy for the configuration recorder.
- If you set this option to
ALL_SUPPORTED_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set theAllSupportedfield of RecordingGroup totrue. When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide . - If you set this option to
INCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for only the resource types that you specify in theResourceTypesfield of RecordingGroup . - If you set this option to
EXCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in theResourceTypesfield of ExclusionByResourceTypes .
Required and optional fields
The
recordingStrategyfield is optional when you set theAllSupportedfield of RecordingGroup totrue.The
recordingStrategyfield is optional when you list resource types in theResourceTypesfield of RecordingGroup .The
recordingStrategyfield is required if you list resource types to exclude from recording in theResourceTypesfield of ExclusionByResourceTypes . > Overriding fieldsIf you choose
EXCLUSION_BY_RESOURCE_TYPESfor the recording strategy, theExclusionByResourceTypesfield will override other properties in the request.For example, even if you set
IncludeGlobalResourceTypesto false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in theResourceTypesfield ofExclusionByResourceTypes. > Global resource types and the exclusion recording strategyBy default, if you choose the
EXCLUSION_BY_RESOURCE_TYPESrecording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.Unless specifically listed as exclusions,
AWS::RDS::GlobalClusterwill be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:
- Asia Pacific (Hyderabad)
- Asia Pacific (Melbourne)
- Canada West (Calgary)
- Europe (Spain)
- Europe (Zurich)
- Israel (Tel Aviv)
- Middle East (UAE)
- If you set this option to
- use
Only String The recording strategy for the configuration recorder.
- If you set this option to
ALL_SUPPORTED_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set theAllSupportedfield of RecordingGroup totrue. When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide . - If you set this option to
INCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for only the resource types that you specify in theResourceTypesfield of RecordingGroup . - If you set this option to
EXCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in theResourceTypesfield of ExclusionByResourceTypes .
Required and optional fields
The
recordingStrategyfield is optional when you set theAllSupportedfield of RecordingGroup totrue.The
recordingStrategyfield is optional when you list resource types in theResourceTypesfield of RecordingGroup .The
recordingStrategyfield is required if you list resource types to exclude from recording in theResourceTypesfield of ExclusionByResourceTypes . > Overriding fieldsIf you choose
EXCLUSION_BY_RESOURCE_TYPESfor the recording strategy, theExclusionByResourceTypesfield will override other properties in the request.For example, even if you set
IncludeGlobalResourceTypesto false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in theResourceTypesfield ofExclusionByResourceTypes. > Global resource types and the exclusion recording strategyBy default, if you choose the
EXCLUSION_BY_RESOURCE_TYPESrecording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.Unless specifically listed as exclusions,
AWS::RDS::GlobalClusterwill be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:
- Asia Pacific (Hyderabad)
- Asia Pacific (Melbourne)
- Canada West (Calgary)
- Europe (Spain)
- Europe (Zurich)
- Israel (Tel Aviv)
- Middle East (UAE)
- If you set this option to
- use
Only string The recording strategy for the configuration recorder.
- If you set this option to
ALL_SUPPORTED_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set theAllSupportedfield of RecordingGroup totrue. When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide . - If you set this option to
INCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for only the resource types that you specify in theResourceTypesfield of RecordingGroup . - If you set this option to
EXCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in theResourceTypesfield of ExclusionByResourceTypes .
Required and optional fields
The
recordingStrategyfield is optional when you set theAllSupportedfield of RecordingGroup totrue.The
recordingStrategyfield is optional when you list resource types in theResourceTypesfield of RecordingGroup .The
recordingStrategyfield is required if you list resource types to exclude from recording in theResourceTypesfield of ExclusionByResourceTypes . > Overriding fieldsIf you choose
EXCLUSION_BY_RESOURCE_TYPESfor the recording strategy, theExclusionByResourceTypesfield will override other properties in the request.For example, even if you set
IncludeGlobalResourceTypesto false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in theResourceTypesfield ofExclusionByResourceTypes. > Global resource types and the exclusion recording strategyBy default, if you choose the
EXCLUSION_BY_RESOURCE_TYPESrecording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.Unless specifically listed as exclusions,
AWS::RDS::GlobalClusterwill be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:
- Asia Pacific (Hyderabad)
- Asia Pacific (Melbourne)
- Canada West (Calgary)
- Europe (Spain)
- Europe (Zurich)
- Israel (Tel Aviv)
- Middle East (UAE)
- If you set this option to
- use_
only str The recording strategy for the configuration recorder.
- If you set this option to
ALL_SUPPORTED_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set theAllSupportedfield of RecordingGroup totrue. When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide . - If you set this option to
INCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for only the resource types that you specify in theResourceTypesfield of RecordingGroup . - If you set this option to
EXCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in theResourceTypesfield of ExclusionByResourceTypes .
Required and optional fields
The
recordingStrategyfield is optional when you set theAllSupportedfield of RecordingGroup totrue.The
recordingStrategyfield is optional when you list resource types in theResourceTypesfield of RecordingGroup .The
recordingStrategyfield is required if you list resource types to exclude from recording in theResourceTypesfield of ExclusionByResourceTypes . > Overriding fieldsIf you choose
EXCLUSION_BY_RESOURCE_TYPESfor the recording strategy, theExclusionByResourceTypesfield will override other properties in the request.For example, even if you set
IncludeGlobalResourceTypesto false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in theResourceTypesfield ofExclusionByResourceTypes. > Global resource types and the exclusion recording strategyBy default, if you choose the
EXCLUSION_BY_RESOURCE_TYPESrecording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.Unless specifically listed as exclusions,
AWS::RDS::GlobalClusterwill be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:
- Asia Pacific (Hyderabad)
- Asia Pacific (Melbourne)
- Canada West (Calgary)
- Europe (Spain)
- Europe (Zurich)
- Israel (Tel Aviv)
- Middle East (UAE)
- If you set this option to
- use
Only String The recording strategy for the configuration recorder.
- If you set this option to
ALL_SUPPORTED_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set theAllSupportedfield of RecordingGroup totrue. When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide . - If you set this option to
INCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for only the resource types that you specify in theResourceTypesfield of RecordingGroup . - If you set this option to
EXCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in theResourceTypesfield of ExclusionByResourceTypes .
Required and optional fields
The
recordingStrategyfield is optional when you set theAllSupportedfield of RecordingGroup totrue.The
recordingStrategyfield is optional when you list resource types in theResourceTypesfield of RecordingGroup .The
recordingStrategyfield is required if you list resource types to exclude from recording in theResourceTypesfield of ExclusionByResourceTypes . > Overriding fieldsIf you choose
EXCLUSION_BY_RESOURCE_TYPESfor the recording strategy, theExclusionByResourceTypesfield will override other properties in the request.For example, even if you set
IncludeGlobalResourceTypesto false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in theResourceTypesfield ofExclusionByResourceTypes. > Global resource types and the exclusion recording strategyBy default, if you choose the
EXCLUSION_BY_RESOURCE_TYPESrecording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.Unless specifically listed as exclusions,
AWS::RDS::GlobalClusterwill be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:
- Asia Pacific (Hyderabad)
- Asia Pacific (Melbourne)
- Canada West (Calgary)
- Europe (Spain)
- Europe (Zurich)
- Israel (Tel Aviv)
- Middle East (UAE)
- If you set this option to
Package Details
- Repository
- AWS Native pulumi/pulumi-aws-native
- License
- Apache-2.0
We recommend new projects start with resources from the AWS provider.
published on Monday, Sep 28, 2026 by Pulumi