We recommend new projects start with resources from the AWS provider.
published on Monday, Sep 28, 2026 by Pulumi
We recommend new projects start with resources from the AWS provider.
published on Monday, Sep 28, 2026 by Pulumi
Resource type definition for AWS::Config::ConfigurationRecorder
Using getConfigurationRecorder
Two invocation forms are available. The direct form accepts plain arguments and either blocks until the result value is available, or returns a Promise-wrapped result. The output form accepts Input-wrapped arguments and returns an Output-wrapped result.
function getConfigurationRecorder(args: GetConfigurationRecorderArgs, opts?: InvokeOptions): Promise<GetConfigurationRecorderResult>
function getConfigurationRecorderOutput(args: GetConfigurationRecorderOutputArgs, opts?: InvokeOutputOptions): Output<GetConfigurationRecorderResult>def get_configuration_recorder(name: Optional[str] = None,
opts: Optional[InvokeOptions] = None) -> GetConfigurationRecorderResult
def get_configuration_recorder_output(name: pulumi.Input[Optional[str]] = None,
opts: Optional[InvokeOutputOptions] = None) -> Output[GetConfigurationRecorderResult]func LookupConfigurationRecorder(ctx *Context, args *LookupConfigurationRecorderArgs, opts ...InvokeOption) (*LookupConfigurationRecorderResult, error)
func LookupConfigurationRecorderOutput(ctx *Context, args *LookupConfigurationRecorderOutputArgs, opts ...InvokeOption) LookupConfigurationRecorderResultOutput> Note: This function is named LookupConfigurationRecorder in the Go SDK.
public static class GetConfigurationRecorder
{
public static Task<GetConfigurationRecorderResult> InvokeAsync(GetConfigurationRecorderArgs args, InvokeOptions? opts = null)
public static Output<GetConfigurationRecorderResult> Invoke(GetConfigurationRecorderInvokeArgs args, InvokeOptions? opts = null)
public static Output<GetConfigurationRecorderResult> Invoke(GetConfigurationRecorderInvokeArgs args, InvokeOutputOptions opts)
}public static CompletableFuture<GetConfigurationRecorderResult> getConfigurationRecorder(GetConfigurationRecorderArgs args, InvokeOptions options)
public static Output<GetConfigurationRecorderResult> getConfigurationRecorder(GetConfigurationRecorderArgs args, InvokeOptions options)
public static Output<GetConfigurationRecorderResult> getConfigurationRecorder(GetConfigurationRecorderArgs args, InvokeOutputOptions options)
fn::invoke:
function: aws-native:configuration:getConfigurationRecorder
arguments:
# arguments dictionarydata "aws-native_configuration_get_configuration_recorder" "name" {
# arguments
}The following arguments are supported:
- Name string
- The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
- Name string
- The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
- name string
- The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
- name String
- The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
- name string
- The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
- name str
- The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
- name String
- The name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
getConfigurationRecorder Result
The following output properties are available:
- Recording
Group Pulumi.Aws Native. Configuration. Outputs. Configuration Recorder Recording Group - Specifies which resource types are in scope for the configuration recorder to record.
- Recording
Mode Pulumi.Aws Native. Configuration. Outputs. Configuration Recorder Recording Mode - Specifies the default recording frequency for the configuration recorder.
- Resource
Arn string - Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
- Role
Arn string - The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
- Recording
Group ConfigurationRecorder Recording Group - Specifies which resource types are in scope for the configuration recorder to record.
- Recording
Mode ConfigurationRecorder Recording Mode - Specifies the default recording frequency for the configuration recorder.
- Resource
Arn string - Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
- Role
Arn string - The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
- recording_
group object - Specifies which resource types are in scope for the configuration recorder to record.
- recording_
mode object - Specifies the default recording frequency for the configuration recorder.
- resource_
arn string - Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
- role_
arn string - The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
- recording
Group ConfigurationRecorder Recording Group - Specifies which resource types are in scope for the configuration recorder to record.
- recording
Mode ConfigurationRecorder Recording Mode - Specifies the default recording frequency for the configuration recorder.
- resource
Arn String - Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
- role
Arn String - The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
- recording
Group ConfigurationRecorder Recording Group - Specifies which resource types are in scope for the configuration recorder to record.
- recording
Mode ConfigurationRecorder Recording Mode - Specifies the default recording frequency for the configuration recorder.
- resource
Arn string - Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
- role
Arn string - The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
- recording_
group ConfigurationRecorder Recording Group - Specifies which resource types are in scope for the configuration recorder to record.
- recording_
mode ConfigurationRecorder Recording Mode - Specifies the default recording frequency for the configuration recorder.
- resource_
arn str - Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
- role_
arn str - The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
- recording
Group Property Map - Specifies which resource types are in scope for the configuration recorder to record.
- recording
Mode Property Map - Specifies the default recording frequency for the configuration recorder.
- resource
Arn String - Returns the Amazon Resource Name (ARN) for the Configuration Recorder.
- role
Arn String - The Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
Supporting Types
ConfigurationRecorderExclusionByResourceTypes
- Resource
Types List<string> - A comma-separated list of resource types to exclude from recording by the configuration recorder.
- Resource
Types []string - A comma-separated list of resource types to exclude from recording by the configuration recorder.
- resource_
types list(string) - A comma-separated list of resource types to exclude from recording by the configuration recorder.
- resource
Types List<String> - A comma-separated list of resource types to exclude from recording by the configuration recorder.
- resource
Types string[] - A comma-separated list of resource types to exclude from recording by the configuration recorder.
- resource_
types Sequence[str] - A comma-separated list of resource types to exclude from recording by the configuration recorder.
- resource
Types List<String> - A comma-separated list of resource types to exclude from recording by the configuration recorder.
ConfigurationRecorderRecordingGroup
- All
Supported bool - Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
- Exclusion
By Pulumi.Resource Types Aws Native. Configuration. Inputs. Configuration Recorder Exclusion By Resource Types - An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
- Include
Global boolResource Types - This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
- Recording
Strategy Pulumi.Aws Native. Configuration. Inputs. Configuration Recorder Recording Strategy - An object that specifies the recording strategy for the configuration recorder.
- Resource
Types List<string> - A comma-separated list that specifies which resource types AWS Config records.
- All
Supported bool - Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
- Exclusion
By ConfigurationResource Types Recorder Exclusion By Resource Types - An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
- Include
Global boolResource Types - This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
- Recording
Strategy ConfigurationRecorder Recording Strategy - An object that specifies the recording strategy for the configuration recorder.
- Resource
Types []string - A comma-separated list that specifies which resource types AWS Config records.
- all_
supported bool - Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
- exclusion_
by_ objectresource_ types - An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
- include_
global_ boolresource_ types - This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
- recording_
strategy object - An object that specifies the recording strategy for the configuration recorder.
- resource_
types list(string) - A comma-separated list that specifies which resource types AWS Config records.
- all
Supported Boolean - Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
- exclusion
By ConfigurationResource Types Recorder Exclusion By Resource Types - An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
- include
Global BooleanResource Types - This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
- recording
Strategy ConfigurationRecorder Recording Strategy - An object that specifies the recording strategy for the configuration recorder.
- resource
Types List<String> - A comma-separated list that specifies which resource types AWS Config records.
- all
Supported boolean - Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
- exclusion
By ConfigurationResource Types Recorder Exclusion By Resource Types - An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
- include
Global booleanResource Types - This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
- recording
Strategy ConfigurationRecorder Recording Strategy - An object that specifies the recording strategy for the configuration recorder.
- resource
Types string[] - A comma-separated list that specifies which resource types AWS Config records.
- all_
supported bool - Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
- exclusion_
by_ Configurationresource_ types Recorder Exclusion By Resource Types - An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
- include_
global_ boolresource_ types - This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
- recording_
strategy ConfigurationRecorder Recording Strategy - An object that specifies the recording strategy for the configuration recorder.
- resource_
types Sequence[str] - A comma-separated list that specifies which resource types AWS Config records.
- all
Supported Boolean - Specifies whether AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types.
- exclusion
By Property MapResource Types - An object that specifies how AWS Config excludes resource types from being recorded by the configuration recorder.
- include
Global BooleanResource Types - This option is a bundle which only applies to the global IAM resource types: IAM users, groups, roles, and customer managed policies.
- recording
Strategy Property Map - An object that specifies the recording strategy for the configuration recorder.
- resource
Types List<String> - A comma-separated list that specifies which resource types AWS Config records.
ConfigurationRecorderRecordingMode
- Recording
Frequency string - The default recording frequency that AWS Config uses to record configuration changes.
- Recording
Mode List<Pulumi.Overrides Aws Native. Configuration. Inputs. Configuration Recorder Recording Mode Override> - An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
- Recording
Frequency string - The default recording frequency that AWS Config uses to record configuration changes.
- Recording
Mode []ConfigurationOverrides Recorder Recording Mode Override - An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
- recording_
frequency string - The default recording frequency that AWS Config uses to record configuration changes.
- recording_
mode_ list(object)overrides - An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
- recording
Frequency String - The default recording frequency that AWS Config uses to record configuration changes.
- recording
Mode List<ConfigurationOverrides Recorder Recording Mode Override> - An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
- recording
Frequency string - The default recording frequency that AWS Config uses to record configuration changes.
- recording
Mode ConfigurationOverrides Recorder Recording Mode Override[] - An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
- recording_
frequency str - The default recording frequency that AWS Config uses to record configuration changes.
- recording_
mode_ Sequence[Configurationoverrides Recorder Recording Mode Override] - An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
- recording
Frequency String - The default recording frequency that AWS Config uses to record configuration changes.
- recording
Mode List<Property Map>Overrides - An array of 'RecordingModeOverride' objects for you to specify your overrides for the recording mode.
ConfigurationRecorderRecordingModeOverride
- Recording
Frequency string - The recording frequency that will be applied to all the resource types specified in the override.
- Resource
Types List<string> - A comma-separated list that specifies which resource types AWS Config includes in the override.
- Description string
- A description that you provide for the override.
- Recording
Frequency string - The recording frequency that will be applied to all the resource types specified in the override.
- Resource
Types []string - A comma-separated list that specifies which resource types AWS Config includes in the override.
- Description string
- A description that you provide for the override.
- recording_
frequency string - The recording frequency that will be applied to all the resource types specified in the override.
- resource_
types list(string) - A comma-separated list that specifies which resource types AWS Config includes in the override.
- description string
- A description that you provide for the override.
- recording
Frequency String - The recording frequency that will be applied to all the resource types specified in the override.
- resource
Types List<String> - A comma-separated list that specifies which resource types AWS Config includes in the override.
- description String
- A description that you provide for the override.
- recording
Frequency string - The recording frequency that will be applied to all the resource types specified in the override.
- resource
Types string[] - A comma-separated list that specifies which resource types AWS Config includes in the override.
- description string
- A description that you provide for the override.
- recording_
frequency str - The recording frequency that will be applied to all the resource types specified in the override.
- resource_
types Sequence[str] - A comma-separated list that specifies which resource types AWS Config includes in the override.
- description str
- A description that you provide for the override.
- recording
Frequency String - The recording frequency that will be applied to all the resource types specified in the override.
- resource
Types List<String> - A comma-separated list that specifies which resource types AWS Config includes in the override.
- description String
- A description that you provide for the override.
ConfigurationRecorderRecordingStrategy
- Use
Only string The recording strategy for the configuration recorder.
- If you set this option to
ALL_SUPPORTED_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set theAllSupportedfield of RecordingGroup totrue. When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide . - If you set this option to
INCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for only the resource types that you specify in theResourceTypesfield of RecordingGroup . - If you set this option to
EXCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in theResourceTypesfield of ExclusionByResourceTypes .
Required and optional fields
The
recordingStrategyfield is optional when you set theAllSupportedfield of RecordingGroup totrue.The
recordingStrategyfield is optional when you list resource types in theResourceTypesfield of RecordingGroup .The
recordingStrategyfield is required if you list resource types to exclude from recording in theResourceTypesfield of ExclusionByResourceTypes . > Overriding fieldsIf you choose
EXCLUSION_BY_RESOURCE_TYPESfor the recording strategy, theExclusionByResourceTypesfield will override other properties in the request.For example, even if you set
IncludeGlobalResourceTypesto false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in theResourceTypesfield ofExclusionByResourceTypes. > Global resource types and the exclusion recording strategyBy default, if you choose the
EXCLUSION_BY_RESOURCE_TYPESrecording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.Unless specifically listed as exclusions,
AWS::RDS::GlobalClusterwill be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:
- Asia Pacific (Hyderabad)
- Asia Pacific (Melbourne)
- Canada West (Calgary)
- Europe (Spain)
- Europe (Zurich)
- Israel (Tel Aviv)
- Middle East (UAE)
- If you set this option to
- Use
Only string The recording strategy for the configuration recorder.
- If you set this option to
ALL_SUPPORTED_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set theAllSupportedfield of RecordingGroup totrue. When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide . - If you set this option to
INCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for only the resource types that you specify in theResourceTypesfield of RecordingGroup . - If you set this option to
EXCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in theResourceTypesfield of ExclusionByResourceTypes .
Required and optional fields
The
recordingStrategyfield is optional when you set theAllSupportedfield of RecordingGroup totrue.The
recordingStrategyfield is optional when you list resource types in theResourceTypesfield of RecordingGroup .The
recordingStrategyfield is required if you list resource types to exclude from recording in theResourceTypesfield of ExclusionByResourceTypes . > Overriding fieldsIf you choose
EXCLUSION_BY_RESOURCE_TYPESfor the recording strategy, theExclusionByResourceTypesfield will override other properties in the request.For example, even if you set
IncludeGlobalResourceTypesto false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in theResourceTypesfield ofExclusionByResourceTypes. > Global resource types and the exclusion recording strategyBy default, if you choose the
EXCLUSION_BY_RESOURCE_TYPESrecording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.Unless specifically listed as exclusions,
AWS::RDS::GlobalClusterwill be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:
- Asia Pacific (Hyderabad)
- Asia Pacific (Melbourne)
- Canada West (Calgary)
- Europe (Spain)
- Europe (Zurich)
- Israel (Tel Aviv)
- Middle East (UAE)
- If you set this option to
- use_
only string The recording strategy for the configuration recorder.
- If you set this option to
ALL_SUPPORTED_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set theAllSupportedfield of RecordingGroup totrue. When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide . - If you set this option to
INCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for only the resource types that you specify in theResourceTypesfield of RecordingGroup . - If you set this option to
EXCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in theResourceTypesfield of ExclusionByResourceTypes .
Required and optional fields
The
recordingStrategyfield is optional when you set theAllSupportedfield of RecordingGroup totrue.The
recordingStrategyfield is optional when you list resource types in theResourceTypesfield of RecordingGroup .The
recordingStrategyfield is required if you list resource types to exclude from recording in theResourceTypesfield of ExclusionByResourceTypes . > Overriding fieldsIf you choose
EXCLUSION_BY_RESOURCE_TYPESfor the recording strategy, theExclusionByResourceTypesfield will override other properties in the request.For example, even if you set
IncludeGlobalResourceTypesto false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in theResourceTypesfield ofExclusionByResourceTypes. > Global resource types and the exclusion recording strategyBy default, if you choose the
EXCLUSION_BY_RESOURCE_TYPESrecording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.Unless specifically listed as exclusions,
AWS::RDS::GlobalClusterwill be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:
- Asia Pacific (Hyderabad)
- Asia Pacific (Melbourne)
- Canada West (Calgary)
- Europe (Spain)
- Europe (Zurich)
- Israel (Tel Aviv)
- Middle East (UAE)
- If you set this option to
- use
Only String The recording strategy for the configuration recorder.
- If you set this option to
ALL_SUPPORTED_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set theAllSupportedfield of RecordingGroup totrue. When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide . - If you set this option to
INCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for only the resource types that you specify in theResourceTypesfield of RecordingGroup . - If you set this option to
EXCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in theResourceTypesfield of ExclusionByResourceTypes .
Required and optional fields
The
recordingStrategyfield is optional when you set theAllSupportedfield of RecordingGroup totrue.The
recordingStrategyfield is optional when you list resource types in theResourceTypesfield of RecordingGroup .The
recordingStrategyfield is required if you list resource types to exclude from recording in theResourceTypesfield of ExclusionByResourceTypes . > Overriding fieldsIf you choose
EXCLUSION_BY_RESOURCE_TYPESfor the recording strategy, theExclusionByResourceTypesfield will override other properties in the request.For example, even if you set
IncludeGlobalResourceTypesto false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in theResourceTypesfield ofExclusionByResourceTypes. > Global resource types and the exclusion recording strategyBy default, if you choose the
EXCLUSION_BY_RESOURCE_TYPESrecording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.Unless specifically listed as exclusions,
AWS::RDS::GlobalClusterwill be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:
- Asia Pacific (Hyderabad)
- Asia Pacific (Melbourne)
- Canada West (Calgary)
- Europe (Spain)
- Europe (Zurich)
- Israel (Tel Aviv)
- Middle East (UAE)
- If you set this option to
- use
Only string The recording strategy for the configuration recorder.
- If you set this option to
ALL_SUPPORTED_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set theAllSupportedfield of RecordingGroup totrue. When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide . - If you set this option to
INCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for only the resource types that you specify in theResourceTypesfield of RecordingGroup . - If you set this option to
EXCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in theResourceTypesfield of ExclusionByResourceTypes .
Required and optional fields
The
recordingStrategyfield is optional when you set theAllSupportedfield of RecordingGroup totrue.The
recordingStrategyfield is optional when you list resource types in theResourceTypesfield of RecordingGroup .The
recordingStrategyfield is required if you list resource types to exclude from recording in theResourceTypesfield of ExclusionByResourceTypes . > Overriding fieldsIf you choose
EXCLUSION_BY_RESOURCE_TYPESfor the recording strategy, theExclusionByResourceTypesfield will override other properties in the request.For example, even if you set
IncludeGlobalResourceTypesto false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in theResourceTypesfield ofExclusionByResourceTypes. > Global resource types and the exclusion recording strategyBy default, if you choose the
EXCLUSION_BY_RESOURCE_TYPESrecording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.Unless specifically listed as exclusions,
AWS::RDS::GlobalClusterwill be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:
- Asia Pacific (Hyderabad)
- Asia Pacific (Melbourne)
- Canada West (Calgary)
- Europe (Spain)
- Europe (Zurich)
- Israel (Tel Aviv)
- Middle East (UAE)
- If you set this option to
- use_
only str The recording strategy for the configuration recorder.
- If you set this option to
ALL_SUPPORTED_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set theAllSupportedfield of RecordingGroup totrue. When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide . - If you set this option to
INCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for only the resource types that you specify in theResourceTypesfield of RecordingGroup . - If you set this option to
EXCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in theResourceTypesfield of ExclusionByResourceTypes .
Required and optional fields
The
recordingStrategyfield is optional when you set theAllSupportedfield of RecordingGroup totrue.The
recordingStrategyfield is optional when you list resource types in theResourceTypesfield of RecordingGroup .The
recordingStrategyfield is required if you list resource types to exclude from recording in theResourceTypesfield of ExclusionByResourceTypes . > Overriding fieldsIf you choose
EXCLUSION_BY_RESOURCE_TYPESfor the recording strategy, theExclusionByResourceTypesfield will override other properties in the request.For example, even if you set
IncludeGlobalResourceTypesto false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in theResourceTypesfield ofExclusionByResourceTypes. > Global resource types and the exclusion recording strategyBy default, if you choose the
EXCLUSION_BY_RESOURCE_TYPESrecording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.Unless specifically listed as exclusions,
AWS::RDS::GlobalClusterwill be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:
- Asia Pacific (Hyderabad)
- Asia Pacific (Melbourne)
- Canada West (Calgary)
- Europe (Spain)
- Europe (Zurich)
- Israel (Tel Aviv)
- Middle East (UAE)
- If you set this option to
- use
Only String The recording strategy for the configuration recorder.
- If you set this option to
ALL_SUPPORTED_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, excluding the global IAM resource types. You also must set theAllSupportedfield of RecordingGroup totrue. When AWS Config adds support for a new resource type, AWS Config automatically starts recording resources of that type. For a list of supported resource types, see Supported Resource Types in the AWS Config developer guide . - If you set this option to
INCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for only the resource types that you specify in theResourceTypesfield of RecordingGroup . - If you set this option to
EXCLUSION_BY_RESOURCE_TYPES, AWS Config records configuration changes for all supported resource types, except the resource types that you specify to exclude from being recorded in theResourceTypesfield of ExclusionByResourceTypes .
Required and optional fields
The
recordingStrategyfield is optional when you set theAllSupportedfield of RecordingGroup totrue.The
recordingStrategyfield is optional when you list resource types in theResourceTypesfield of RecordingGroup .The
recordingStrategyfield is required if you list resource types to exclude from recording in theResourceTypesfield of ExclusionByResourceTypes . > Overriding fieldsIf you choose
EXCLUSION_BY_RESOURCE_TYPESfor the recording strategy, theExclusionByResourceTypesfield will override other properties in the request.For example, even if you set
IncludeGlobalResourceTypesto false, global IAM resource types will still be automatically recorded in this option unless those resource types are specifically listed as exclusions in theResourceTypesfield ofExclusionByResourceTypes. > Global resource types and the exclusion recording strategyBy default, if you choose the
EXCLUSION_BY_RESOURCE_TYPESrecording strategy, when AWS Config adds support for a new resource type in the Region where you set up the configuration recorder, including global resource types, AWS Config starts recording resources of that type automatically.Unless specifically listed as exclusions,
AWS::RDS::GlobalClusterwill be recorded automatically in all supported AWS Config Regions were the configuration recorder is enabled.IAM users, groups, roles, and customer managed policies will be recorded in the Region where you set up the configuration recorder if that is a Region where AWS Config was available before February 2022. You cannot be record the global IAM resouce types in Regions supported by AWS Config after February 2022. This list where you cannot record the global IAM resource types includes the following Regions:
- Asia Pacific (Hyderabad)
- Asia Pacific (Melbourne)
- Canada West (Calgary)
- Europe (Spain)
- Europe (Zurich)
- Israel (Tel Aviv)
- Middle East (UAE)
- If you set this option to
Package Details
- Repository
- AWS Native pulumi/pulumi-aws-native
- License
- Apache-2.0
We recommend new projects start with resources from the AWS provider.
published on Monday, Sep 28, 2026 by Pulumi