View a markdown version of this page

Supported Resource Types for AWS Config - AWS Config
Amazon AppStreamAmazon AppFlowAmazon AppIntegrationsAmazon API GatewayAmazon AthenaAmazon BedrockAmazon CloudFrontAmazon CloudWatchAmazon CodeGuruAmazon CognitoAmazon ComprehendConnect CustomerAmazon DetectiveAmazon DynamoDBAmazon EC2Amazon ECRAmazon ECSAmazon EFSAmazon EKSAmazon EMRAmazon EMR ServerlessAmazon EventBridgeAmazon ForecastAmazon Fraud DetectorAmazon GameLiftAmazon GuardDutyAmazon InspectorAmazon IVSAmazon KeyspacesAmazon Location ServiceAmazon OpenSearch ServiceAmazon OpenSearch IngestionAmazon PersonalizeAmazon PinpointAmazon QLDBAmazon KendraAmazon KinesisAmazon LexAmazon LightsailAmazon Lookout for MetricsAmazon Lookout for VisionAmazon MacieAmazon Managed GrafanaAmazon Managed Service for PrometheusAmazon MemoryDBAmazon MQAmazon MSKAmazon LexAmazon QuickAmazon RedshiftAmazon RDSAmazon Route 53Amazon SageMaker AIAmazon SESAmazon SNSAmazon SQSAmazon S3Amazon S3 VectorsAmazon Verified PermissionsAmazon WorkSpacesAWS AmplifyAWS AppConfigAWS App RunnerAWS App MeshAWS AppSyncAWS Audit ManagerAWS Auto ScalingAWS B2B Data InterchangeAWS BackupAWS BatchAWS Billing and Cost ManagementAWS BudgetsAWS Certificate ManagerAWS Clean RoomsAWS CloudFormationAWS CloudTrailAWS Cloud9AWS Cloud MapAWS CodeArtifactAWS CodeBuildAWS CodeDeployAWS CodePipelineAWS ConfigAWS Cost ExplorerAWS DMSAWS DataSyncAmazon Aurora DSQLAWS Deadline CloudAWS Device FarmAWS Elastic BeanstalkAWS Entity ResolutionAWS FISAWS Global AcceleratorAWS GlueAWS Glue DataBrewAWS Ground StationAWS HealthLakeAWS IAMAWS IoTAWS KMSAWS LambdaAWS Mainframe ModernizationAWS Network FirewallAWS Network ManagerAWS OrganizationsAWS HealthOmicsAWS PanoramaAWS Private CAAWS Resilience HubAWS Resource ExplorerAWS Resource GroupsAWS Resource Access ManagerAWS RoboMakerAWS SignerAWS Secrets ManagerAWS Security Hub CSPMAWS Service CatalogAWS ShieldAWS Step FunctionsAmazon EventBridge SchedulerAWS Systems ManagerAWS Transfer FamilyAWS WAFAWS X-RayElastic Load BalancingMediaConnectMediaLiveMediaPackageMediaPackageMediaTailor

Supported Resource Types for AWS Config

Important

This page is updated on a monthly cadence at the beginning of each month.

AWS Config supports the following AWS resources types and resource relationships.

  • For more detailed information about a resource type, see its reference information (such as syntax, properties and return values) in the AWS resource and property types reference in the AWS CloudFormation User Guide.

  • For AWS Config recording, some AWS Regions support a subset of these resource types. For information on which resource types are supported in which Regions, see Resource Coverage by Region Availability.

  • Advanced queries for AWS Config supports a subset of these resource types. For a list of those supported resource types, see Supported Resource Types for Advanced Queries.

  • Proactive evaluation for AWS Config supports a subset of these resource types. For a list of those supported resource types, see Supported Resource Types for Proactive Evaluation.

  • Periodic rules run without the configuration recorder being enabled since periodic rules do not depend on configuration items (CIs). For more information on the difference between change–triggered rules and periodic rules, see Evaluation Mode and Trigger Types for AWS Config Rules.

    This means that if you view the rule page, there is no listed CI or supported resource. If you select the resource ID, you will see the following error: The provided resource ID and resource type cannot be found. This is expected behavior.

Note

Region availability for resource types

Before specifying a resource type for AWS Config to track, check Resource Coverage by Region Availability to see if the resource type is supported in the AWS Region where you set up AWS Config. If a resource type is supported by AWS Config in at least one Region, you can enable the recording of that resource type in all Regions supported by AWS Config, even if the specified resource type is not supported in the AWS Region where you set up AWS Config.

Tagging support for resource types

If a resource type does not support tagging or does not include tag information in its describe API response, AWS Config won't capture tag data in the configuration items (CIs) for that resource type. AWS Config will still record these resources. However, any functionality that relies on tag data won't work. This affects tag-based filtering, grouping, or compliance evaluation that relies on tag data.

Amazon AppStream

AWS Service Resource Type Value Relationship Related Resource Notes
Amazon AppStream AWS::AppStream::Application NA NA
AWS::AppStream::AppBlockBuilder NA NA
AWS::AppStream::DirectoryConfig NA NA
AWS::AppStream::Fleet NA NA
AWS::AppStream::Stack NA NA

Amazon AppFlow

AWS Service Resource Type Value Relationship Related Resource Notes
Amazon AppFlow AWS::AppFlow::Flow NA NA

Amazon AppIntegrations

AWS Service Resource Type Value Relationship Related Resource Notes
Amazon AppIntegrations AWS::AppIntegrations::EventIntegration NA NA
AWS::AppIntegrations::Application NA NA

Amazon API Gateway

AWS Service Resource Type Value Relationship Related Resource Notes
API Gateway AWS::ApiGateway::DomainName NA NA
AWS::ApiGateway::DomainNameV2 NA NA
AWS::ApiGateway::Stage is contained in ApiGateway Rest Api
is associated with WAFRegional WebACL
AWS::ApiGateway::Method NA NA Stage
AWS::ApiGateway::RestApi contains ApiGateway Stage
AWS::ApiGateway::UsagePlan NA NA
API Gateway V2 AWS::ApiGatewayV2::Stage is contained in ApiGatewayV2 Api
AWS::ApiGatewayV2::Api contains ApiGatewayV2 Stage
AWS::ApiGatewayV2::Integration NA NA
AWS::ApiGatewayV2::VpcLink NA NA

To learn more about how AWS Config integrates with Amazon API Gateway, see Monitoring API Gateway API Configuration with AWS Config.

Amazon Athena

AWS Service Resource Type Value Relationship Related Resource Notes
Amazon Athena AWS::Athena::WorkGroup NA NA
AWS::Athena::DataCatalog NA NA
AWS::Athena::PreparedStatement NA NA

Amazon Bedrock

AWS Service Resource Type Value Relationship Related Resource Notes
Amazon Bedrock AWS::Bedrock::ApplicationInferenceProfile NA NA
AWS::Bedrock::DataSource NA NA Recording configuration items for resource deletion events might take up to 120 hours to reflect in AWS Config.
AWS::Bedrock::FlowAlias NA NA
AWS::Bedrock::Guardrail NA NA
AWS::Bedrock::KnowledgeBase NA NA
AWS::Bedrock::Prompt NA NA
AWS::BedrockAgentCore::BrowserCustom NA NA
AWS::BedrockAgentCore::CodeInterpreterCustom NA NA
AWS::BedrockAgentCore::Evaluator NA NA
AWS::BedrockAgentCore::Gateway NA NA
AWS::BedrockAgentCore::GatewayTarget NA NA
AWS::BedrockAgentCore::Memory NA NA Recording configuration items for resource deletion events might take up to 360 hours to reflect in AWS Config.
AWS::BedrockAgentCore::OnlineEvaluationConfig NA NA
AWS::BedrockAgentCore::Runtime NA NA
AWS::BedrockAgentCore::RuntimeEndpoint NA NA
AWS::BedrockAgentCore::WorkloadIdentity NA NA

Amazon CloudFront

AWS Service Resource Type Value Relationship Related Resource Notes
Amazon CloudFront AWS::CloudFront::Distribution is associated with AWS WAF WebACL
ACM Certificate
S3 Bucket
IAM Server Certificate
AWS::CloudFront::KeyValueStore NA NA
AWS::CloudFront::PublicKey NA NA
AWS::CloudFront::StreamingDistribution is associated with AWS WAF WebACL
ACM Certificate
S3 Bucket
IAM Server Certificate
AWS::CloudFront::RealtimeLogConfig NA NA

Amazon CloudWatch

AWS Service Resource Type Value Relationship Related Resource Notes
Amazon CloudWatch AWS::CloudWatch::Alarm NA NA
AWS::CloudWatch::MetricStream NA NA
Amazon CloudWatch Application Signals AWS::ApplicationSignals::ServiceLevelObjective NA NA
Amazon CloudWatch Internet Monitor AWS::InternetMonitor::Monitor NA NA
Amazon CloudWatch Logs AWS::Logs::Destination NA NA
Amazon CloudWatch RUM AWS::RUM::AppMonitor NA NA
Amazon CloudWatch Evidently AWS::Evidently::Project NA NA
AWS::Evidently::Launch NA NA
AWS::Evidently::Segment NA NA

Amazon CodeGuru

AWS Service Resource Type Value Relationship Related Resource Notes
Amazon CodeGuru Reviewer AWS::CodeGuruReviewer::RepositoryAssociation NA NA
Amazon CodeGuru Profiler AWS::CodeGuruProfiler::ProfilingGroup NA NA

Amazon Cognito

AWS Service Resource Type Value Relationship Related Resource Notes
Amazon Cognito AWS::Cognito::IdentityPool NA NA
AWS::Cognito::IdentityPoolRoleAttachment NA NA
AWS::Cognito::LogDeliveryConfiguration NA NA
AWS::Cognito::UserPool NA NA
AWS::Cognito::UserPoolClient NA NA
AWS::Cognito::UserPoolDomain NA NA
AWS::Cognito::UserPoolGroup NA NA
AWS::Cognito::UserPoolIdentityProvider NA NA
AWS::Cognito::UserPoolResourceServer NA NA
AWS::Cognito::UserPoolUICustomizationAttachment NA NA

Amazon Comprehend

AWS Service Resource Type Value Relationship Related Resource Notes
Amazon Comprehend AWS::Comprehend::Flywheel NA NA

Connect Customer

AWS Service Resource Type Value Relationship Related Resource Notes
Connect Customer AWS::Connect::Instance NA NA
AWS::Connect::PhoneNumber NA NA
AWS::Connect::PredefinedAttribute NA NA
AWS::Connect::Prompt NA NA Recording configuration items for resource deletion events might take up to 120 hours to reflect in AWS Config.
AWS::Connect::QuickConnect NA NA
AWS::Connect::RoutingProfile NA NA Recording configuration items for resource deletion events might take up to 120 hours to reflect in AWS Config.
AWS::Connect::Rule NA NA
AWS::Connect::SecurityProfile NA NA
AWS::Connect::TaskTemplate NA NA Recording configuration items for resource deletion events might take up to 120 hours to reflect in AWS Config.
AWS::Connect::User NA NA
Connect Customer Customer Profiles AWS::CustomerProfiles::Domain NA NA
AWS::CustomerProfiles::ObjectType NA NA

Amazon Detective

AWS Service Resource Type Value Relationship Related Resource Notes
Amazon Detective AWS::Detective::Graph NA NA
AWS::Detective::OrganizationAdmin NA NA

Amazon DynamoDB

AWS Service Resource Type Value Relationship Related Resource Notes
Amazon DynamoDB AWS::DynamoDB::Table NA NA

Amazon Elastic Compute Cloud

AWS Service Resource Type Value Relationship Related Resource Notes
Amazon Elastic Compute Cloud AWS::EC2::Host* contains EC2 instance
AWS::EC2::EIP is attached to EC2 instance
Network interface
AWS::EC2::Instance contains EC2 network interface
is associated with EC2 security group
is attached to Amazon EBS volume
EC2 Elastic IP (EIP)
is contained in EC2 Dedicated host
Route table
Subnet
Virtual private cloud (VPC)
AWS::EC2::NetworkInterface is associated with EC2 security group
is attached to EC2 Elastic IP (EIP)
EC2 instance
is contained in Route table
Subnet
Virtual private cloud (VPC)
AWS::EC2::SecurityGroup* is associated with EC2 instance
EC2 network interface
Virtual private cloud (VPC)
AWS::EC2::NatGateway is contained in Virtual private cloud (VPC)
is contained in Subnet
AWS::EC2::EgressOnlyInternetGateway is attached to Virtual private cloud (VPC)
AWS::EC2::EC2Fleet NA NA
AWS::EC2::SpotFleet NA NA
AWS::EC2::SubnetNetworkAclAssociation NA NA
AWS::EC2::PrefixList NA NA
AWS::EC2::FlowLog NA NA
AWS::EC2::TransitGateway NA NA
AWS::EC2::TransitGatewayAttachment NA NA
AWS::EC2::TransitGatewayRouteTable NA NA
AWS::EC2::VPCEncryptionControl NA NA
AWS::EC2::VPCEndpoint is contained in Virtual private cloud (VPC)
is attached to Network interface
is contained in Subnet
is contained in Route table
AWS::EC2::VPCEndpointService is associated with ElasticLoadBalancingV2 LoadBalancer
AWS::EC2::VPCPeeringConnection is associated with Virtual private cloud (VPC)
AWS::EC2::RegisteredHAInstance is associated with EC2 instance
AWS::EC2::SubnetRouteTableAssociation NA NA
AWS::EC2::LaunchTemplate NA NA
AWS::EC2::NetworkInsightsAccessScopeAnalysis NA NA
AWS::EC2::TrafficMirrorTarget NA NA
AWS::EC2::TrafficMirrorSession NA NA
AWS::EC2::DHCPOptions NA NA
AWS::EC2::IPAM NA NA
AWS::EC2::IPAMResourceDiscovery NA NA
AWS::EC2::IPAMResourceDiscoveryAssociation NA NA