Supported Resource Types for AWS Config
Important
This page is updated on a monthly cadence at the beginning of each month.
AWS Config supports the following AWS resources types and resource relationships.
-
For more detailed information about a resource type, see its reference information (such as syntax, properties and return values) in the AWS resource and property types reference in the AWS CloudFormation User Guide.
-
For AWS Config recording, some AWS Regions support a subset of these resource types. For information on which resource types are supported in which Regions, see Resource Coverage by Region Availability.
-
Advanced queries for AWS Config supports a subset of these resource types. For a list of those supported resource types, see Supported Resource Types for Advanced Queries
. -
Proactive evaluation for AWS Config supports a subset of these resource types. For a list of those supported resource types, see Supported Resource Types for Proactive Evaluation.
-
Periodic rules run without the configuration recorder being enabled since periodic rules do not depend on configuration items (CIs). For more information on the difference between change–triggered rules and periodic rules, see Evaluation Mode and Trigger Types for AWS Config Rules.
This means that if you view the rule page, there is no listed CI or supported resource. If you select the resource ID, you will see the following error:
The provided resource ID and resource type cannot be found. This is expected behavior.
Note
Region availability for resource types
Before specifying a resource type for AWS Config to track, check Resource Coverage by Region Availability to see if the resource type is supported in the AWS Region where you set up AWS Config. If a resource type is supported by AWS Config in at least one Region, you can enable the recording of that resource type in all Regions supported by AWS Config, even if the specified resource type is not supported in the AWS Region where you set up AWS Config.
Tagging support for resource types
If a resource type does not support tagging or does not include tag information in its describe API response, AWS Config won't capture tag data in the configuration items (CIs) for that resource type. AWS Config will still record these resources. However, any functionality that relies on tag data won't work. This affects tag-based filtering, grouping, or compliance evaluation that relies on tag data.
Amazon AppStream
| AWS Service | Resource Type Value | Relationship | Related Resource | Notes |
|---|---|---|---|---|
| Amazon AppStream | AWS::AppStream::Application |
NA | NA | |
AWS::AppStream::AppBlockBuilder |
NA | NA | ||
AWS::AppStream::DirectoryConfig |
NA | NA | ||
AWS::AppStream::Fleet |
NA | NA | ||
AWS::AppStream::Stack |
NA | NA |
Amazon AppFlow
| AWS Service | Resource Type Value | Relationship | Related Resource | Notes |
|---|---|---|---|---|
| Amazon AppFlow | AWS::AppFlow::Flow |
NA | NA |
Amazon AppIntegrations
| AWS Service | Resource Type Value | Relationship | Related Resource | Notes |
|---|---|---|---|---|
| Amazon AppIntegrations | AWS::AppIntegrations::EventIntegration |
NA | NA | |
AWS::AppIntegrations::Application |
NA | NA |
Amazon API Gateway
| AWS Service | Resource Type Value | Relationship | Related Resource | Notes |
|---|---|---|---|---|
| API Gateway | AWS::ApiGateway::DomainName |
NA | NA | |
AWS::ApiGateway::DomainNameV2 |
NA | NA | ||
AWS::ApiGateway::Stage |
is contained in | ApiGateway Rest Api | ||
| is associated with | WAFRegional WebACL | |||
AWS::ApiGateway::Method |
NA | NA Stage | ||
AWS::ApiGateway::RestApi |
contains | ApiGateway Stage | ||
AWS::ApiGateway::UsagePlan |
NA | NA | ||
| API Gateway V2 | AWS::ApiGatewayV2::Stage |
is contained in | ApiGatewayV2 Api | |
AWS::ApiGatewayV2::Api |
contains | ApiGatewayV2 Stage | ||
AWS::ApiGatewayV2::Integration |
NA | NA | ||
AWS::ApiGatewayV2::VpcLink |
NA | NA |
To learn more about how AWS Config integrates with Amazon API Gateway, see Monitoring API Gateway API Configuration with AWS Config.
Amazon Athena
| AWS Service | Resource Type Value | Relationship | Related Resource | Notes |
|---|---|---|---|---|
| Amazon Athena | AWS::Athena::WorkGroup |
NA | NA | |
AWS::Athena::DataCatalog |
NA | NA | ||
AWS::Athena::PreparedStatement |
NA | NA |
Amazon Bedrock
| AWS Service | Resource Type Value | Relationship | Related Resource | Notes |
|---|---|---|---|---|
| Amazon Bedrock | AWS::Bedrock::ApplicationInferenceProfile |
NA | NA | |
AWS::Bedrock::DataSource |
NA | NA | Recording configuration items for resource deletion events might take up to 120 hours to reflect in AWS Config. | |
AWS::Bedrock::FlowAlias |
NA | NA | ||
AWS::Bedrock::Guardrail |
NA | NA | ||
AWS::Bedrock::KnowledgeBase |
NA | NA | ||
AWS::Bedrock::Prompt |
NA | NA | ||
AWS::BedrockAgentCore::BrowserCustom |
NA | NA | ||
AWS::BedrockAgentCore::CodeInterpreterCustom |
NA | NA | ||
AWS::BedrockAgentCore::Evaluator |
NA | NA | ||
AWS::BedrockAgentCore::Gateway |
NA | NA | ||
AWS::BedrockAgentCore::GatewayTarget |
NA | NA | ||
AWS::BedrockAgentCore::Memory |
NA | NA | Recording configuration items for resource deletion events might take up to 360 hours to reflect in AWS Config. | |
AWS::BedrockAgentCore::OnlineEvaluationConfig |
NA | NA | ||
AWS::BedrockAgentCore::Runtime |
NA | NA | ||
AWS::BedrockAgentCore::RuntimeEndpoint |
NA | NA | ||
AWS::BedrockAgentCore::WorkloadIdentity |
NA | NA |
Amazon CloudFront
| AWS Service | Resource Type Value | Relationship | Related Resource | Notes |
|---|---|---|---|---|
| Amazon CloudFront | AWS::CloudFront::Distribution |
is associated with | AWS WAF WebACL | |
| ACM Certificate | ||||
| S3 Bucket | ||||
| IAM Server Certificate | ||||
AWS::CloudFront::KeyValueStore |
NA | NA | ||
AWS::CloudFront::PublicKey |
NA | NA | ||
AWS::CloudFront::StreamingDistribution |
is associated with | AWS WAF WebACL | ||
| ACM Certificate | ||||
| S3 Bucket | ||||
| IAM Server Certificate | ||||
AWS::CloudFront::RealtimeLogConfig |
NA | NA |
Amazon CloudWatch
| AWS Service | Resource Type Value | Relationship | Related Resource | Notes |
|---|---|---|---|---|
| Amazon CloudWatch | AWS::CloudWatch::Alarm |
NA | NA | |
AWS::CloudWatch::MetricStream |
NA | NA | ||
| Amazon CloudWatch Application Signals | AWS::ApplicationSignals::ServiceLevelObjective |
NA | NA | |
| Amazon CloudWatch Internet Monitor | AWS::InternetMonitor::Monitor |
NA | NA | |
| Amazon CloudWatch Logs | AWS::Logs::Destination |
NA | NA | |
| Amazon CloudWatch RUM | AWS::RUM::AppMonitor |
NA | NA | |
| Amazon CloudWatch Evidently | AWS::Evidently::Project |
NA | NA | |
AWS::Evidently::Launch |
NA | NA | ||
AWS::Evidently::Segment |
NA | NA |
Amazon CodeGuru
| AWS Service | Resource Type Value | Relationship | Related Resource | Notes |
|---|---|---|---|---|
| Amazon CodeGuru Reviewer | AWS::CodeGuruReviewer::RepositoryAssociation |
NA | NA | |
| Amazon CodeGuru Profiler | AWS::CodeGuruProfiler::ProfilingGroup |
NA | NA |
Amazon Cognito
| AWS Service | Resource Type Value | Relationship | Related Resource | Notes |
|---|---|---|---|---|
| Amazon Cognito | AWS::Cognito::IdentityPool |
NA | NA | |
AWS::Cognito::IdentityPoolRoleAttachment |
NA | NA | ||
AWS::Cognito::LogDeliveryConfiguration |
NA | NA | ||
AWS::Cognito::UserPool |
NA | NA | ||
AWS::Cognito::UserPoolClient |
NA | NA | ||
AWS::Cognito::UserPoolDomain |
NA | NA | ||
AWS::Cognito::UserPoolGroup |
NA | NA | ||
AWS::Cognito::UserPoolIdentityProvider |
NA | NA | ||
AWS::Cognito::UserPoolResourceServer |
NA | NA | ||
AWS::Cognito::UserPoolUICustomizationAttachment |
NA | NA |
Amazon Comprehend
| AWS Service | Resource Type Value | Relationship | Related Resource | Notes |
|---|---|---|---|---|
| Amazon Comprehend | AWS::Comprehend::Flywheel |
NA | NA |
Connect Customer
| AWS Service | Resource Type Value | Relationship | Related Resource | Notes |
|---|---|---|---|---|
| Connect Customer | AWS::Connect::Instance |
NA | NA | |
AWS::Connect::PhoneNumber |
NA | NA | ||
AWS::Connect::PredefinedAttribute |
NA | NA | ||
AWS::Connect::Prompt |
NA | NA | Recording configuration items for resource deletion events might take up to 120 hours to reflect in AWS Config. | |
AWS::Connect::QuickConnect |
NA | NA | ||
AWS::Connect::RoutingProfile |
NA | NA | Recording configuration items for resource deletion events might take up to 120 hours to reflect in AWS Config. | |
AWS::Connect::Rule |
NA | NA | ||
AWS::Connect::SecurityProfile |
NA | NA | ||
AWS::Connect::TaskTemplate |
NA | NA | Recording configuration items for resource deletion events might take up to 120 hours to reflect in AWS Config. | |
AWS::Connect::User |
NA | NA | ||
| Connect Customer Customer Profiles | AWS::CustomerProfiles::Domain |
NA | NA | |
AWS::CustomerProfiles::ObjectType |
NA | NA |
Amazon Detective
| AWS Service | Resource Type Value | Relationship | Related Resource | Notes |
|---|---|---|---|---|
| Amazon Detective | AWS::Detective::Graph |
NA | NA | |
AWS::Detective::OrganizationAdmin |
NA | NA |
Amazon DynamoDB
| AWS Service | Resource Type Value | Relationship | Related Resource | Notes |
|---|---|---|---|---|
| Amazon DynamoDB | AWS::DynamoDB::Table |
NA | NA |
Amazon Elastic Compute Cloud
| AWS Service | Resource Type Value | Relationship | Related Resource | Notes |
|---|---|---|---|---|
| Amazon Elastic Compute Cloud | AWS::EC2::Host* |
contains | EC2 instance | |
AWS::EC2::EIP |
is attached to | EC2 instance | ||
| Network interface | ||||
AWS::EC2::Instance |
contains | EC2 network interface | ||
| is associated with | EC2 security group | |||
| is attached to | Amazon EBS volume | |||
| EC2 Elastic IP (EIP) | ||||
| is contained in | EC2 Dedicated host | |||
| Route table | ||||
| Subnet | ||||
| Virtual private cloud (VPC) | ||||
AWS::EC2::NetworkInterface |
is associated with | EC2 security group | ||
| is attached to | EC2 Elastic IP (EIP) | |||
| EC2 instance | ||||
| is contained in | Route table | |||
| Subnet | ||||
| Virtual private cloud (VPC) | ||||
AWS::EC2::SecurityGroup* |
is associated with | EC2 instance | ||
| EC2 network interface | ||||
| Virtual private cloud (VPC) | ||||
AWS::EC2::NatGateway |
is contained in | Virtual private cloud (VPC) | ||
| is contained in | Subnet | |||
AWS::EC2::EgressOnlyInternetGateway |
is attached to | Virtual private cloud (VPC) | ||
AWS::EC2::EC2Fleet
|
NA | NA | ||
AWS::EC2::SpotFleet
|
NA | NA | ||
AWS::EC2::SubnetNetworkAclAssociation
|
NA | NA | ||
AWS::EC2::PrefixList
|
NA | NA | ||
AWS::EC2::FlowLog |
NA | NA | ||
AWS::EC2::TransitGateway |
NA | NA | ||
AWS::EC2::TransitGatewayAttachment |
NA | NA | ||
AWS::EC2::TransitGatewayRouteTable |
NA | NA | ||
AWS::EC2::VPCEncryptionControl |
NA | NA | ||
AWS::EC2::VPCEndpoint |
is contained in | Virtual private cloud (VPC) | ||
| is attached to | Network interface | |||
| is contained in | Subnet | |||
| is contained in | Route table | |||
AWS::EC2::VPCEndpointService |
is associated with | ElasticLoadBalancingV2 LoadBalancer | ||
AWS::EC2::VPCPeeringConnection |
is associated with | Virtual private cloud (VPC) | ||
AWS::EC2::RegisteredHAInstance |
is associated with | EC2 instance | ||
AWS::EC2::SubnetRouteTableAssociation |
NA | NA | ||
AWS::EC2::LaunchTemplate |
NA | NA | ||
AWS::EC2::NetworkInsightsAccessScopeAnalysis |
NA | NA | ||
AWS::EC2::TrafficMirrorTarget |
NA | NA | ||
AWS::EC2::TrafficMirrorSession |
NA | NA | ||
AWS::EC2::DHCPOptions |
NA | NA | ||
AWS::EC2::IPAM |
NA | NA | ||
AWS::EC2::IPAMResourceDiscovery |
NA | NA | ||
AWS::EC2::IPAMResourceDiscoveryAssociation |
NA | NA |