- Newest
- Most votes
- Most comments
Hello,
Firstly, from the standpoint view of AWS services, one can leverage CloudFormation [1] stack templates to deploy resources to automate the integration testing in comparison to a manual creation of dummy resources for testing Config rule compliance.
With CloudFormation, you can write your own templates which can then help you to spin up the resources in the test account.
Secondly, moving on to the scenario for a multi-account architecture, AWS CloudFormation StackSets extends the capability of stacks by enabling you to create, update, or delete stacks across multiple accounts and AWS Regions with a single operation.
Please feel free to refer to our AWS Documentation on the same here [2] for more details.
Finally, in regards to the collection/exporting of results, one can leverage any of the below methods -
-
If you want the information related to the current Configuration Items, you can use the "Advanced Query" option on the AWS Config dashboard and you can then download that information in CSV format [3].
-
In addition to Advanced Query, we can also use the API - GetResourceConfigHistory [4]
For example -
$ aws configservice get-resource-config-history --resource-type AWS::Config::ResourceCompliance --resource-id <resource_id>
- Basically, this command will returns a list of ConfigurationItems for the specified resource.
- You can also leverage the usage of Config snapshot, however, in such a case use of Amazon Athena would be recommended to query the data as a Config snapshot collects CIs of all supported resources that exist in an account.
I would highly recommend checking our AWS Blogpost [5] which provides detailed information on the difference between configuration history and configuration snapshot files in AWS Config.
I hope the above shared information is able to shed light on some of the options available for your use case. Please feel free to reach out if you have any questions.
References:
[1] https://aws.amazon.com/cloudformation/
[2] https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/what-is-cfnstacksets.html
[3] https://docs.aws.amazon.com/config/latest/developerguide/querying-AWS-resources.html
[4] https://docs.aws.amazon.com/config/latest/APIReference/API_GetResourceConfigHistory.html
Relevant content
- asked 2 years ago
- AWS OFFICIALUpdated 9 months ago
- AWS OFFICIALUpdated 3 years ago
- AWS OFFICIALUpdated 5 months ago
- AWS OFFICIALUpdated 3 years ago