Menu
AWS CloudFormation
User Guide (API Version 2010-05-15)

AWS Config ConfigRule Scope

Scope is a property of the AWS::Config::ConfigRule resource that specifies which AWS resources will trigger AWS Config to run an evaluation when their configurations change. The scope can include one or more resource types, a tag key and value, or one resource type and one resource ID. You cannot specify a tag-key value and a resource ID or type.

Syntax

JSON

Copy
{ "ComplianceResourceId" : String, "ComplianceResourceTypes" : [ String, ... ], "TagKey" : String, "TagValue" : String }

YAML

Copy
ComplianceResourceId: String ComplianceResourceTypes: - String TagKey: String TagValue: String

Properties

ComplianceResourceId

The ID of an AWS resource that you want AWS Config to evaluate against a rule. If you specify an ID, you must also specify a resource type for the ComplianceResourceTypes property.

Required: No

Type: String

ComplianceResourceTypes

The types of AWS resources that you want AWS Config to evaluate against the rule. If you specify the ComplianceResourceId property, specify only one resource type.

Required: Conditional. If you specify a value for the ComplianceResourceId property, you must also specify this property.

Type: List of strings

TagKey

The tag key that is applied to the AWS resources that you want AWS Config to evaluate against the rule.

Required: Conditional. If you specify a tag value, you must specify this property.

Type: String

TagValue

The tag value that is applied to the AWS resources that you want AWS Config to evaluate against the rule.

Required: Conditional. If you specify a tag key, you must specify this property.

Type: String

On this page: