Description
An AWS Config aggregation limited to selected Regions omits configuration and compliance data from other Regions. The all-Regions option includes supported current and future Regions in the aggregation scope.
Potential impact
Resource states may be overlooked when the required review scope is broader than the aggregation scope.
Remediation
Set AllAwsRegions to true on the selected account or organization source when all-Region aggregation is required. Enable Config recording and the required aggregation permissions in the source accounts and Regions.
Examples
The examples invoke the AWS CLI from Ansible for account-based aggregation. Prepare the CLI and AWS authentication, and replace account IDs with actual 12-digit values. Retain the full required account list when updating an existing aggregator.
Before
- name: Create Config aggregator
ansible.builtin.command:
argv:
- aws
- configservice
- put-configuration-aggregator
- --configuration-aggregator-name
- test_config_rule
- --account-aggregation-sources
- >-
[{"AccountIds":["123456789012","012345678901","901234567890"],"AllAwsRegions":false,"AwsRegions":["us-east-1"]}]
After
- name: Create Config aggregator
ansible.builtin.command:
argv:
- aws
- configservice
- put-configuration-aggregator
- --configuration-aggregator-name
- test_config_rule
- --account-aggregation-sources
- >-
[{"AccountIds":["123456789012","012345678901","901234567890"],"AllAwsRegions":true}]