Review AWS Config aggregation Region coverage

Aggregate Config data from the required accounts and Regions.

Description

An AWS Config aggregation limited to selected Regions omits configuration and compliance data from other Regions. The all-Regions option includes supported current and future Regions in the aggregation scope.

Potential impact

Resource states may be overlooked when the required review scope is broader than the aggregation scope.

Remediation

Set AllAwsRegions to true on the selected account or organization source when all-Region aggregation is required. Enable Config recording and the required aggregation permissions in the source accounts and Regions.

Examples

The examples invoke the AWS CLI from Ansible for account-based aggregation. Prepare the CLI and AWS authentication, and replace account IDs with actual 12-digit values. Retain the full required account list when updating an existing aggregator.

Before

yaml
- name: Create Config aggregator
  ansible.builtin.command:
    argv:
      - aws
      - configservice
      - put-configuration-aggregator
      - --configuration-aggregator-name
      - test_config_rule
      - --account-aggregation-sources
      - >-
        [{"AccountIds":["123456789012","012345678901","901234567890"],"AllAwsRegions":false,"AwsRegions":["us-east-1"]}]

After

yaml
- name: Create Config aggregator
  ansible.builtin.command:
    argv:
      - aws
      - configservice
      - put-configuration-aggregator
      - --configuration-aggregator-name
      - test_config_rule
      - --account-aggregation-sources
      - >-
        [{"AccountIds":["123456789012","012345678901","901234567890"],"AllAwsRegions":true}]

References