Description
When an AWS Config aggregator is limited to selected Regions, its central view excludes configuration and compliance data from other Regions. Aggregators collect data already recorded in source accounts and Regions.
Potential impact
If an active Region is omitted, central reviews may miss configuration changes or compliance problems there.
Remediation
For a view across all Regions, set all_regions = true on the account or organization aggregation source. Verify AWS Config recording in source Regions and the necessary aggregation authorizations.
Examples
The examples replace an explicit Region list with all Regions for the same account. Do not set all_regions together with an explicit regions list.
Before
hcl
resource "aws_config_configuration_aggregator" "example" {
name = "example"
account_aggregation_source {
account_ids = ["123456789012"]
regions = ["us-east-2", "us-east-1", "us-west-1", "us-west-2"]
}
}
After
hcl
resource "aws_config_configuration_aggregator" "example" {
name = "example"
account_aggregation_source {
account_ids = ["123456789012"]
all_regions = true
}
}