Review the Regions included in AWS Config aggregation

Include the Regions that need a central AWS Config view.

Description

When an AWS Config aggregator is limited to selected Regions, its central view excludes configuration and compliance data from other Regions. Aggregators collect data already recorded in source accounts and Regions.

Potential impact

If an active Region is omitted, central reviews may miss configuration changes or compliance problems there.

Remediation

For a view across all Regions, set all_regions = true on the account or organization aggregation source. Verify AWS Config recording in source Regions and the necessary aggregation authorizations.

Examples

The examples replace an explicit Region list with all Regions for the same account. Do not set all_regions together with an explicit regions list.

Before

hcl
resource "aws_config_configuration_aggregator" "example" {
  name = "example"

  account_aggregation_source {
    account_ids = ["123456789012"]
    regions     = ["us-east-2", "us-east-1", "us-west-1", "us-west-2"]
  }
}

After

hcl
resource "aws_config_configuration_aggregator" "example" {
  name = "example"

  account_aggregation_source {
    account_ids = ["123456789012"]
    all_regions = true
  }
}

References