Control: AWS > RDS > DB Cluster Snapshot [Manual] > Allowed > Region
Take an action when an AWS RDS db cluster snapshot [manual] is created in a region that is not allowed.
The Allowed > Region control checks if the db cluster snapshot [manual] is created in an allowed region based on the Allowed > Region > * policies. If the db cluster snapshot [manual] is created in a region that is not in the allowed list, this control raises an alarm and takes the defined enforcement action.
For any enforcement actions that specify if new, e.g., Enforce: Delete if region not allowed and db cluster snapshot [manual] is new, this control will only take the enforcement actions for resources created within the last 60 minutes.
Resource Types
This control targets the following resource types:
Policies
The following policies can be used to configure this control:
This control type relies on these other policies when running actions:
Permissions
Cloud permissions used by this control and its actions:
rds:DeleteDBClusterSnapshot
Category
In Your Workspace
Developers
- tmod:@turbot/aws-rds#/control/types/dbClusterSnapshotManualAllowedRegion
- tmod:@turbot/turbot#/control/categories/resourceAllowed
- turbot graphql controls --filter "controlTypeId:tmod:@turbot/aws-rds#/control/types/dbClusterSnapshotManualAllowedRegion"
Get Controls