Policy: AWS > Config > Configuration Recording > Configuration Recorder > Role
The ARN of the IAM role that AWS Config will assume. The default will use the role created in AWS > Guardrails > Service Roles > AWS Config
. If you choose to use a different role, note that it: - must allow the config service to assume the role in its trust policy - requires PutObject, GetBucketAcl on the bucket - requires publish on the SNS topic - Needs describe/get/list access to any resources types being recorded
Resource Types
This policy targets the following resource types:
Primary Policy
This policy is used with the following primary policy:
Controls
Policy Specification
Schema Type |
|
---|---|
Default template |
|
Default template input |
|
Examples [YAML] | arn:aws:iam::123456789012:role/config-ConfigRole-A1B2C3D4E5F6 |
Category
In Your Workspace
Developers
- tmod:@turbot/turbot#/control/categories/configured
- tmod:@turbot/aws-config#/policy/types/configurationRecorderRole
- turbot graphql policy-type --id "tmod:@turbot/aws-config#/policy/types/configurationRecorderRole"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/aws-config#/policy/types/configurationRecorderRole"
Get Policy TypeGet Policy Settings
Category URI
Policy Type URI
GraphQL
CLI