Policy: AWS > EC2 > Snapshot > CMDB > Excluded Services
A list of AWS services whose snapshots should be excluded from the Guardrails CMDB.
When a service is selected, the Snapshot > Discovery control stops recording snapshots created by that service, and the Snapshot > CMDB control removes any such snapshots already tracked in the CMDB. All other snapshots - including user-created, third-party, and non-excluded service snapshots - continue to be tracked.
Excluded snapshots are identified by the service-managed tag that each service applies to every snapshot it creates: - AWS Backup - aws:backup:source-resource - AWS Elastic Disaster Recovery - AWSElasticDisasterRecoveryManaged - AWS Application Migration Service - AWSApplicationMigrationServiceManaged
This policy only applies when AWS > EC2 > Snapshot > CMDB is in an enabled state. It composes with the legacy Enforce: Enabled for Snapshots not created with AWS Backup CMDB option (the effective exclusion set is the union of both).
Targets
This policy targets the following resource types:
Primary Policy
This policy is used with the following primary policy:
Controls
Setting this policy configures these controls:
Policy Specification
Schema Type | |
|---|---|
Default | |
Category
In Your Workspace
Developers
- tmod:@turbot/turbot#/control/categories/cmdb
- tmod:@turbot/aws-ec2#/policy/types/snapshotCmdbExcludedServices
- turbot graphql policy-type --id "tmod:@turbot/aws-ec2#/policy/types/snapshotCmdbExcludedServices"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/aws-ec2#/policy/types/snapshotCmdbExcludedServices"
Get Policy TypeGet Policy Settings