Updated on 2024-03-18 GMT+08:00

Predefined Policy List

You can use predefined policies to create rules on the Config console.

The following table lists predefined policies provided by Config.

Table 1 Predefined policies

Service

Policy

Triggered By

Object

General services

regular-matching-of-names

Configuration change

All resources

required-tag-check

Configuration change

All resources

resource-in-enterprise-project

Configuration change

All resources

resources-in-supported-region

Configuration change

All resources

API Gateway (APIG)

apig-instances-authorization-type-configured

Configuration change

apig.instances

apig-instances-execution-logging-enabled

Configuration change

apig.instances

apig-instances-ssl-enabled

Configuration change

apig.instances

CodeArts Deploy

codeartsdeploy-host-cluster-resource-status

Configuration change

codeartsdeploy.host-cluster

MapReduce Service (MRS)

mrs-cluster-in-allowed-security-groups

Configuration change

mrs.mrs

mrs-cluster-in-vpc

Configuration change

mrs.mrs

mrs-cluster-kerberos-enabled

Configuration change

mrs.mrs

mrs-cluster-multiAZ-deployment

Configuration change

mrs.mrs

mrs-cluster-no-public-ip

Configuration change

mrs.mrs

NAT Gateway

private-nat-gateway-authorized-vpc-only

Configuration change

nat.privateNatGateways

VPC Endpoint (VPCEP)

vpcep-endpoint-enabled

Periodic

vpcep.endpoints

Web Application Firewall (WAF)

waf-instance-policy-not-empty

Configuration change

waf.instance

ELB

elb-loadbalancers-no-public-ip

Configuration change

elb.loadbalancers

elb-predefined-security-policy-https-check

Configuration change

elb.loadbalancers

elb-tls-https-listeners-only

Configuration change

elb.loadbalancers

elb-members-weight-check

Configuration change

elb.members

Elastic IP (EIP)

eip-bandwidth-limit

Configuration change

vpc.publicips

eip-unbound-check

Configuration change

vpc.publicips

eip-use-in-specified-days

Periodic

vpc.publicips

Auto Scaling (AS)

as-capacity-rebalancing

Configuration change

as.scalingGroups

as-group-elb-healthcheck-required

Configuration change

as.scalingGroups

as-multiple-az

Configuration change

as.scalingGroups

Scalable File Service (SFS)

sfsturbo-encrypted-check

Configuration change

sfsturbo.shares

Elastic Cloud Server (ECS)

allowed-ecs-flavors

Configuration change

ecs.cloudservers

allowed-images-by-id

Configuration change

ecs.cloudservers

approved-ims-by-tag

Configuration change

ecs.cloudservers

ecs-in-allowed-security-groups

Configuration change

ecs.cloudservers

ecs-instance-in-vpc

Configuration change

ecs.cloudservers

ecs-instance-key-pair-login

Configuration change

ecs.cloudservers

ecs-instance-no-public-ip

Configuration change

ecs.cloudservers

ecs-multiple-public-ip-check

Configuration change

ecs.cloudservers

stopped-ecs-date-diff

Periodic

ecs.cloudservers

Distributed Cache Service (DCS)

dcs-memcached-enable-ssl

Configuration change

dcs.memcached

dcs-memcached-in-vpc

Configuration change

dcs.memcached

dcs-memcached-no-public-ip

Configuration change

dcs.memcached

dcs-memcached-password-access

Configuration change

dcs.memcached

dcs-redis-enable-ssl

Configuration change

dcs.redis

dcs-redis-high-tolerance

Configuration change

dcs.redis

dcs-redis-in-vpc

Configuration change

dcs.redis

dcs-redis-no-public-ip

Configuration change

dcs.redis

dcs-redis-password-access

Configuration change

dcs.redis

FunctionGraph

function-graph-concurrency-check

Configuration change

fgs.functions

function-graph-inside-vpc

Configuration change

fgs.functions

function-graph-public-access-prohibited

Configuration change

fgs.functions

function-graph-settings-check

Configuration change

fgs.functions

Content Delivery Network (CDN)

cdn-enable-https-certificate

Configuration change

cdn.domains

cdn-origin-protocol-no-http

Configuration change

cdn.domains

cdn-security-policy-check

Configuration change

cdn.domains

cdn-use-my-certificate

Configuration change

cdn.domains

Config

tracker-config-enabled-check

Periodic

config.trackers

Data Warehouse Service (DWS)

dws-enable-kms

Configuration change

dws.clusters

dws-enable-log-dump

Configuration change

dws.clusters

dws-enable-snapshot

Configuration change

dws.clusters

dws-enable-ssl

Configuration change

dws.clusters

Data Replication Service (DRS)

drs-data-guard-job-not-public

Configuration change

drs.dataGuardJob

drs-migration-job-not-public

Configuration change

drs.migrationJob

drs-synchronization-job-not-public

Configuration change

drs.synchronizationJob

Data Encryption Workshop (DEW)

kms-not-scheduled-for-deletion

Configuration change

kms.keys

kms-rotation-enabled

Configuration change

kms.keys

Identity and Access Management (IAM)

access-keys-rotated

Periodic

iam.users

iam-customer-policy-blocked-kms-actions

Configuration changes

iam.roles&iam.policies

iam-group-has-users-check

Configuration change

iam.groups

iam-password-policy

Configuration change

iam.users

iam-policy-blacklisted-check

Configuration change

iam.users, iam.groups, iam.agencies

iam-policy-no-statements-with-admin-access

Configuration change

iam.roles, iam.policies

iam-role-has-all-permissions

Configuration change

iam.roles, iam.policies

iam-root-access-key-check

Periodic

iam.users

iam-user-access-mode

Configuration change

iam.users

iam-user-console-and-api-access-at-creation

Configuration change

iam.users

iam-user-group-membership-check

Configuration change

iam.users

iam-user-last-login-check

Periodic

iam.users

iam-user-mfa-enabled

Configuration change

iam.users

iam-user-single-access-key

Configuration change

iam.users

mfa-enabled-for-iam-console-access

Configuration change

iam.users

root-account-mfa-enabled

Periodic

iam.users

Document Database Service (DDS)

dds-instance-enable-ssl

Configuration change

dds.instances

dds-instance-hamode

Configuration change

dds.instances

dds-instance-has-eip

Configuration change

dds.instances

dds-instance-in-vpc

Configuration change

dds.instances

Simple Message Notification (SMN)

smn-lts-enable

Configuration change

smn.topic

Virtual Private Cloud (VPC)

vpc-acl-unused-check

Configuration change

vpc.firewallGroups

vpc-default-sg-closed

Configuration change

vpc.securityGroups

vpc-flow-logs-enabled

Configuration change

vpc.vpcs

vpc-sg-ports-check

Configuration change

vpc.securityGroups

vpc-sg-restricted-common-ports

Configuration change

vpc.securityGroups

vpc-sg-restricted-ssh

Configuration change

vpc.securityGroups

Virtual Private Network (VPN)

vpn-connections-active

Configuration change

vpnaas.vpnConnections, vpnaas.ipsec-site-connections

Cloud Eye

alarm-action-enabled-check

Configuration change

ces.alarms

alarm-kms-disable-or-delete-key

Periodic

ces.alarms

alarm-obs-bucket-policy-change

Periodic

ces.alarms

alarm-resource-check

Periodic

ces.alarms

alarm-settings-check

Configuration change

ces.alarms

alarm-vpc-change

Periodic

ces.alarms

Cloud Container Engine (CCE)

cce-cluster-end-of-maintenance-version

Configuration change

cce.clusters

cce-cluster-oldest-supported-version

Configuration change

cce.clusters

cce-endpoint-public-access

Configuration change

cce.clusters

Cloud Trace Service (CTS)

cts-kms-encrypted-check

Configuration change

cts.trackers

cts-lts-enable

Configuration change

cts.trackers

cts-obs-bucket-track

Periodic

cts.trackers

cts-support-validate-check

Configuration change

cts.trackers

cts-tracker-exists

Periodic

cts.trackers

multi-region-cts-tracker-exists

Periodic

cts.trackers

Relational Database Service (RDS)

gaussdb-instance-in-vpc

Configuration change

gaussdb.instance

gaussdb-nosql-deploy-in-single-az

Configuration change

nosql.instances

gaussdb-nosql-enable-backup

Configuration change

nosql.instances

gaussdb-nosql-enable-disk-encryption

Configuration change

nosql.instances

gaussdb-nosql-enable-error-log

Configuration change

nosql.instances

gaussdb-nosql-support-slow-log

Configuration change

nosql.instances

rds-instance-enable-backup

Configuration change

rds.instances

rds-instance-enable-errorLog

Configuration change

rds.instances

rds-instance-enable-slowLog

Configuration change

rds.instances

rds-instance-multi-az-support

Configuration change

rds.instances

rds-instance-no-public-ip

Configuration change

rds.instances

rds-instances-enable-kms

Configuration change

rds.instances

rds-instances-in-vpc

Configuration change

rds.instances

rds-instance-logging-enabled

Configuration change

rds.instances

Cloud Search Service (CSS)

css-cluster-authority-enable

Configuration change

css.clusters

css-cluster-backup-available

Configuration change

css.clusters

css-cluster-disk-encryption-check

Configuration change

css.clusters

css-cluster-https-required

Configuration change

css.clusters

css-cluster-in-vpc

Configuration change

css.clusters

css-cluster-multiple-az-check

Configuration change

css.clusters

css-cluster-multiple-instances-check

Configuration change

css.clusters

css-cluster-no-public-zone

Configuration change

css.clusters

css-cluster-security-mode-enable

Configuration change

css.clusters

css-cluster-not-enable-white-list

Configuration change

css.clusters

css-cluster-kibana-not-enable-white-list

Configuration change

css.clusters

Elastic Volume Service (EVS)

allowed-volume-specs

Configuration changes

evs.volumes

evs-use-in-specified-days

Periodic

evs.volumes

volume-unused-check

Configuration changes

evs.volumes

volumes-encrypted-check

Configuration change

evs.volumes

Cloud Certificate Manager (CCM)

pca-certificate-authority-expiration-check

Periodic

pca.ca

pca-certificate-expiration-check

Periodic

pca.cert

Distributed Message Service (for Kafka)

dms-kafka-not-enable-private-ssl

Configuration change

dms.kafkas

dms-kafka-not-enable-public-ssl

Configuration change

dms.kafkas

dms-kafka-public-access-enabled-check

Configuration change

dms.kafkas

Distributed Message Service for RabbitMQ (for RabbitMQ)

dms-rabbitmq-not-enable-ssl

Configuration change

dms.rabbitmqs

Distributed Message Service for RocketMQ (for RocketMQ)

dms-rocketmq-not-enable-ssl

Configuration change

dms.reliabilitys