Amazon AWS Config
This connector allows Turbine to connect with AWS Config.
Prerequisites
This connector authenticates with AWS Config using the following input values:
Requirements
- AWS Access Key ID: A long-term AWS access key ID with access to IAM.
- AWS Access Secret Key: A long-term secret access key associated with the above AccessKey ID.
Capabilities
This connector provides the following capabilities:
- Get Compliance by Resource
- Get Compliance Summary By Resource Type
- Get Resources Compliance Details by Resource Type
- Get Rules
- List Resources
Task Setup
- The following tasks inputs there are different ways to pass parameters
- Get Compliance Summary By Resource Type
- you can provide either a ResourceEvaluationID or a ResourceID and ResourceType.
Notes
For more information on AWS Config:
Configurations
AWS Config Asset
Authenticates using AWS credentials.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
access_key | A specific long-term AWS access key ID. | string | Required |
secret_key | A specific long-term AWS secret access key. | string | Required |
region_name | The AWS Region where you want to create new connections. | string | Required |
role_arn | Role ARN | string | Optional |
session_token | Use if a session token is provided when switching roles. | string | Optional |
external_id | External ID to assume IAM Role. Optional value used for assuming roles. Can be added, or removed in Trusted Relationships of target role. | string | Optional |
role_session_name | Defaults to SessionFromSwimlane_<HASH> when no value is provided. | string | Optional |
Actions
Get Compliance by Resource
Describe AWS Config compliance by resource
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
ResourceType | string | Required | The types of Amazon Web Services resources for which you want compliance information. |
ResourceId | string | Required | The ID of the Amazon Web Services resource for which you want compliance information. You can specify only one resource ID. If you specify a resource ID, you must also specify a type for ResourceType. |
ComplianceTypes | array | Optional | Filters the results by compliance. |
Limit | number | Optional | The maximum number of evaluation results returned on each page. The default is 10. |
NextToken | string | Optional | The nextToken string returned on a previous page that you use to get the next page of results in a paginated response. |
Input Example
{"ResourceType":"AWS::EC2::Instance","ResourceId":"apphub-bundles-artifacts","ComplianceTypes":["COMPLIANT"],"Limit":123,"NextToken":"string1"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
ComplianceByResources | array | Output field: ComplianceByResources |
ComplianceByResources.ResourceType | string | Type of the resource |
ComplianceByResources.ResourceId | string | Unique identifier |
ComplianceByResources.Compliance | object | Output field: ComplianceByResources.Compliance |
ComplianceByResources.Compliance.ComplianceType | string | Type of the resource |
ComplianceByResources.Compliance.ComplianceContributorCount | object | Count value |
ComplianceByResources.Compliance.ComplianceContributorCount.CappedCount | number | Count value |
ComplianceByResources.Compliance.ComplianceContributorCount.CapExceeded | boolean | Output field: ComplianceByResources.Compliance.ComplianceContributorCount.CapExceeded |
NextToken | string | Output field: NextToken |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"ComplianceByResources":[{}],"NextToken":"string1"}}
Get Compliance Summary By Resource Type
Retrieve AWS Config compliance summary by resource type
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
ResourceTypes | array | Optional | Specify one or more resource types to get the number of resources that are compliant and the number that are noncompliant for each resource type. |
Input Example
{"ResourceTypes":["AWS::EC2::Instance"]}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
ComplianceSummariesByResourceType | array | Type of the resource |
ComplianceSummariesByResourceType.ResourceType | string | Type of the resource |
ComplianceSummariesByResourceType.ComplianceSummary | object | Type of the resource |
ComplianceSummariesByResourceType.ComplianceSummary.CompliantResourceCount | object | Type of the resource |
ComplianceSummariesByResourceType.ComplianceSummary.CompliantResourceCount.CappedCount | number | Type of the resource |
ComplianceSummariesByResourceType.ComplianceSummary.CompliantResourceCount.CapExceeded | boolean | Type of the resource |
ComplianceSummariesByResourceType.ComplianceSummary.NonCompliantResourceCount | object | Type of the resource |
ComplianceSummariesByResourceType.ComplianceSummary.NonCompliantResourceCount.CappedCount | number | Type of the resource |
ComplianceSummariesByResourceType.ComplianceSummary.NonCompliantResourceCount.CapExceeded | boolean | Type of the resource |
ComplianceSummariesByResourceType.ComplianceSummary.ComplianceSummaryTimestamp | string | Type of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"ComplianceSummariesByResourceType":[{}]}}
Get Resources Compliance Details by Resource Type
Retrieve AWS Config compliance details for resources by resource type.
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
ResourceType | string | Required | The type of AWS resource. |
ResourceId | string | Optional | The ID of the AWS resource. |
ComplianceTypes | array | Optional | Filters the results by compliance. |
NextToken | string | Optional | The nextToken string use to get next page of results in a paginated response. |
ResourceEvaluationId | string | Optional | The unique ID of AWS resource to retrieve evaluation results. |
Input Example
{"ResourceType":"string","ResourceId":"abc12","ComplianceTypes":["COMPLIANT"],"NextToken":"string1","ResourceEvaluationId":"string1"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
EvaluationResults | array | Result of the operation |
EvaluationResults.EvaluationResultIdentifier | object | Unique identifier |
EvaluationResults.EvaluationResultIdentifier.EvaluationResultQualifier | object | Unique identifier |
EvaluationResults.EvaluationResultIdentifier.EvaluationResultQualifier.ConfigRuleName | string | Unique identifier |
EvaluationResults.EvaluationResultIdentifier.EvaluationResultQualifier.ResourceType | string | Unique identifier |
EvaluationResults.EvaluationResultIdentifier.EvaluationResultQualifier.ResourceId | string | Unique identifier |
EvaluationResults.EvaluationResultIdentifier.EvaluationResultQualifier.EvaluationMode | string | Unique identifier |
EvaluationResults.EvaluationResultIdentifier.OrderingTimestamp | string | Unique identifier |
EvaluationResults.EvaluationResultIdentifier.ResourceEvaluationId | string | Unique identifier |
EvaluationResults.ComplianceType | string | Type of the resource |
EvaluationResults.ResultRecordedTime | string | Result of the operation |
EvaluationResults.ConfigRuleInvokedTime | string | Result of the operation |
EvaluationResults.Annotation | string | Result of the operation |
EvaluationResults.ResultToken | string | Result of the operation |
NextToken | string | Output field: NextToken |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"EvaluationResults":[{}],"NextToken":"string"}}
Get Rules
Retrieve a list of AWS Config rules
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
ConfigRuleNames | array | Optional | The names of the Config rules for which you want details. If you do not specify any names, Config returns details for all your rules. |
NextToken | string | Optional | The nextToken string returned on a previous page that you use to get the next page of results in a paginated response. |
Filters | object | Optional | Returns a list of Detective or Proactive Config rules. By default, this API returns an unfiltered list. |
Filters.EvaluationMode | string | Optional | The mode of an evaluation. The valid values are Detective or Proactive. |
Input Example
{"ConfigRuleNames":["abcdefghij"],"NextToken":"xyzng","Filters":{"EvaluationMode":"DETECTIVE"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
ConfigRules | array | Output field: ConfigRules |
ConfigRules.ConfigRuleName | string | Name of the resource |
ConfigRules.ConfigRuleArn | string | Output field: ConfigRules.ConfigRuleArn |
ConfigRules.ConfigRuleId | string | Unique identifier |
ConfigRules.Description | string | Output field: ConfigRules.Description |
ConfigRules.Scope | object | Output field: ConfigRules.Scope |
ConfigRules.Scope.ComplianceResourceTypes | array | Type of the resource |
ConfigRules.Scope.TagKey | string | Output field: ConfigRules.Scope.TagKey |
ConfigRules.Scope.TagValue | string | Value for the parameter |
ConfigRules.Scope.ComplianceResourceId | string | Unique identifier |
ConfigRules.Source | object | Output field: ConfigRules.Source |
ConfigRules.Source.Owner | string | Output field: ConfigRules.Source.Owner |
ConfigRules.Source.SourceIdentifier | string | Unique identifier |
ConfigRules.Source.SourceDetails | array | Output field: ConfigRules.Source.SourceDetails |
ConfigRules.Source.SourceDetails.EventSource | string | Output field: ConfigRules.Source.SourceDetails.EventSource |
ConfigRules.Source.SourceDetails.MessageType | string | Type of the resource |
ConfigRules.Source.SourceDetails.MaximumExecutionFrequency | string | Output field: ConfigRules.Source.SourceDetails.MaximumExecutionFrequency |
ConfigRules.Source.CustomPolicyDetails | object | Output field: ConfigRules.Source.CustomPolicyDetails |
ConfigRules.Source.CustomPolicyDetails.PolicyRuntime | string | Time value |
ConfigRules.Source.CustomPolicyDetails.PolicyText | string | Output field: ConfigRules.Source.CustomPolicyDetails.PolicyText |
ConfigRules.Source.CustomPolicyDetails.EnableDebugLogDelivery | boolean | Output field: ConfigRules.Source.CustomPolicyDetails.EnableDebugLogDelivery |
ConfigRules.InputParameters | string | Parameters for the Get Rules action |
ConfigRules.MaximumExecutionFrequency | string | Output field: ConfigRules.MaximumExecutionFrequency |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"ConfigRules":[{}],"NextToken":"axyz"}}
List Resources
Retrieve AWS Config discovered resources
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
resourceType | string | Required | The type of resources that you want Config to list in the response. |
resourceIds | array | Optional | The IDs of only those resources that you want Config to list in the response. |
resourceName | string | Optional | The custom name of only those resources that you want Config to list in the response. |
limit | number | Optional | The maximum number of resource identifiers returned on each page. |
includeDeletedResources | boolean | Optional | Specifies whether Config includes deleted resources in the results. By default, deleted resources are not included. |
nextToken | string | Optional | The nextToken string returned on a previous page that you use to get the next page of results in a paginated response. |
Input Example
{"resourceType":"AWS::EC2::CustomerGateway","resourceIds":["string"],"resourceName":"string","limit":123,"includeDeletedResources":true,"nextToken":"string"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
resourceIdentifiers | array | Unique identifier |
resourceIdentifiers.resourceType | string | Unique identifier |
resourceIdentifiers.resourceId | string | Unique identifier |
resourceIdentifiers.resourceName | string | Unique identifier |
resourceIdentifiers.resourceDeletionTime | string | Unique identifier |
nextToken | string | Output field: nextToken |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"resourceIdentifiers":[{}],"nextToken":"abc123"}}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |