Skip to main content

Aws/config

@swamp/aws/configv2026.10.06.1· 1d agoMODELS
01README

AWS CONFIG infrastructure models

02Models11
@swamp/aws/config/aggregation-authorizationv2026.08.17.2aggregation_authorization.ts

Global Arguments

ArgumentTypeDescription
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
accessKeyId?stringAWS access key ID; overrides AWS_ACCESS_KEY_ID environment variable. Wire with a vault.get(...) expression to source it from a vault.
secretAccessKey?stringAWS secret access key; overrides AWS_SECRET_ACCESS_KEY environment variable. Wire with a vault.get(...) expression to source it from a vault.
sessionToken?stringAWS session token for temporary credentials; overrides AWS_SESSION_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
region?stringAWS region; overrides AWS_REGION / AWS_DEFAULT_REGION environment variables and ~/.aws/config profile region. Defaults to us-east-1.
AuthorizedAccountIdstringThe 12-digit account ID of the account authorized to aggregate data.
AuthorizedAwsRegionstringThe region authorized to collect aggregated data.
Tags?arrayThe tags for the AggregationAuthorization.
fn create()
Create a Config AggregationAuthorization
fn get(identifier: string)
Get a Config AggregationAuthorization
ArgumentTypeDescription
identifierstringThe primary identifier of the Config AggregationAuthorization
fn update()
Update a Config AggregationAuthorization
fn delete(identifier: string)
Delete a Config AggregationAuthorization
ArgumentTypeDescription
identifierstringThe primary identifier of the Config AggregationAuthorization
fn sync()
Sync Config AggregationAuthorization state from AWS
fn list(maxPages?: number, resourceModel?: string)
List Config AggregationAuthorization resources
ArgumentTypeDescription
maxPages?numberMaximum number of pages to fetch (default: 10)
resourceModel?stringJSON resource model for parent-scoped listing (e.g. parent identifier)

Resources

state(infinite)— Config AggregationAuthorization resource state
@swamp/aws/config/config-rulev2026.08.20.1config_rule.ts

Global Arguments

ArgumentTypeDescription
accessKeyId?stringAWS access key ID; overrides AWS_ACCESS_KEY_ID environment variable. Wire with a vault.get(...) expression to source it from a vault.
secretAccessKey?stringAWS secret access key; overrides AWS_SECRET_ACCESS_KEY environment variable. Wire with a vault.get(...) expression to source it from a vault.
sessionToken?stringAWS session token for temporary credentials; overrides AWS_SESSION_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
region?stringAWS region; overrides AWS_REGION / AWS_DEFAULT_REGION environment variables and ~/.aws/config profile region. Defaults to us-east-1.
Description?stringThe description that you provide for the CC rule.
Scope?objectDefines which resources can trigger an evaluation for the rule. The scope can include one or more resource types, a combination of one resource type and one resource ID, or a combination of a tag key and value. Specify a scope to constrain the resources that can trigger an evaluation for the rule. If you do not specify a scope, evaluations are triggered when any resource in the recording group changes.
ConfigRuleName?stringA name for the CC rule. If you don't specify a name, CFN generates a unique physical ID and uses that ID for the rule name. For more information, see [Name Type](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-name.html).
MaximumExecutionFrequency?stringThe maximum frequency with which CC runs evaluations for a rule. You can specify a value for MaximumExecutionFrequency when: You are using an AWS managed rule that is triggered at a periodic frequency. Your custom rule is triggered when CC delivers the configuration snapshot. For more information, see [ConfigSnapshotDeliveryProperties](https://docs.aws.amazon.com/config/latest/APIReference/API_ConfigSnapshotDeliveryProperties.html). By default, rules with a periodic trigger are evaluated every 2
SourceobjectProvides the rule owner (`` for managed rules, CUSTOM_POLICY for Custom Policy rules, and CUSTOM_LAMBDA`` for Custom Lambda rules), the rule identifier, and the notifications that cause the function to evaluate your AWS resources.
InputParameters?recordA string, in JSON format, that is passed to the CC rule Lambda function.
EvaluationModes?arrayThe modes the CC rule can be evaluated in. The valid values are distinct objects. By default, the value is Detective evaluation mode only.
fn create()
Create a Config ConfigRule
fn get(identifier: string)
Get a Config ConfigRule
ArgumentTypeDescription
identifierstringThe primary identifier of the Config ConfigRule
fn update()
Update a Config ConfigRule
fn delete(identifier: string)
Delete a Config ConfigRule
ArgumentTypeDescription
identifierstringThe primary identifier of the Config ConfigRule
fn sync()
Sync Config ConfigRule state from AWS
fn list(maxPages?: number, resourceModel?: string)
List Config ConfigRule resources
ArgumentTypeDescription
maxPages?numberMaximum number of pages to fetch (default: 10)
resourceModel?stringJSON resource model for parent-scoped listing (e.g. parent identifier)

Resources

state(infinite)— Config ConfigRule resource state
@swamp/aws/config/configuration-aggregatorv2026.08.17.2configuration_aggregator.ts

Global Arguments

ArgumentTypeDescription
accessKeyId?stringAWS access key ID; overrides AWS_ACCESS_KEY_ID environment variable. Wire with a vault.get(...) expression to source it from a vault.
secretAccessKey?stringAWS secret access key; overrides AWS_SECRET_ACCESS_KEY environment variable. Wire with a vault.get(...) expression to source it from a vault.
sessionToken?stringAWS session token for temporary credentials; overrides AWS_SESSION_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
region?stringAWS region; overrides AWS_REGION / AWS_DEFAULT_REGION environment variables and ~/.aws/config profile region. Defaults to us-east-1.
AccountAggregationSources?array
ConfigurationAggregatorName?stringThe name of the aggregator.
OrganizationAggregationSource?object
Tags?arrayThe tags for the configuration aggregator.
fn create()
Create a Config ConfigurationAggregator
fn get(identifier: string)
Get a Config ConfigurationAggregator
ArgumentTypeDescription
identifierstringThe primary identifier of the Config ConfigurationAggregator
fn update()
Update a Config ConfigurationAggregator
fn delete(identifier: string)
Delete a Config ConfigurationAggregator
ArgumentTypeDescription
identifierstringThe primary identifier of the Config ConfigurationAggregator
fn sync()
Sync Config ConfigurationAggregator state from AWS
fn list(maxPages?: number, resourceModel?: string)
List Config ConfigurationAggregator resources
ArgumentTypeDescription
maxPages?numberMaximum number of pages to fetch (default: 10)
resourceModel?stringJSON resource model for parent-scoped listing (e.g. parent identifier)

Resources

state(infinite)— Config ConfigurationAggregator resource state
@swamp/aws/config/configuration-recorderv2026.09.25.1configuration_recorder.ts

Global Arguments

ArgumentTypeDescription
accessKeyId?stringAWS access key ID; overrides AWS_ACCESS_KEY_ID environment variable. Wire with a vault.get(...) expression to source it from a vault.
secretAccessKey?stringAWS secret access key; overrides AWS_SECRET_ACCESS_KEY environment variable. Wire with a vault.get(...) expression to source it from a vault.
sessionToken?stringAWS session token for temporary credentials; overrides AWS_SESSION_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
region?stringAWS region; overrides AWS_REGION / AWS_DEFAULT_REGION environment variables and ~/.aws/config profile region. Defaults to us-east-1.
Name?stringThe name of the configuration recorder. By default, AWS Config assigns the name "default" when creating the configuration recorder. To change the configuration recorder name, you must use the DeleteConfigurationRecorder action to delete your current configuration recorder, and then you must use the PutConfigurationRecorder command to create a configuration recorder that has the desired name.
RecordingGroup?objectSpecifies which resource types are in scope for the configuration recorder to record.
RecordingMode?objectSpecifies the default recording frequency for the configuration recorder.
RoleARNstringThe Amazon Resource Name (ARN) of the role that allows AWS Config to read S3 objects.
StartedOnCreate?booleanDefaults to 'true'. Controls whether the recorder starts recording after the create operation. Set this to 'false' for development and testing purposes.
fn create()
Create a Config ConfigurationRecorder
fn get(identifier: string)
Get a Config ConfigurationRecorder
ArgumentTypeDescription
identifierstringThe primary identifier of the Config ConfigurationRecorder
fn update()
Update a Config ConfigurationRecorder
fn delete(identifier: string)
Delete a Config ConfigurationRecorder
ArgumentTypeDescription
identifierstringThe primary identifier of the Config ConfigurationRecorder
fn sync()
Sync Config ConfigurationRecorder state from AWS
fn list(maxPages?: number, resourceModel?: string)
List Config ConfigurationRecorder resources
ArgumentTypeDescription
maxPages?numberMaximum number of pages to fetch (default: 10)
resourceModel?stringJSON resource model for parent-scoped listing (e.g. parent identifier)

Resources

state(infinite)— Config ConfigurationRecorder resource state
@swamp/aws/config/conformance-packv2026.08.17.2conformance_pack.ts

Global Arguments

ArgumentTypeDescription
accessKeyId?stringAWS access key ID; overrides AWS_ACCESS_KEY_ID environment variable. Wire with a vault.get(...) expression to source it from a vault.
secretAccessKey?stringAWS secret access key; overrides AWS_SECRET_ACCESS_KEY environment variable. Wire with a vault.get(...) expression to source it from a vault.
sessionToken?stringAWS session token for temporary credentials; overrides AWS_SESSION_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
region?stringAWS region; overrides AWS_REGION / AWS_DEFAULT_REGION environment variables and ~/.aws/config profile region. Defaults to us-east-1.
ConformancePackNamestringName of the conformance pack which will be assigned as the unique identifier.
DeliveryS3Bucket?stringAWS Config stores intermediate files while processing conformance pack template.
DeliveryS3KeyPrefix?stringThe prefix for delivery S3 bucket.
TemplateBody?stringA string containing full conformance pack template body. You can only specify one of the template body or template S3Uri fields.
TemplateS3Uri?stringLocation of file containing the template body which points to the conformance pack template that is located in an Amazon S3 bucket. You can only specify one of the template body or template S3Uri fields.
TemplateSSMDocumentDetails?objectThe TemplateSSMDocumentDetails object contains the name of the SSM document and the version of the SSM document.
ConformancePackInputParameters?arrayA list of ConformancePackInputParameter objects.
Tags?arrayThe tags for the conformance pack.
fn create()
Create a Config ConformancePack
fn get(identifier: string)
Get a Config ConformancePack
ArgumentTypeDescription
identifierstringThe primary identifier of the Config ConformancePack
fn update()
Update a Config ConformancePack
fn delete(identifier: string)
Delete a Config ConformancePack
ArgumentTypeDescription
identifierstringThe primary identifier of the Config ConformancePack
fn sync()
Sync Config ConformancePack state from AWS
fn list(maxPages?: number, resourceModel?: string)
List Config ConformancePack resources
ArgumentTypeDescription
maxPages?numberMaximum number of pages to fetch (default: 10)
resourceModel?stringJSON resource model for parent-scoped listing (e.g. parent identifier)

Resources

state(infinite)— Config ConformancePack resource state
@swamp/aws/config/connectorv2026.08.17.2connector.ts

Global Arguments

ArgumentTypeDescription
namestringInstance name for this resource (used as the unique identifier in the factory pattern)
accessKeyId?stringAWS access key ID; overrides AWS_ACCESS_KEY_ID environment variable. Wire with a vault.get(...) expression to source it from a vault.
secretAccessKey?stringAWS secret access key; overrides AWS_SECRET_ACCESS_KEY environment variable. Wire with a vault.get(...) expression to source it from a vault.
sessionToken?stringAWS session token for temporary credentials; overrides AWS_SESSION_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
region?stringAWS region; overrides AWS_REGION / AWS_DEFAULT_REGION environment variables and ~/.aws/config profile region. Defaults to us-east-1.
ConnectorConfigurationobjectThe configuration for the connector that specifies the third-party cloud provider connection details.
Tags?arrayThe tags for the connector.
fn create()
Create a Config Connector
fn get(identifier: string)
Get a Config Connector
ArgumentTypeDescription
identifierstringThe primary identifier of the Config Connector
fn update()
Update a Config Connector
fn delete(identifier: string)
Delete a Config Connector
ArgumentTypeDescription
identifierstringThe primary identifier of the Config Connector
fn sync()
Sync Config Connector state from AWS
fn list(maxPages?: number, resourceModel?: string)
List Config Connector resources
ArgumentTypeDescription
maxPages?numberMaximum number of pages to fetch (default: 10)
resourceModel?stringJSON resource model for parent-scoped listing (e.g. parent identifier)

Resources

state(infinite)— Config Connector resource state
@swamp/aws/config/delivery-channelv2026.09.10.1delivery_channel.ts

Global Arguments

ArgumentTypeDescription
accessKeyId?stringAWS access key ID; overrides AWS_ACCESS_KEY_ID environment variable. Wire with a vault.get(...) expression to source it from a vault.
secretAccessKey?stringAWS secret access key; overrides AWS_SECRET_ACCESS_KEY environment variable. Wire with a vault.get(...) expression to source it from a vault.
sessionToken?stringAWS session token for temporary credentials; overrides AWS_SESSION_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
region?stringAWS region; overrides AWS_REGION / AWS_DEFAULT_REGION environment variables and ~/.aws/config profile region. Defaults to us-east-1.
Name?stringThe name of the delivery channel. By default, AWS Config assigns the name "default" when creating the delivery channel. To change the delivery channel name, you must use the DeleteDeliveryChannel action to delete your current delivery channel, and then you must use the PutDeliveryChannel command to create a delivery channel that has the desired name.
S3KeyPrefix?stringThe prefix for the specified Amazon S3 bucket.
ConfigSnapshotDeliveryProperties?objectThe options for how often AWS Config delivers configuration snapshots to the Amazon S3 bucket.
S3BucketNamestringThe name of the Amazon S3 bucket to which AWS Config delivers configuration snapshots and configuration history files.
SnsTopicARN?stringThe Amazon Resource Name (ARN) of the Amazon SNS topic to which AWS Config sends notifications about configuration changes.
S3KmsKeyArn?stringThe Amazon Resource Name (ARN) of the AWS Key Management Service (AWS KMS) AWS KMS key (KMS key) used to encrypt objects delivered by AWS Config. Must belong to the same Region as the destination S3 bucket.
fn create()
Create a Config DeliveryChannel
fn get(identifier: string)
Get a Config DeliveryChannel
ArgumentTypeDescription
identifierstringThe primary identifier of the Config DeliveryChannel
fn update()
Update a Config DeliveryChannel
fn delete(identifier: string)
Delete a Config DeliveryChannel
ArgumentTypeDescription
identifierstringThe primary identifier of the Config DeliveryChannel
fn sync()
Sync Config DeliveryChannel state from AWS
fn list(maxPages?: number, resourceModel?: string)
List Config DeliveryChannel resources
ArgumentTypeDescription
maxPages?numberMaximum number of pages to fetch (default: 10)
resourceModel?stringJSON resource model for parent-scoped listing (e.g. parent identifier)

Resources

state(infinite)— Config DeliveryChannel resource state
@swamp/aws/config/organization-config-rulev2026.10.01.1organization_config_rule.ts

Global Arguments

ArgumentTypeDescription
accessKeyId?stringAWS access key ID; overrides AWS_ACCESS_KEY_ID environment variable. Wire with a vault.get(...) expression to source it from a vault.
secretAccessKey?stringAWS secret access key; overrides AWS_SECRET_ACCESS_KEY environment variable. Wire with a vault.get(...) expression to source it from a vault.
sessionToken?stringAWS session token for temporary credentials; overrides AWS_SESSION_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
region?stringAWS region; overrides AWS_REGION / AWS_DEFAULT_REGION environment variables and ~/.aws/config profile region. Defaults to us-east-1.
OrganizationCustomRuleMetadata?objectThis object specifies organization custom rule metadata such as resource type, resource ID of AWS resource, Lambda function ARN, and organization trigger types that trigger AWS Config to evaluate your AWS resources against a rule.
OrganizationManagedRuleMetadata?objectThis object specifies organization managed rule metadata such as resource type and ID of AWS resource along with the rule identifier.
ExcludedAccounts?arrayA comma-separated list of accounts that you want to exclude from an organization AWS Config rule.
OrganizationConfigRuleNamestringThe name that you assign to an organization AWS Config rule. Required.
OrganizationCustomPolicyRuleMetadata?objectThis object specifies metadata for your organization's AWS Config Custom Policy rule.
fn create()
Create a Config OrganizationConfigRule
fn get(identifier: string)
Get a Config OrganizationConfigRule
ArgumentTypeDescription
identifierstringThe primary identifier of the Config OrganizationConfigRule
fn update()
Update a Config OrganizationConfigRule
fn delete(identifier: string)
Delete a Config OrganizationConfigRule
ArgumentTypeDescription
identifierstringThe primary identifier of the Config OrganizationConfigRule
fn sync()
Sync Config OrganizationConfigRule state from AWS
fn list(maxPages?: number, resourceModel?: string)
List Config OrganizationConfigRule resources
ArgumentTypeDescription
maxPages?numberMaximum number of pages to fetch (default: 10)
resourceModel?stringJSON resource model for parent-scoped listing (e.g. parent identifier)

Resources

state(infinite)— Config OrganizationConfigRule resource state
@swamp/aws/config/organization-conformance-packv2026.08.17.2organization_conformance_pack.ts

Global Arguments

ArgumentTypeDescription
accessKeyId?stringAWS access key ID; overrides AWS_ACCESS_KEY_ID environment variable. Wire with a vault.get(...) expression to source it from a vault.
secretAccessKey?stringAWS secret access key; overrides AWS_SECRET_ACCESS_KEY environment variable. Wire with a vault.get(...) expression to source it from a vault.
sessionToken?stringAWS session token for temporary credentials; overrides AWS_SESSION_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
region?stringAWS region; overrides AWS_REGION / AWS_DEFAULT_REGION environment variables and ~/.aws/config profile region. Defaults to us-east-1.
OrganizationConformancePackNamestringThe name of the organization conformance pack.
TemplateS3Uri?stringLocation of file containing the template body.
TemplateBody?stringA string containing full conformance pack template body.
DeliveryS3Bucket?stringAWS Config stores intermediate files while processing conformance pack template.
DeliveryS3KeyPrefix?stringThe prefix for the delivery S3 bucket.
ConformancePackInputParameters?arrayA list of ConformancePackInputParameter objects.
ExcludedAccounts?arrayA list of AWS accounts to be excluded from an organization conformance pack while deploying a conformance pack.
Tags?arrayThe tags for the organization conformance pack.
fn create()
Create a Config OrganizationConformancePack
fn get(identifier: string)
Get a Config OrganizationConformancePack
ArgumentTypeDescription
identifierstringThe primary identifier of the Config OrganizationConformancePack
fn update()
Update a Config OrganizationConformancePack
fn delete(identifier: string)
Delete a Config OrganizationConformancePack
ArgumentTypeDescription
identifierstringThe primary identifier of the Config OrganizationConformancePack
fn sync()
Sync Config OrganizationConformancePack state from AWS
fn list(maxPages?: number, resourceModel?: string)
List Config OrganizationConformancePack resources
ArgumentTypeDescription
maxPages?numberMaximum number of pages to fetch (default: 10)
resourceModel?stringJSON resource model for parent-scoped listing (e.g. parent identifier)

Resources

state(infinite)— Config OrganizationConformancePack resource state
@swamp/aws/config/remediation-configurationv2026.08.17.2remediation_configuration.ts

Global Arguments

ArgumentTypeDescription
accessKeyId?stringAWS access key ID; overrides AWS_ACCESS_KEY_ID environment variable. Wire with a vault.get(...) expression to source it from a vault.
secretAccessKey?stringAWS secret access key; overrides AWS_SECRET_ACCESS_KEY environment variable. Wire with a vault.get(...) expression to source it from a vault.
sessionToken?stringAWS session token for temporary credentials; overrides AWS_SESSION_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
region?stringAWS region; overrides AWS_REGION / AWS_DEFAULT_REGION environment variables and ~/.aws/config profile region. Defaults to us-east-1.
TargetVersion?string
ExecutionControls?object
Parameters?record
TargetTypestring
ConfigRuleNamestring
ResourceType?string
RetryAttemptSeconds?number
MaximumAutomaticAttempts?number
TargetIdstring
Automatic?boolean
fn create()
Create a Config RemediationConfiguration
fn get(identifier: string)
Get a Config RemediationConfiguration
ArgumentTypeDescription
identifierstringThe primary identifier of the Config RemediationConfiguration
fn update()
Update a Config RemediationConfiguration
fn delete(identifier: string)
Delete a Config RemediationConfiguration
ArgumentTypeDescription
identifierstringThe primary identifier of the Config RemediationConfiguration
fn sync()
Sync Config RemediationConfiguration state from AWS
fn list(maxPages?: number, resourceModel?: string)
List Config RemediationConfiguration resources
ArgumentTypeDescription
maxPages?numberMaximum number of pages to fetch (default: 10)
resourceModel?stringJSON resource model for parent-scoped listing (e.g. parent identifier)

Resources

state(infinite)— Config RemediationConfiguration resource state
@swamp/aws/config/stored-queryv2026.08.17.2stored_query.ts

Global Arguments

ArgumentTypeDescription
accessKeyId?stringAWS access key ID; overrides AWS_ACCESS_KEY_ID environment variable. Wire with a vault.get(...) expression to source it from a vault.
secretAccessKey?stringAWS secret access key; overrides AWS_SECRET_ACCESS_KEY environment variable. Wire with a vault.get(...) expression to source it from a vault.
sessionToken?stringAWS session token for temporary credentials; overrides AWS_SESSION_TOKEN environment variable. Wire with a vault.get(...) expression to source it from a vault.
region?stringAWS region; overrides AWS_REGION / AWS_DEFAULT_REGION environment variables and ~/.aws/config profile region. Defaults to us-east-1.
QueryNamestring
QueryDescription?string
QueryExpressionstring
Tags?arrayThe tags for the stored query.
fn create()
Create a Config StoredQuery
fn get(identifier: string)
Get a Config StoredQuery
ArgumentTypeDescription
identifierstringThe primary identifier of the Config StoredQuery
fn update()
Update a Config StoredQuery
fn delete(identifier: string)
Delete a Config StoredQuery
ArgumentTypeDescription
identifierstringThe primary identifier of the Config StoredQuery
fn sync()
Sync Config StoredQuery state from AWS
fn list(maxPages?: number, resourceModel?: string)
List Config StoredQuery resources
ArgumentTypeDescription
maxPages?numberMaximum number of pages to fetch (default: 10)
resourceModel?stringJSON resource model for parent-scoped listing (e.g. parent identifier)

Resources

state(infinite)— Config StoredQuery resource state
03Previous Versions19
2026.10.04.1
2026.10.03.1
2026.10.02.1
2026.10.01.1
  • Added: organization_config_rule

Added 1 models

2026.09.30.1
2026.09.29.1
2026.09.28.1
2026.09.27.1
2026.09.26.1
2026.09.25.1
  • Added: configuration_recorder

Added 1 models

2026.09.24.1
2026.09.23.1
2026.09.21.1
2026.09.20.1
2026.09.19.1
2026.09.18.1
2026.09.17.1
2026.09.16.1
2026.09.15.1
04Stats
A
100 / 100
Downloads
99
Archive size
2.2 MB
Verified by Swamp
  • Has README or module doc2/2earned
  • README has a code example1/1earned
  • README is substantive1/1earned
  • Most symbols documented1/1earned
  • No slow types (deprecated)1/1earned
  • Dependencies pass trust audit2/2earned
  • Has description1/1earned
  • Platform support declared (or universal)2/2earned
  • License declared1/1earned
  • Verified public repository2/2earned
05Platforms
06Labels