Interface ConfigurationRecorder.Builder

All Superinterfaces:
Buildable, CopyableBuilder<ConfigurationRecorder.Builder,ConfigurationRecorder>, SdkBuilder<ConfigurationRecorder.Builder,ConfigurationRecorder>, SdkPojo
Enclosing class:
ConfigurationRecorder

public static interface ConfigurationRecorder.Builder extends SdkPojo, CopyableBuilder<ConfigurationRecorder.Builder,ConfigurationRecorder>
  • Method Details

    • name

      The name of the configuration recorder. Config automatically assigns the name of "default" when creating the configuration recorder.

      You cannot change the name of the configuration recorder after it has been created. To change the configuration recorder name, you must delete it and create a new configuration recorder with a new name.

      Parameters:
      name - The name of the configuration recorder. Config automatically assigns the name of "default" when creating the configuration recorder.

      You cannot change the name of the configuration recorder after it has been created. To change the configuration recorder name, you must delete it and create a new configuration recorder with a new name.

      Returns:
      Returns a reference to this object so that method calls can be chained together.
    • roleARN

      Amazon Resource Name (ARN) of the IAM role assumed by Config and used by the configuration recorder.

      While the API model does not require this field, the server will reject a request without a defined roleARN for the configuration recorder.

      Pre-existing Config role

      If you have used an Amazon Web Services service that uses Config, such as Security Hub or Control Tower, and an Config role has already been created, make sure that the IAM role that you use when setting up Config keeps the same minimum permissions as the already created Config role. You must do this so that the other Amazon Web Services service continues to run as expected.

      For example, if Control Tower has an IAM role that allows Config to read Amazon Simple Storage Service (Amazon S3) objects, make sure that the same permissions are granted within the IAM role you use when setting up Config. Otherwise, it may interfere with how Control Tower operates. For more information about IAM roles for Config, see Identity and Access Management for Config in the Config Developer Guide.

      Parameters:
      roleARN - Amazon Resource Name (ARN) of the IAM role assumed by Config and used by the configuration recorder.

      While the API model does not require this field, the server will reject a request without a defined roleARN for the configuration recorder.

      Pre-existing Config role

      If you have used an Amazon Web Services service that uses Config, such as Security Hub or Control Tower, and an Config role has already been created, make sure that the IAM role that you use when setting up Config keeps the same minimum permissions as the already created Config role. You must do this so that the other Amazon Web Services service continues to run as expected.

      For example, if Control Tower has an IAM role that allows Config to read Amazon Simple Storage Service (Amazon S3) objects, make sure that the same permissions are granted within the IAM role you use when setting up Config. Otherwise, it may interfere with how Control Tower operates. For more information about IAM roles for Config, see Identity and Access Management for Config in the Config Developer Guide.

      Returns:
      Returns a reference to this object so that method calls can be chained together.
    • recordingGroup

      ConfigurationRecorder.Builder recordingGroup(RecordingGroup recordingGroup)

      Specifies which resource types Config records for configuration changes.

      High Number of Config Evaluations

      You may notice increased activity in your account during your initial month recording with Config when compared to subsequent months. During the initial bootstrapping process, Config runs evaluations on all the resources in your account that you have selected for Config to record.

      If you are running ephemeral workloads, you may see increased activity from Config as it records configuration changes associated with creating and deleting these temporary resources. An ephemeral workload is a temporary use of computing resources that are loaded and run when needed. Examples include Amazon Elastic Compute Cloud (Amazon EC2) Spot Instances, Amazon EMR jobs, and Auto Scaling. If you want to avoid the increased activity from running ephemeral workloads, you can run these types of workloads in a separate account with Config turned off to avoid increased configuration recording and rule evaluations.

      Parameters:
      recordingGroup - Specifies which resource types Config records for configuration changes.

      High Number of Config Evaluations

      You may notice increased activity in your account during your initial month recording with Config when compared to subsequent months. During the initial bootstrapping process, Config runs evaluations on all the resources in your account that you have selected for Config to record.

      If you are running ephemeral workloads, you may see increased activity from Config as it records configuration changes associated with creating and deleting these temporary resources. An ephemeral workload is a temporary use of computing resources that are loaded and run when needed. Examples include Amazon Elastic Compute Cloud (Amazon EC2) Spot Instances, Amazon EMR jobs, and Auto Scaling. If you want to avoid the increased activity from running ephemeral workloads, you can run these types of workloads in a separate account with Config turned off to avoid increased configuration recording and rule evaluations.

      Returns:
      Returns a reference to this object so that method calls can be chained together.
    • recordingGroup

      default ConfigurationRecorder.Builder recordingGroup(Consumer<RecordingGroup.Builder> recordingGroup)

      Specifies which resource types Config records for configuration changes.

      High Number of Config Evaluations

      You may notice increased activity in your account during your initial month recording with Config when compared to subsequent months. During the initial bootstrapping process, Config runs evaluations on all the resources in your account that you have selected for Config to record.

      If you are running ephemeral workloads, you may see increased activity from Config as it records configuration changes associated with creating and deleting these temporary resources. An ephemeral workload is a temporary use of computing resources that are loaded and run when needed. Examples include Amazon Elastic Compute Cloud (Amazon EC2) Spot Instances, Amazon EMR jobs, and Auto Scaling. If you want to avoid the increased activity from running ephemeral workloads, you can run these types of workloads in a separate account with Config turned off to avoid increased configuration recording and rule evaluations.

      This is a convenience method that creates an instance of the RecordingGroup.Builder avoiding the need to create one manually via RecordingGroup.builder().

      When the Consumer completes, SdkBuilder.build() is called immediately and its result is passed to recordingGroup(RecordingGroup).

      Parameters:
      recordingGroup - a consumer that will call methods on RecordingGroup.Builder
      Returns:
      Returns a reference to this object so that method calls can be chained together.
      See Also:
    • recordingMode

      ConfigurationRecorder.Builder recordingMode(RecordingMode recordingMode)

      Specifies the default recording frequency that Config uses to record configuration changes. Config supports Continuous recording and Daily recording.

      • Continuous recording allows you to record configuration changes continuously whenever a change occurs.

      • Daily recording allows you to receive a configuration item (CI) representing the most recent state of your resources over the last 24-hour period, only if it’s different from the previous CI recorded.

      Firewall Manager depends on continuous recording to monitor your resources. If you are using Firewall Manager, it is recommended that you set the recording frequency to Continuous.

      You can also override the recording frequency for specific resource types.

      Parameters:
      recordingMode - Specifies the default recording frequency that Config uses to record configuration changes. Config supports Continuous recording and Daily recording.

      • Continuous recording allows you to record configuration changes continuously whenever a change occurs.

      • Daily recording allows you to receive a configuration item (CI) representing the most recent state of your resources over the last 24-hour period, only if it’s different from the previous CI recorded.

      Firewall Manager depends on continuous recording to monitor your resources. If you are using Firewall Manager, it is recommended that you set the recording frequency to Continuous.

      You can also override the recording frequency for specific resource types.

      Returns:
      Returns a reference to this object so that method calls can be chained together.
    • recordingMode

      default ConfigurationRecorder.Builder recordingMode(Consumer<RecordingMode.Builder> recordingMode)

      Specifies the default recording frequency that Config uses to record configuration changes. Config supports Continuous recording and Daily recording.

      • Continuous recording allows you to record configuration changes continuously whenever a change occurs.

      • Daily recording allows you to receive a configuration item (CI) representing the most recent state of your resources over the last 24-hour period, only if it’s different from the previous CI recorded.

      Firewall Manager depends on continuous recording to monitor your resources. If you are using Firewall Manager, it is recommended that you set the recording frequency to Continuous.

      You can also override the recording frequency for specific resource types.

      This is a convenience method that creates an instance of the RecordingMode.Builder avoiding the need to create one manually via RecordingMode.builder().

      When the Consumer completes, SdkBuilder.build() is called immediately and its result is passed to recordingMode(RecordingMode).

      Parameters:
      recordingMode - a consumer that will call methods on RecordingMode.Builder
      Returns:
      Returns a reference to this object so that method calls can be chained together.
      See Also: