本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。
Amazon Config 目前支持以下托管规则。在使用这些规则之前,请参阅注意事项。
access-keys-rotated
acm-certificate-expiration-check
active-mq-supported-version
alb-desync-mode-check
alb-http-drop-invalid-已启用标题
alb-http-to-https-重定向检查
alb-waf-enabled
api-gwv2-access-logs-enabled
api-gwv2-authorization-type-configured
api-gw-associated-with-waf
api-gw-cache-enabled并已加密
api-gw-endpoint-type-检查
api-gw-execution-logging-已启用
api-gw-ssl-enabled
api-gw-xray-enabled
approved-amis-by-id
approved-amis-by-tag
appsync-associated-with-waf
appsync-authorization-check
appsync-logging-enabled
athena-workgroup-encrypted-at-休息
athena-workgroup-logging-enabled
autoscaling-group-elb-healthcheck-必填项
autoscaling-launchconfig-requires-imdsv2
autoscaling-launch-config-hop-限制
autoscaling-launch-config-public-ip 已禁用
autoscaling-launch-template
autoscaling-multiple-az
autoscaling-multiple-instance-types
beanstalk-enhanced-health-reporting-已启用
clb-desync-mode-check
clb-multiple-az
cloudformation-stack-drift-detection-检查
cloudformation-stack-notification-check
cloudtrail-s3-bucket-access-logging
cloudtrail-s3-bucket-public-access-prohibited
cloudtrail-s3-dataevents-enabled
cloudtrail-security-trail-enabled
cloudwatch-alarm-action-check
cloudwatch-alarm-action-enabled-检查
cloudwatch-alarm-resource-check
cloudwatch-alarm-settings-check
cloudwatch-log-group-encrypted
cloud-trail-cloud-watch-启用日志
cloudtrail-enabled
cloud-trail-encryption-enabled
cloud-trail-log-file-已启用验证
cmk-backing-key-rotation-已启用
codebuild-project-environment-privileged-检查
codebuild-project-envvar-awscred-检查
codebuild-project-logging-enabled
codebuild-project-s3 个日志加密
codebuild-project-source-repo-url-check
codebuild-report-group-encrypted-在休息时
custom-eventbus-policy-attached
cw-loggroup-retention-period-检查
datasync-task-logging-enabled
dax-encryption-enabled
db-instance-backup-enabled
desired-instance-tenancy
desired-instance-type
dms-auto-minor-version-升级检查
dms-endpoint-ssl-configured
dms-replication-not-public
dms-replication-task-sourcedb-日志
dms-replication-task-targetdb-记录
docdb-cluster-encrypted-in-交通
dynamodb-autoscaling-enabled
dynamodb-in-backup-plan
dynamodb-pitr-enabled
dynamodb-table-deletion-protection-已启用
dynamodb-table-encrypted-kms
dynamodb-throughput-limit-check
ebs-in-backup-plan
ebs-optimized-instance
ebs-snapshot-public-restorable-检查
ec2-ebs-encryption-by-default
ec2-imdsv2-check
ec2-instance-detailed-monitoring-enabled
ec2-instance-launched-with-allowed-ami
ec2-管理instance-managed-by-systems器
ec2-instance-multiple-eni-check
ec2-instance-no-public-ip
ec2-instance-profile-attached
ec launch-template-imdsv 2-2-check
ec2-launch-template-public-ip-已禁用
ec2-managedinstance-applications-blacklisted
ec2-managedinstance-applications-required
ec2-managedinstance-association-compliance-status-check
ec2-managedinstance-inventory-blacklisted
ec2-managedinstance-patch-compliance-status-check
ec2-managedinstance-platform-check
ec2-security-group-attached-to-eni
ec2-stopped-instance
ec2-volume-inuse-check
ecr-private-lifecycle-policy-已配置
ecr-private-tag-immutability-已启用
ecr-repository-cmk-encryption-已启用
ecs-containers-nonprivileged
ecs-containers-readonly-access
ecs-container-insights-enabled
ecs-fargate-latest-platform-版本
ecs-no-environment-secrets
ecs-task-definition-log-配置
ecs-task-definition-network-mode-not-host
ecs-task-definition-pid-模式检查
ecs-task-definition-user-for-host-mode-check
efs-automatic-backups-enabled
efs-encrypted-check
efs-filesystem-ct-encrypted
efs-in-backup-plan
eip-attached
eks-cluster-log-enabled
eks-cluster-supported-version
eks-endpoint-no-public-访问
eks-secrets-encrypted
elasticache-auto-minor-version-升级检查
elasticache-redis-cluster-automatic-备份检查
elasticache-repl-grp-auto-启用故障转移
elasticache-repl-grp-encrypted-在休息时
elasticache-repl-grp-encrypted在途中
elasticache-repl-grp-redis-已启用 auth
elasticache-subnet-group-check
elasticsearch-encrypted-at-rest
elasticsearch-in-vpc-only
elasticsearch-logs-to-cloudwatch
elasticsearch-node-to-node-加密检查
elastic-beanstalk-managed-updates-已启用
elbv2-acm-certificate-required
elbv2-multiple-az
elb-acm-certificate-required
elb-cross-zone-load-启用平衡
elb-custom-security-policy-ssl-check
elb-deletion-protection-enabled
elb-logging-enabled
elb-predefined-security-policy-ssl-check
elb-tls-https-listeners-只有
emr-kerberos-enabled
emr-master-no-public-ip
encrypted-volumes
fms-webacl-resource-policy-检查
fms-webacl-rulegroup-association-检查
fsx-ontap-deployment-type-检查
fsx-openzfs-deployment-type-检查
glue-job-logging-enabled
glue-spark-job-supported-版本
guardduty-enabled-centralized
guardduty-non-archived-findings
iam-customer-policy-blocked-kms 动作
iam-group-has-users-检查
iam-inline-policy-blocked-kms 动作
iam-no-inline-policy-检查
iam-password-policy
iam-policy-blacklisted-check
iam-policy-in-use
iam-policy-no-statements-with-admin-access
iam-policy-no-statements-with-full-access
iam-role-managed-policy-检查
iam-root-access-key-检查
iam-user-group-membership-检查
iam-user-mfa-enabled
iam-user-no-policies-检查
iam-user-unused-credentials-检查
restricted-ssh
ec2-instances-in-vpc
internet-gateway-authorized-vpc-只有
kinesis-stream-backup-retention-检查
kinesis-stream-encrypted
kms-cmk-not-scheduled-用于删除
kms-key-policy-no-公共访问
mfa-enabled-for-iam-控制台访问权限
mq-active-deployment-mode
mq-auto-minor-version-已启用升级
mq-rabbit-deployment-mode
msk-enhanced-monitoring-enabled
msk-in-cluster-node-需要-tls
multi-region-cloudtrail-enabled
nacl-no-unrestricted-ssh-rdp
no-unrestricted-route-to-igw
opensearch-update-check
rabbit-mq-supported-version
rds-automatic-minor-version-已启用升级
rds-enhanced-monitoring-enabled
rds-instance-deletion-protection-已启用
rds-instance-iam-authentication-已启用
rds-instance-public-access-检查
rds-instance-subnet-igw-检查
rds-in-backup-plan
rds-logging-enabled
rds-multi-az-support
rds-mysql-instance-encrypted在途中
rds-postgresql-logs-to-云观察
rds-postgres-instance-encrypted在途中
rds-snapshots-public-prohibited
rds-snapshot-encrypted
rds-sqlserver-encrypted-in-交通
rds-sql-server-logs到云端观察
rds-storage-encrypted
redshift-backup-enabled
redshift-cluster-configuration-check
redshift-cluster-kms-enabled
redshift-cluster-maintenancesettings-check
redshift-cluster-public-access-检查
redshift-cluster-subnet-group-多可用区
redshift-default-admin-check
redshift-default-db-name-检查
redshift-enhanced-vpc-routing-已启用
redshift-require-tls-ssl
redshift-serverless-default-admin-检查
redshift-serverless-default-db-姓名检查
redshift-serverless-namespace-cmk-加密
redshift-serverless-publish-logs到云端观察
required-tags
restricted-common-ports
仅限 s3 access-point-in-vpc-
s3 access-point-public-access-方块
s3-account-level-public-access-blocks
s3--account-level-public-access 区块-周期性
s3-bucket-acl-prohibited
s3-bucket-blacklisted-actions-prohibited
s3-已bucket-cross-region-replication启用
s3-bucket-default-lock-enabled
s3-bucket-level-public-access-禁止使用
s3-bucket-logging-enabled
s3-bucket-mfa-delete-enabled
s3-bucket-policy-grantee-check
s3-bucket-policy-not-more-宽容
s3-bucket-public-read-prohibited
s3-bucket-public-write-prohibited
s3-bucket-replication-enabled
s3-已bucket-server-side-encryption启用
s3-bucket-ssl-requests-only
s3-bucket-versioning-enabled
s3-default-encryption-kms
s3-event-notifications-enabled
s3-lifecycle-policy-check
s3-version-lifecycle-policy-check
sagemaker-endpoint-configuration-kms-密钥已配置
sagemaker-notebook-instance-inside-vpc
sagemaker-notebook-instance-kms-密钥已配置
sagemaker-notebook-instance-platform-版本
sagemaker-notebook-instance-root-访问检查
sagemaker-notebook-no-direct-互联网接入
secretsmanager-rotation-enabled-check
secretsmanager-scheduled-rotation-success-检查
secretsmanager-secret-periodic-rotation
secretsmanager-secret-unused
secretsmanager-using-cmk
securityhub-enabled
security-account-information-provided
service-vpc-endpoint-enabled
sns-encrypted-kms
sns-topic-message-delivery-启用通知
sns-topic-no-public-访问
sqs-queue-no-public-访问
ssm-document-not-public
step-functions-state-machine-启用日志功能
subnet-auto-assign-public-ip 已禁用
transfer-connector-logging-enabled
vpc-default-security-group-已关闭
vpc-endpoint-enabled
vpc-flow-logs-enabled
vpc-network-acl-unused-检查
vpc-sg-open-only-to-authorized-ports
wafv2-logging-enabled
wafv2-rulegroup-logging-enabled
wafv2-webacl-not-empty
waf-regional-rule-not-空
waf-regional-webacl-not-空
Javascript 在您的浏览器中被禁用或不可用。
要使用 Amazon Web Services 文档,必须启用 Javascript。请参阅浏览器的帮助页面以了解相关说明。