本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。
Amazon Config 托管规则的列表
Amazon Config当前支持以下托管规则。
为托管规则指定的默认值仅在使用Amazon控制台。不为 API、CLI 或开发工具包提供默认值。
主题
- access-keys-rotated
- alb-http-drop-invalid-已启用标头
- alb-http-to-https-重定向检查
- api-gw-cache-enabled和加密
- api-gw-endpoint-type-Check
- api-gw-execution-logging-已启用
- approved-amis-by-id
- approved-amis-by-tag
- autoscaling-group-elb-healthcheck-必需
- autoscaling-launch-config-public-ip-已禁用
- cloudtrail-s3-dataevents-enabled
- cloudtrail-security-trail-enabled
- cloudwatch-alarm-action-check
- cloudwatch-alarm-resource-check
- cloudwatch-alarm-settings-check
- cloud-trail-cloud-watch-logs 已启用
- cloudtrail-enabled
- cloud-trail-encryption-enabled
- cloud-trail-log-file-已启用验证
- cmk-backing-key-rotation-启用
- codebuild-project-envvar-awscred-Check
- codebuild-project-source-repo-url-check
- cw-loggroup-retention-period-check
- db-instance-backup-enabled
- desired-instance-tenancy
- desired-instance-type
- dms-replication-not-public
- dynamodb-autoscaling-enabled
- dynamodb-in-backup-plan
- dynamodb-pitr-enabled
- dynamodb-table-encrypted-kms
- dynamodb-throughput-limit-check
- ebs-in-backup-plan
- ebs-optimized-instance
- ebs-snapshot-public-restorable-Check
- ec2-ebs-encryption-by-default
- ec2-imdsv2-check
- ec2-instance-detailed-monitoring-enabled
- ec2-instance-managed-by-systems-Manager
- ec2-instance-multiple-eni-check
- ec2-instance-no-public-ip
- ec2-managedinstance-applications-blacklisted
- ec2-managedinstance-applications-required
- ec2-managedinstance-association-compliance-status-Check
- ec2-managedinstance-inventory-blacklisted
- ec2-managedinstance-patch-compliance-status-Check
- ec2-managedinstance-platform-check
- ec2security-group-attached-to-eni
- ec2-stopped-instance
- ec2-volume-inuse-check
- efs-encrypted-check
- efs-in-backup-plan
- eip-attached
- eks-endpoint-no-public-访问
- eks-secrets-encrypted
- elasticache-redis-cluster-automatic-备份检查
- elasticsearch-in-vpc-only
- elbv2-acm-certificate-required
- elb-cross-zone-load-已启用平衡
- elb-custom-security-policy-ssl-check
- elb-deletion-protection-enabled
- elb-logging-enabled
- elb-predefined-security-policy-ssl-check
- elb-tls-https-listeners-仅限
- emr-kerberos-enabled
- emr-master-no-public-ip
- encrypted-volumes
- fms-webacl-resource-policy-Check
- fms-webacl-rulegroup-association-check
- iam-customer-policy-blocked-kms-actions
- iam-group-has-users-Check
- iam-inline-policy-blocked-kms-actions
- iam-no-inline-policy-Check
- iam-password-policy
- iam-policy-blacklisted-check
- iam-policy-in-use
- iam-policy-no-statements-with-admin-access
- iam-role-managed-policy-Check
- iam-root-access-key-check
- iam-user-group-membership-check
- iam-user-mfa-enabled
- iam-user-no-policies-Check
- iam-user-unused-credentials-Check
- restricted-ssh
- ec2-instances-in-vpc
- internet-gateway-authorized-vpc-限
- kms-cmk-not-scheduled-for delete
- mfa-enabled-for-iam-控制台访问权限
- multi-region-cloudtrail-enabled
- rds-enhanced-monitoring-enabled
- rds-instance-deletion-protection-已启用
- rds-instance-public-access-Check
- rds-in-backup-plan
- rds-multi-az-support
- rds-snapshots-public-prohibited
- rds-snapshot-encrypted
- rds-storage-encrypted
- redshift-cluster-configuration-check
- redshift-cluster-maintenancesettings-check
- redshift-cluster-public-access-check
- redshift-require-tls-ssl
- required-tags
- restricted-common-ports
- s3-account-level-public-access-块
- s3-bucket-blacklisted-actions-prohibited
- s3-bucket-default-lock-enabled
- s3-bucket-logging-enabled
- s3-bucket-policy-grantee-check
- s3-bucket-policy-not-more-宽容
- s3.bucket-public-read-prohibited
- s3bucket-public-write-prohibited
- s3-bucket-replication-enabled
- s3-bucket-server-side-encryption-已启用
- s3-bucket-ssl-requests-only
- s3-bucket-versioning-enabled
- s3-default-encryption-kms
- secretsmanager-rotation-enabled-check
- secretsmanager-scheduled-rotation-success-check
- service-vpc-endpoint-enabled
- sns-encrypted-kms
- ssm-document-not-public
- vpc-default-security-group-Close
- vpc-flow-logs-enabled
- vpc-sg-open-only-to-authorized-ports