Build Config conformance pack configurations with managed/custom rules, input parameters, and compliance templates.
Build Config conformance pack configurations with managed/custom rules, input parameters, and compliance templates.
Required Fields
ConformancePackNameTemplateBody.ResourcesOutput will appear here...The builder validates that ConformancePackName and TemplateBody.Resources resolve before accepting the JSON as a valid PutConformancePack request, the fields Config needs to name the pack and know what rules it bundles; it can't verify the referenced S3 delivery bucket has the correct permissions or that every {Ref} parameter reference in TemplateBody actually matches a defined ConformancePackInputParameters entry, those are checked only against the live API.
Build an AWS Config conformance pack, a CloudFormation-like template bundling multiple Config rules (managed, like S3_BUCKET_VERSIONING_ENABLED, or custom) plus ConformancePackInputParameters that get substituted via {Ref} into individual rules' InputParameters, letting one parameterized template define a reusable compliance baseline instead of duplicating near-identical rule definitions per account. ExcludedAccounts only applies when the conformance pack is deployed at the organization level via an organization conformance pack, a standalone, single-account conformance pack has no concept of excluded accounts at all, that field only does something in the org-wide deployment path.
Test a new conformance pack in a single non-production account before deploying it as an organization conformance pack, a mistake in the TemplateBody or an input parameter reaches every account in scope simultaneously once deployed at the org level.
ConformancePackInputParameters not referenced by any rule via {Ref} are silently unused, don't assume defining a parameter automatically applies it anywhere, verify each parameter is actually wired into the rule that needs it.
DeliveryS3Bucket needs a bucket policy granting Config service permission to write there, a missing or incorrect bucket policy causes compliance result delivery to silently fail with no obvious error in the conformance pack's own status.
No, ExcludedAccounts only has meaning for an organization conformance pack deployed org-wide (via PutOrganizationConformancePack), it excludes specific member accounts from an otherwise org-wide deployment. A standalone conformance pack deployed to one account has no concept of 'excluded accounts', if you see this field having no effect, confirm you're actually deploying via the organization conformance pack API, not the single-account one.
Via the {Ref} intrinsic function inside the rule's own InputParameters in TemplateBody, exactly like a CloudFormation parameter reference, the conformance pack's top-level ConformancePackInputParameters values get substituted wherever a rule references that parameter name with {Ref}. A rule that doesn't reference the parameter simply doesn't receive it, parameters aren't globally injected into every rule automatically.
Yes, a rule's Source.Owner can be AWS (for a managed rule identified by SourceIdentifier like S3_BUCKET_VERSIONING_ENABLED) or CUSTOM_LAMBDA (for your own compliance logic backed by a Lambda function), both types can coexist as different Resources entries within the same conformance pack's TemplateBody.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.