AWS Config
Config
You need to track resource configuration changes and evaluate whether deployed resources meet your rules.
Reach for it when
- Recording configuration history for supported resource types across accounts.
- Evaluating compliance rules and investigating when a resource setting changed.
Do not reach for it when
- Capturing application logs: use CloudWatch Logs.
- Proving every API call occurred: use CloudTrail alongside configuration history.
Alternatives, and how to choose
| Service | Pick it instead when |
|---|---|
| CloudTrail | Use API event records to identify the actor and operation. |
| CloudWatch | Use metrics and logs for runtime health. |
How you pay
- The model
- Configuration items, rule evaluations and enabled features contribute to cost.
- The line item that surprises people
- Broad recording and frequent evaluations can accumulate across many resources.
What trips people up
- Recording must cover the resource types and Regions relevant to the question.
- A compliance finding does not automatically repair a resource; remediation must be configured and permissioned.
Verify the live service
This page is a concept reference. Cost models are qualitative; confirm the current offering, Region and pricing before deploying.