Overview

A config rule that checks whether running instances are using specified AMIs. Specify the tags that identify the AMIs. Running instances with AMIs that don't have at least one of the specified tags are noncompliant.

This config rule supports Auto Remediation actions using SSM Automation triggered with CloudWatch Events. The following actions are supported:

  • Stop Instance: Non-compliant instances are stopped.
  • Terminate Instance: Non-compliant instances are terminated. (Be careful when selecting this option to not accidentally terminate existing resources).

In addition to an action, a notification using an SNS Topic can be added to send a custom message when a non-compliant resource is detected.

Configuration Templates

Items
1
Size
0.6 KB
Missing Parameters
AWSTemplateFormatVersion: '2010-09-09'
Description: ''
Resources:
  ConfigRule:
    Type: 'AWS::Config::ConfigRule'
    Properties:
      ConfigRuleName: approved-amis-by-tag
      Description: >-
        A config rule that checks whether running instances are using specified
        AMIs. Specify the tags that identify the AMIs. Running instances with
        AMIs that don't have at least one of the specified tags are
        noncompliant.
      Scope:
        ComplianceResourceTypes:
          - 'AWS::EC2::Instance'
      Source:
        Owner: AWS
        SourceIdentifier: APPROVED_AMIS_BY_TAG
Parameters: {}
Metadata: {}
Conditions: {}

Actions



Rule Parameters

 
  
* Required field

Sources and Documentation

Configuration Source: AWS Documentation

Additional Documentation: