Learn the key terms used in Cloud Config.
|
Term |
Description |
|
Resource type |
A classification for resources. For example, the resource type of ECS instances is ECS Instance. Resources include:
|
|
Resource configuration details |
Cloud Config retrieves all resources under your Alibaba Cloud account through the resource query APIs of each service. You can view resource configurations in the resource list or manage resources in the corresponding service console. |
|
Monitoring scope |
The monitoring scope defines which resource types Cloud Config tracks. Monitoring operates at the resource type level.
|
|
Rule |
A rule determines whether a resource configuration is compliant. Cloud Config hosts rule code as Function Compute functions. When a rule is attached to a resource type, configuration changes to resources of that type automatically trigger an evaluation. Rules can also run on a periodic schedule. Cloud Config supports the following rule types:
|
|
Configuration history |
Cloud Config provides a configuration history for each monitored resource.
|
|
Compliance history |
Rule evaluations are triggered when resource configurations change. Each resource's configuration history has a corresponding compliance history that records evaluation results. The records depend on the rule's trigger method.
|
|
Classified protection precheck |
The MLPS 2.0 precheck is a cloud-based compliance check that dynamically and continuously checks your Alibaba Cloud resources for compliance, helping you avoid repeated rectifications and pass the official assessment faster. |
|
CIS |
CIS (Center for Internet Security) is a community of organizations and individuals that want actionable security resources. The CIS Controls list the top 20 objectives enterprises must meet for basic network security. |
|
Resource directory |
Resource Directory is an Alibaba Cloud service that helps enterprise customers manage multi-level relationships between resources and accounts. |
|
Management account |
An Alibaba Cloud account that has passed enterprise verification and enabled a resource directory. The management account is the super administrator with full permissions over the resource directory, all folders, and all members. Each resource directory has exactly one management account. Note
A management account does not belong to the resource directory and is not subject to its access control policies. |
|
Member |
An account within a resource directory. Members are either resource accounts (created in the directory to isolate project or application resources) or cloud accounts (existing Alibaba Cloud accounts invited to join).
|
|
Account group |
A collection of members in a resource directory. The management account adds all or some members to an account group for centralized compliance management. The group also serves as a resource pool that aggregates resources from its members. The management account can view resource lists, details, configuration histories, compliance histories, and linked instances of all members. It can also create rules and compliance packages that apply to all member resources for continuous compliance evaluation. |