Manage compliance packages
A compliance package contains the rules that Cloud Config uses to check the compliance of your resources. You can perform the following operations on compliance packages:
Modify a compliance package: update the basic information and rules of a compliance package.
Copy a compliance package: copy a compliance package from one account group to another in the same Resource Directory.
Export and import compliance packages: reuse compliance package configurations across environments through template files.
Download the compliance evaluation report of a compliance package: download the evaluation results of a compliance package to your computer.
Delete a compliance package: delete a compliance package that you no longer need.
Member accounts in an account group view cannot modify, delete, or import compliance packages, and can copy a compliance package only to the current account.
Modify a compliance package
You can modify the basic information and effective scope of a compliance package, add or remove rules in the package, or change the parameters of its rules.
Log on to the Cloud Config console.
Optional. In the upper-left corner, select an account group.
This operation is required only if you are using a management account of a resource directory. Otherwise, you do not need to perform the operation.
In the left-side navigation pane, choose .
Log on to the Cloud Config console.
(Optional) In the upper-left corner, select an account group.
This operation is required only if you are using a management account of Resource Directory.
In the left-side navigation pane, choose Compliance & Audit > Compliance Package.
On the Compliance Packages page, find the compliance package that you want to modify and click Modify in the Actions column.
NoteModify is unavailable while the compliance package is in the Creating state. Member accounts in an account group view cannot modify compliance packages.
On the Set Basic Properties page, modify the basic information and effective scope of the compliance package, and then click Next.
On the Select Rules page, add or delete rules, and then click Next.
On the Set Rule Parameters page, set parameters for the rules, and then click OK.
Result
After you submit the modification, the Compliance Package Status changes to Applying. You can view the detection results by rule, resource, and member. The Member Detection Results tab is displayed only in multi-account mode.
Copy a compliance package
In multi-account scenarios, the management account or the Cloud Config delegated administrator can copy a compliance package from one account group (account group A) to another account group (account group B).
Prerequisites
To copy a compliance package between account groups, make sure that the following requirements are met:
You log on with the management account or the Cloud Config delegated administrator, and the management account has activated Resource Directory. For more information, see Enable Resource Directory.
Members are created or invited in Resource Directory. For more information, see Create a member and Invite an Alibaba Cloud account.
An account group and a compliance package are created. For more information, see Create an account group and Create a compliance package.
Log on to the Cloud Config console.
In the left-side navigation pane, choose .
Log on to the Cloud Config console.
In the upper-left corner, select account group A, which contains the compliance package that you want to copy.
In the left-side navigation pane, choose Compliance & Audit > Compliance Package.
On the Compliance Package page, click the ID of the compliance package that you want to copy, or click the
icon in the Actions column and then select Copy.NoteA member account in an account group view can copy a compliance package only to the current account.
In the Copy Compliance Package dialog box, select account group B to which you want to copy the compliance package, and then click OK.
View the copied compliance package in account group B.
In the upper-left corner, select account group B. On the Compliance Packages page, you can view the compliance package copied from account group A and its evaluation results.
Export and import compliance packages
You can export a compliance package as a template file, and import a template file to create a compliance package. This allows you to reuse compliance package configurations across environments.
Exporting a compliance package produces a reusable template file in .json format. To download the evaluation results of a compliance package as an Excel file, see Download the compliance evaluation report of a compliance package.
Export a compliance package
Log on to the Cloud Config console.
Optional. In the upper-left corner, select an account group.
This operation is required only if you are using a management account of a resource directory. Otherwise, you do not need to perform the operation.
In the left-side navigation pane, choose .
Log on to the Cloud Config console.
(Optional) In the upper-left corner, select an account group.
This operation is required only if you are using a management account of Resource Directory.
In the left-side navigation pane, choose Compliance & Audit > Compliance Package.
On the Compliance Packages page, find the compliance package that you want to export and click Export in the Actions column.
Result
The browser downloads the compliance package as a template file named CompliancePackageName.json.
Import a compliance package
Log on to the Cloud Config console.
Optional. In the upper-left corner, select an account group.
This operation is required only if you are using a management account of a resource directory. Otherwise, you do not need to perform the operation.
In the left-side navigation pane, choose .
Log on to the Cloud Config console.
(Optional) In the upper-left corner, select an account group.
This operation is required only if you are using a management account of Resource Directory.
In the left-side navigation pane, choose Compliance & Audit > Compliance Package.
On the Compliance Packages page, click Import Compliance Package.
NoteImport Compliance Package is unavailable to member accounts in an account group view.
In the dialog box, click Upload File and select a text file whose name ends with
.jsonor.txtand whose size is less than 1 MB. You can upload only one file at a time.
Result
After the import succeeds, the console automatically opens the details page of the new compliance package.
Download the compliance evaluation report of a compliance package
You can download the evaluation results of a compliance package to your computer to assign remediation tasks offline and track the modification of resource configurations.
Log on to the Cloud Config console.
Optional. In the upper-left corner, select an account group.
This operation is required only if you are using a management account of a resource directory. Otherwise, you do not need to perform the operation.
In the left-side navigation pane, choose .
Log on to the Cloud Config console.
(Optional) In the upper-left corner, select an account group.
This operation is required only if you are using a management account of Resource Directory.
In the left-side navigation pane, choose Compliance & Audit > Compliance Package.
On the Compliance Package page, click the ID of the compliance package whose compliance evaluation report you want to download.
In the upper-right corner, click Download Report.
NoteIf the download feature is upgraded in your environment, the Download Feature Upgrade dialog box appears first. Click Continue Download to proceed with the download, or click Go to Compliance Reports to use the new compliance reports page in a new tab.
In the Download Compliance Report dialog box, click OK.
Result
In single-account mode, you receive one evaluation report in Excel format. In multi-account mode, you receive the evaluation reports of all members in the account group. The Excel report of each member is named in the MemberID_MemberName format.
Delete a compliance package
If you no longer need a compliance package to check resources, you can delete it. After a compliance package is deleted, all rules in the package and their evaluation results are automatically deleted.
Log on to the Cloud Config console.
Optional. In the upper-left corner, select an account group.
This operation is required only if you are using a management account of a resource directory. Otherwise, you do not need to perform the operation.
In the left-side navigation pane, choose .
Log on to the Cloud Config console.
(Optional) In the upper-left corner, select an account group.
This operation is required only if you are using a management account of Resource Directory.
In the left-side navigation pane, choose Compliance & Audit > Compliance Package.
On the Compliance Packages page, find the compliance package that you want to delete, click the
icon in the Actions column, and then select Delete.NoteMember accounts in an account group view cannot delete compliance packages.
In the Delete Compliance Package dialog box, click OK.
-
View the compliance evaluation results.
On the Compliance Package page, click the target compliance package's ID, or click Details in the Actions column for the package.
-
On the Rule Result tab, view the number of non-compliant resources by rule. You can also perform the following operations on the rules in the compliance package:
-
Click Edit or Delete in the Actions column for a rule to modify or delete it from the current compliance package and the Rules list.
-
Click Remove in the Actions column for a rule to remove it from the current compliance package.
-
-
On the Resource Result tab, view a list of non-compliant resources. You can also perform the following operations:
-
Click a resource's ID or name to view its Details, Related Resources, Historical Configuration Changes, and Compliance Timeline. For more information, see View resource information, View related resource information, View the configuration change history of a resource, and View the compliance timeline of a resource.
-
-
Result
The compliance package no longer appears on the Compliance Packages page.