Checks whether your CloudFormation stacks' actual configuration differs, or has drifted, from its expected configuration.
import { CloudFormationStackDriftDetectionCheck } from 'aws-cdk-lib/aws-config';Or use the module namespace:
import * as config from 'aws-cdk-lib/aws-config';
// config.CloudFormationStackDriftDetectionCheckConfiguration passed to the constructor as CloudFormationStackDriftDetectionCheckProps.
ownStackOnlyOptionalbooleanWhether to check only the stack where this rule is deployed.
Default: false
roleOptionalIRoleRefThe IAM role to use for this rule. It must have permissions to detect drift for AWS CloudFormation stacks. Ensure to attach `config.amazonaws.com` trusted permissions and `ReadOnlyAccess` policy permissions. For specific policy permissions, refer to https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/using-cfn-stack-drift.html.
Default: - A role will be created
RulePropsconfigRuleNameOptionalinherited from RulePropsstringA name for the AWS Config rule.
Default: - CloudFormation generated name
descriptionOptionalinherited from RulePropsstringA description about this AWS Config rule.
Default: - No description
evaluationModesOptionalinherited from RulePropsEvaluationModeThe modes the AWS Config rule can be evaluated in. The valid values are distinct objects.
Default: - Detective evaluation mode only
inputParametersOptionalinherited from RuleProps{ [key: string]: any }Input parameter values that are passed to the AWS Config rule.
Default: - No input parameters
maximumExecutionFrequencyOptionalinherited from RulePropsMaximumExecutionFrequencyThe maximum frequency at which the AWS Config rule runs evaluations.
Default: MaximumExecutionFrequency.TWENTY_FOUR_HOURS
ruleScopeOptionalinherited from RulePropsRuleScopeDefines which resources trigger an evaluation for an AWS Config rule.
Default: - evaluations for the rule are triggered when any resource in the recording group changes.
Our bi-weekly newsletter teaches hands-on AWS fundamentals. No certification fluff - just practical knowledge.
Subscribe to Newsletteraws-config