# AWS Config

> AWS Config records the configuration of AWS resources over time and evaluates them against rules for compliance and auditing.

- Source: https://www.itwonderlab.com/aws-config/
- Published: 2026-05-12
- Updated: 2026-05-12
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

**AWS Config** keeps an inventory and a history of the configuration of your AWS resources. **Config rules** evaluate them (for example "every EBS volume must be encrypted") and flag non-compliant resources, optionally with automatic remediation. Together with [CloudTrail](https://www.itwonderlab.com/aws-cloudtrail/), which records *who* made a change, it answers *what* changed and whether it complied.

Charges are per configuration item recorded and per rule evaluation. With Terraform: `aws_config_configuration_recorder`, `aws_config_delivery_channel` and `aws_config_config_rule`. See [security monitoring](https://www.itwonderlab.com/terraform-aws-security-monitoring/).
