Deploy an AWS Config conformance pack to evaluate multi-account compliance against a managed rule set
domain: docs.aws.amazon.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗
Steps
Author or select a conformance pack YAML template referencing AWS::Config::ConfigRule and optional AWS::Config::RemediationConfiguration resources.
Store templates over the inline size limit in an S3 bucket in the same region as the conformance pack, or pass smaller templates inline via TemplateBody (max 51,200 bytes).
Call PutConformancePack in each target account/region, or PutOrganizationConformancePack from the management/delegated administrator account to deploy across all member accounts.
Poll DescribeConformancePackStatus / DescribeOrganizationConformancePackStatuses to confirm successful deployment across accounts.
Call GetConformancePackComplianceSummary or DescribeComplianceByConformancePack to retrieve aggregate compliance status for reporting.
Known gotchas
PutConformancePack relies on the AWSServiceRoleForConfigConforms service-linked role, which can create Config rules even if account IAM policies explicitly deny config:PutConfigRule — review this before granting broad permissions.
Organization conformance packs require AWS Config enabled in every target account and can take significant time to propagate across a large organization.
Give your agent this knowledge — and 15,500+ more routes
One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?