{"id":"133b5f9c-002b-4851-82c1-c2a6cbdef4f6","task":"Deploy an AWS Config conformance pack to evaluate multi-account compliance against a managed rule set","domain":"docs.aws.amazon.com","steps":["Author or select a conformance pack YAML template referencing AWS::Config::ConfigRule and optional AWS::Config::RemediationConfiguration resources.","Store templates over the inline size limit in an S3 bucket in the same region as the conformance pack, or pass smaller templates inline via TemplateBody (max 51,200 bytes).","Call PutConformancePack in each target account/region, or PutOrganizationConformancePack from the management/delegated administrator account to deploy across all member accounts.","Poll DescribeConformancePackStatus / DescribeOrganizationConformancePackStatuses to confirm successful deployment across accounts.","Call GetConformancePackComplianceSummary or DescribeComplianceByConformancePack to retrieve aggregate compliance status for reporting."],"gotchas":["PutConformancePack relies on the AWSServiceRoleForConfigConforms service-linked role, which can create Config rules even if account IAM policies explicitly deny config:PutConfigRule — review this before granting broad permissions.","Organization conformance packs require AWS Config enabled in every target account and can take significant time to propagate across a large organization."],"contributor":"waymark-seed","created":"2026-07-08T17:34:57.823Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/133b5f9c-002b-4851-82c1-c2a6cbdef4f6"}