Amazon Config #X Amz Target=StarlingDoveService.DescribeOrganizationConfigRules API

The #X Amz Target=StarlingDoveService.DescribeOrganizationConfigRules API from Amazon Config — 1 operation(s) for #x amz target=starlingdoveservice.describeorganizationconfigrules.

OpenAPI Specification

amazon-config-x-amz-target-starlingdoveservice-describeorganizationconfigrules-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  version: '2014-11-12'
  x-release: v4
  title: 'AWS Config #X Amz Target=StarlingDoveService.BatchGetAggregateResourceConfig #X Amz Target=StarlingDoveService.BatchGetAggregateResourceConfig #X Amz Target=StarlingDoveService.DescribeOrganizationConfigRules API'
  description: <fullname>Config</fullname> <p>Config provides a way to keep track of the configurations of all the Amazon Web Services resources associated with your Amazon Web Services account. You can use Config to get the current and historical configurations of each Amazon Web Services resource and also to get information about the relationship between the resources. An Amazon Web Services resource can be an Amazon Compute Cloud (Amazon EC2) instance, an Elastic Block Store (EBS) volume, an elastic network Interface (ENI), or a security group. For a complete list of resources currently supported by Config, see <a href="https://docs.aws.amazon.com/config/latest/developerguide/resource-config-reference.html#supported-resources">Supported Amazon Web Services resources</a>.</p> <p>You can access and manage Config through the Amazon Web Services Management Console, the Amazon Web Services Command Line Interface (Amazon Web Services CLI), the Config API, or the Amazon Web Services SDKs for Config. This reference guide contains documentation for the Config API and the Amazon Web Services CLI commands that you can use to manage Config. The Config API uses the Signature Version 4 protocol for signing requests. For more information about how to sign a request with this protocol, see <a href="https://docs.aws.amazon.com/general/latest/gr/signature-version-4.html">Signature Version 4 Signing Process</a>. For detailed information about Config features and their associated actions or commands, as well as how to work with Amazon Web Services Management Console, see <a href="https://docs.aws.amazon.com/config/latest/developerguide/WhatIsConfig.html">What Is Config</a> in the <i>Config Developer Guide</i>.</p>
  x-logo:
    url: https://twitter.com/awscloud/profile_image?size=original
    backgroundColor: '#FFFFFF'
  termsOfService: https://aws.amazon.com/service-terms/
  contact:
    name: Mike Ralphson
    email: mike.ralphson@gmail.com
    url: https://github.com/mermade/aws2openapi
    x-twitter: PermittedSoc
  license:
    name: Apache 2.0 License
    url: http://www.apache.org/licenses/
  x-providerName: amazonaws.com
  x-serviceName: config
  x-origin:
  - contentType: application/json
    url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/config-2014-11-12.normal.json
    converter:
      url: https://github.com/mermade/aws2openapi
      version: 1.0.0
    x-apisguru-driver: external
  x-apiClientRegistration:
    url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct
  x-apisguru-categories:
  - cloud
  x-preferred: true
servers:
- url: http://config.{region}.amazonaws.com
  variables:
    region:
      description: The AWS region
      enum:
      - us-east-1
      - us-east-2
      - us-west-1
      - us-west-2
      - us-gov-west-1
      - us-gov-east-1
      - ca-central-1
      - eu-north-1
      - eu-west-1
      - eu-west-2
      - eu-west-3
      - eu-central-1
      - eu-south-1
      - af-south-1
      - ap-northeast-1
      - ap-northeast-2
      - ap-northeast-3
      - ap-southeast-1
      - ap-southeast-2
      - ap-east-1
      - ap-south-1
      - sa-east-1
      - me-south-1
      default: us-east-1
  description: The Config Service multi-region endpoint
- url: https://config.{region}.amazonaws.com
  variables:
    region:
      description: The AWS region
      enum:
      - us-east-1
      - us-east-2
      - us-west-1
      - us-west-2
      - us-gov-west-1
      - us-gov-east-1
      - ca-central-1
      - eu-north-1
      - eu-west-1
      - eu-west-2
      - eu-west-3
      - eu-central-1
      - eu-south-1
      - af-south-1
      - ap-northeast-1
      - ap-northeast-2
      - ap-northeast-3
      - ap-southeast-1
      - ap-southeast-2
      - ap-east-1
      - ap-south-1
      - sa-east-1
      - me-south-1
      default: us-east-1
  description: The Config Service multi-region endpoint
- url: http://config.{region}.amazonaws.com.cn
  variables:
    region:
      description: The AWS region
      enum:
      - cn-north-1
      - cn-northwest-1
      default: cn-north-1
  description: The Config Service endpoint for China (Beijing) and China (Ningxia)
- url: https://config.{region}.amazonaws.com.cn
  variables:
    region:
      description: The AWS region
      enum:
      - cn-north-1
      - cn-northwest-1
      default: cn-north-1
  description: The Config Service endpoint for China (Beijing) and China (Ningxia)
security:
- hmac: []
tags:
- name: '#X Amz Target=StarlingDoveService.DescribeOrganizationConfigRules'
paths:
  /#X-Amz-Target=StarlingDoveService.DescribeOrganizationConfigRules:
    parameters:
    - $ref: '#/components/parameters/X-Amz-Content-Sha256'
    - $ref: '#/components/parameters/X-Amz-Date'
    - $ref: '#/components/parameters/X-Amz-Algorithm'
    - $ref: '#/components/parameters/X-Amz-Credential'
    - $ref: '#/components/parameters/X-Amz-Security-Token'
    - $ref: '#/components/parameters/X-Amz-Signature'
    - $ref: '#/components/parameters/X-Amz-SignedHeaders'
    post:
      operationId: DescribeOrganizationConfigRules
      description: <p>Returns a list of organization Config rules. </p> <note> <p>When you specify the limit and the next token, you receive a paginated response.</p> <p>Limit and next token are not applicable if you specify organization Config rule names. It is only applicable, when you request all the organization Config rules.</p> <p> <i>For accounts within an organzation</i> </p> <p>If you deploy an organizational rule or conformance pack in an organization administrator account, and then establish a delegated administrator and deploy an organizational rule or conformance pack in the delegated administrator account, you won't be able to see the organizational rule or conformance pack in the organization administrator account from the delegated administrator account or see the organizational rule or conformance pack in the delegated administrator account from organization administrator account. The <code>DescribeOrganizationConfigRules</code> and <code>DescribeOrganizationConformancePacks</code> APIs can only see and interact with the organization-related resource that were deployed from within the account calling those APIs.</p> </note>
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DescribeOrganizationConfigRulesResponse'
              examples:
                DescribeOrganizationConfigRules200Example:
                  summary: Default DescribeOrganizationConfigRules 200
                  x-microcks-default: true
                  value:
                    OrganizationConfigRules: example
                    NextToken: example
        '480':
          description: NoSuchOrganizationConfigRuleException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NoSuchOrganizationConfigRuleException'
              examples:
                DescribeOrganizationConfigRules480Example:
                  summary: Default DescribeOrganizationConfigRules 480
                  x-microcks-default: true
                  value: example
        '481':
          description: InvalidNextTokenException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvalidNextTokenException'
              examples:
                DescribeOrganizationConfigRules481Example:
                  summary: Default DescribeOrganizationConfigRules 481
                  x-microcks-default: true
                  value: example
        '482':
          description: InvalidLimitException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvalidLimitException'
              examples:
                DescribeOrganizationConfigRules482Example:
                  summary: Default DescribeOrganizationConfigRules 482
                  x-microcks-default: true
                  value: example
        '483':
          description: OrganizationAccessDeniedException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OrganizationAccessDeniedException'
              examples:
                DescribeOrganizationConfigRules483Example:
                  summary: Default DescribeOrganizationConfigRules 483
                  x-microcks-default: true
                  value: example
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DescribeOrganizationConfigRulesRequest'
      parameters:
      - name: Limit
        in: query
        schema:
          type: string
        description: Pagination limit
        required: false
      - name: NextToken
        in: query
        schema:
          type: string
        description: Pagination token
        required: false
      - name: X-Amz-Target
        in: header
        required: true
        schema:
          type: string
          enum:
          - StarlingDoveService.DescribeOrganizationConfigRules
      summary: Amazon Config Describe Organization Config Rules
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
      tags:
      - '#X Amz Target=StarlingDoveService.DescribeOrganizationConfigRules'
components:
  schemas:
    DebugLogDeliveryAccounts:
      type: array
      items:
        $ref: '#/components/schemas/AccountId'
      minItems: 0
      maxItems: 1000
    StringWithCharLimit64:
      type: string
      minLength: 1
      maxLength: 64
    StringWithCharLimit256:
      type: string
      minLength: 1
      maxLength: 256
    MaximumExecutionFrequency:
      type: string
      enum:
      - One_Hour
      - Three_Hours
      - Six_Hours
      - Twelve_Hours
      - TwentyFour_Hours
    OrganizationConfigRuleNames:
      type: array
      items:
        $ref: '#/components/schemas/StringWithCharLimit64'
      minItems: 0
      maxItems: 25
    NoSuchOrganizationConfigRuleException: {}
    ExcludedAccounts:
      type: array
      items:
        $ref: '#/components/schemas/AccountId'
      minItems: 0
      maxItems: 1000
    DescribeOrganizationConfigRulesRequest:
      type: object
      title: DescribeOrganizationConfigRulesRequest
      properties:
        OrganizationConfigRuleNames:
          allOf:
          - $ref: '#/components/schemas/OrganizationConfigRuleNames'
          - description: The names of organization Config rules for which you want details. If you do not specify any names, Config returns details for all your organization Config rules.
        Limit:
          allOf:
          - $ref: '#/components/schemas/CosmosPageLimit'
          - description: The maximum number of organization Config rules returned on each page. If you do no specify a number, Config uses the default. The default is 100.
        NextToken:
          allOf:
          - $ref: '#/components/schemas/String'
          - description: 'The <code>nextToken</code> string returned on a previous page that you use to get the next page of results in a paginated response. '
    PolicyRuntime:
      type: string
      pattern: guard\-2\.x\.x
      minLength: 1
      maxLength: 64
    OrganizationConfigRuleName:
      type: string
      pattern: .*\S.*
      minLength: 1
      maxLength: 64
    OrganizationCustomRuleMetadata:
      type: object
      required:
      - LambdaFunctionArn
      - OrganizationConfigRuleTriggerTypes
      properties:
        Description:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit256Min0'
          - description: The description that you provide for your organization Config rule.
        LambdaFunctionArn:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit256'
          - description: The lambda function ARN.
        OrganizationConfigRuleTriggerTypes:
          allOf:
          - $ref: '#/components/schemas/OrganizationConfigRuleTriggerTypes'
          - description: <p>The type of notification that triggers Config to run an evaluation for a rule. You can specify the following notification types:</p> <ul> <li> <p> <code>ConfigurationItemChangeNotification</code> - Triggers an evaluation when Config delivers a configuration item as a result of a resource change.</p> </li> <li> <p> <code>OversizedConfigurationItemChangeNotification</code> - Triggers an evaluation when Config delivers an oversized configuration item. Config may generate this notification type when a resource changes and the notification exceeds the maximum size allowed by Amazon SNS.</p> </li> <li> <p> <code>ScheduledNotification</code> - Triggers a periodic evaluation at the frequency specified for <code>MaximumExecutionFrequency</code>.</p> </li> </ul>
        InputParameters:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit2048'
          - description: A string, in JSON format, that is passed to your organization Config rule Lambda function.
        MaximumExecutionFrequency:
          allOf:
          - $ref: '#/components/schemas/MaximumExecutionFrequency'
          - description: <p>The maximum frequency with which Config runs evaluations for a rule. Your custom rule is triggered when Config delivers the configuration snapshot. For more information, see <a>ConfigSnapshotDeliveryProperties</a>.</p> <note> <p>By default, rules with a periodic trigger are evaluated every 24 hours. To change the frequency, specify a valid value for the <code>MaximumExecutionFrequency</code> parameter.</p> </note>
        ResourceTypesScope:
          allOf:
          - $ref: '#/components/schemas/ResourceTypesScope'
          - description: The type of the Amazon Web Services resource that was evaluated.
        ResourceIdScope:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit768'
          - description: The ID of the Amazon Web Services resource that was evaluated.
        TagKeyScope:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit128'
          - description: 'One part of a key-value pair that make up a tag. A key is a general label that acts like a category for more specific tag values. '
        TagValueScope:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit256'
          - description: 'The optional part of a key-value pair that make up a tag. A value acts as a descriptor within a tag category (key). '
      description: ' organization custom rule metadata such as resource type, resource ID of Amazon Web Services resource, Lambda function ARN, and organization trigger types that trigger Config to evaluate your Amazon Web Services resources against a rule. It also provides the frequency with which you want Config to run evaluations for the rule if the trigger type is periodic.'
    Date:
      type: string
      format: date-time
    InvalidNextTokenException: {}
    OrganizationConfigRuleTriggerType:
      type: string
      enum:
      - ConfigurationItemChangeNotification
      - OversizedConfigurationItemChangeNotification
      - ScheduledNotification
    StringWithCharLimit128:
      type: string
      minLength: 1
      maxLength: 128
    CosmosPageLimit:
      type: integer
      minimum: 0
      maximum: 100
    OrganizationConfigRuleTriggerTypeNoSN:
      type: string
      enum:
      - ConfigurationItemChangeNotification
      - OversizedConfigurationItemChangeNotification
    InvalidLimitException: {}
    StringWithCharLimit2048:
      type: string
      minLength: 1
      maxLength: 2048
    OrganizationConfigRules:
      type: array
      items:
        $ref: '#/components/schemas/OrganizationConfigRule'
    String:
      type: string
    StringWithCharLimit768:
      type: string
      minLength: 1
      maxLength: 768
    DescribeOrganizationConfigRulesResponse:
      type: object
      properties:
        OrganizationConfigRules:
          allOf:
          - $ref: '#/components/schemas/OrganizationConfigRules'
          - description: Returns a list of <code>OrganizationConfigRule</code> objects.
        NextToken:
          allOf:
          - $ref: '#/components/schemas/String'
          - description: 'The <code>nextToken</code> string returned on a previous page that you use to get the next page of results in a paginated response. '
    StringWithCharLimit256Min0:
      type: string
      minLength: 0
      maxLength: 256
    OrganizationManagedRuleMetadata:
      type: object
      required:
      - RuleIdentifier
      properties:
        Description:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit256Min0'
          - description: The description that you provide for your organization Config rule.
        RuleIdentifier:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit256'
          - description: For organization config managed rules, a predefined identifier from a list. For example, <code>IAM_PASSWORD_POLICY</code> is a managed rule. To reference a managed rule, see <a href="https://docs.aws.amazon.com/config/latest/developerguide/evaluate-config_use-managed-rules.html">Using Config managed rules</a>.
        InputParameters:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit2048'
          - description: A string, in JSON format, that is passed to your organization Config rule Lambda function.
        MaximumExecutionFrequency:
          allOf:
          - $ref: '#/components/schemas/MaximumExecutionFrequency'
          - description: <p>The maximum frequency with which Config runs evaluations for a rule. This is for an Config managed rule that is triggered at a periodic frequency.</p> <note> <p>By default, rules with a periodic trigger are evaluated every 24 hours. To change the frequency, specify a valid value for the <code>MaximumExecutionFrequency</code> parameter.</p> </note>
        ResourceTypesScope:
          allOf:
          - $ref: '#/components/schemas/ResourceTypesScope'
          - description: The type of the Amazon Web Services resource that was evaluated.
        ResourceIdScope:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit768'
          - description: The ID of the Amazon Web Services resource that was evaluated.
        TagKeyScope:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit128'
          - description: 'One part of a key-value pair that make up a tag. A key is a general label that acts like a category for more specific tag values. '
        TagValueScope:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit256'
          - description: The optional part of a key-value pair that make up a tag. A value acts as a descriptor within a tag category (key).
      description: ' organization managed rule metadata such as resource type and ID of Amazon Web Services resource along with the rule identifier. It also provides the frequency with which you want Config to run evaluations for the rule if the trigger type is periodic.'
    AccountId:
      type: string
      pattern: \d{12}
    OrganizationConfigRuleTriggerTypes:
      type: array
      items:
        $ref: '#/components/schemas/OrganizationConfigRuleTriggerType'
    OrganizationConfigRuleTriggerTypeNoSNs:
      type: array
      items:
        $ref: '#/components/schemas/OrganizationConfigRuleTriggerTypeNoSN'
    OrganizationCustomPolicyRuleMetadataNoPolicy:
      type: object
      properties:
        Description:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit256Min0'
          - description: The description that you provide for your organization Config Custom Policy rule.
        OrganizationConfigRuleTriggerTypes:
          allOf:
          - $ref: '#/components/schemas/OrganizationConfigRuleTriggerTypeNoSNs'
          - description: <p>The type of notification that triggers Config to run an evaluation for a rule. For Config Custom Policy rules, Config supports change triggered notification types:</p> <ul> <li> <p> <code>ConfigurationItemChangeNotification</code> - Triggers an evaluation when Config delivers a configuration item as a result of a resource change.</p> </li> <li> <p> <code>OversizedConfigurationItemChangeNotification</code> - Triggers an evaluation when Config delivers an oversized configuration item. Config may generate this notification type when a resource changes and the notification exceeds the maximum size allowed by Amazon SNS.</p> </li> </ul>
        InputParameters:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit2048'
          - description: A string, in JSON format, that is passed to your organization Config Custom Policy rule.
        MaximumExecutionFrequency:
          allOf:
          - $ref: '#/components/schemas/MaximumExecutionFrequency'
          - description: The maximum frequency with which Config runs evaluations for a rule. Your Config Custom Policy rule is triggered when Config delivers the configuration snapshot. For more information, see <a>ConfigSnapshotDeliveryProperties</a>.
        ResourceTypesScope:
          allOf:
          - $ref: '#/components/schemas/ResourceTypesScope'
          - description: The type of the Amazon Web Services resource that was evaluated.
        ResourceIdScope:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit768'
          - description: The ID of the Amazon Web Services resource that was evaluated.
        TagKeyScope:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit128'
          - description: One part of a key-value pair that make up a tag. A key is a general label that acts like a category for more specific tag values.
        TagValueScope:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit256'
          - description: The optional part of a key-value pair that make up a tag. A value acts as a descriptor within a tag category (key).
        PolicyRuntime:
          allOf:
          - $ref: '#/components/schemas/PolicyRuntime'
          - description: The runtime system for your organization Config Custom Policy rules. Guard is a policy-as-code language that allows you to write policies that are enforced by Config Custom Policy rules. For more information about Guard, see the <a href="https://github.com/aws-cloudformation/cloudformation-guard">Guard GitHub Repository</a>.
        DebugLogDeliveryAccounts:
          allOf:
          - $ref: '#/components/schemas/DebugLogDeliveryAccounts'
          - description: A list of accounts that you can enable debug logging for your organization Config Custom Policy rule. List is null when debug logging is enabled for all accounts.
      description: ' metadata for your organization Config Custom Policy rule including the runtime system in use, which accounts have debug logging enabled, and other custom rule metadata such as resource type, resource ID of Amazon Web Services resource, and organization trigger types that trigger Config to evaluate Amazon Web Services resources against a rule.'
    OrganizationAccessDeniedException: {}
    ResourceTypesScope:
      type: array
      items:
        $ref: '#/components/schemas/StringWithCharLimit256'
      minItems: 0
      maxItems: 100
    OrganizationConfigRule:
      type: object
      required:
      - OrganizationConfigRuleName
      - OrganizationConfigRuleArn
      properties:
        OrganizationConfigRuleName:
          allOf:
          - $ref: '#/components/schemas/OrganizationConfigRuleName'
          - description: The name that you assign to organization Config rule.
        OrganizationConfigRuleArn:
          allOf:
          - $ref: '#/components/schemas/StringWithCharLimit256'
          - description: Amazon Resource Name (ARN) of organization Config rule.
        OrganizationManagedRuleMetadata:
          allOf:
          - $ref: '#/components/schemas/OrganizationManagedRuleMetadata'
          - description: An <code>OrganizationManagedRuleMetadata</code> object.
        OrganizationCustomRuleMetadata:
          allOf:
          - $ref: '#/components/schemas/OrganizationCustomRuleMetadata'
          - description: An <code>OrganizationCustomRuleMetadata</code> object.
        ExcludedAccounts:
          allOf:
          - $ref: '#/components/schemas/ExcludedAccounts'
          - description: A comma-separated list of accounts excluded from organization Config rule.
        LastUpdateTime:
          allOf:
          - $ref: '#/components/schemas/Date'
          - description: The timestamp of the last update.
        OrganizationCustomPolicyRuleMetadata:
          allOf:
          - $ref: '#/components/schemas/OrganizationCustomPolicyRuleMetadataNoPolicy'
          - description: An object that specifies metadata for your organization's Config Custom Policy rule. The metadata includes the runtime system in use, which accounts have debug logging enabled, and other custom rule metadata, such as resource type, resource ID of Amazon Web Services resource, and organization trigger types that initiate Config to evaluate Amazon Web Services resources against a rule.
      description: An organization Config rule that has information about Config rules that Config creates in member accounts.
  parameters:
    X-Amz-Content-Sha256:
      name: X-Amz-Content-Sha256
      in: header
      schema:
        type: string
      required: false
    X-Amz-Algorithm:
      name: X-Amz-Algorithm
      in: header
      schema:
        type: string
      required: false
    X-Amz-Credential:
      name: X-Amz-Credential
      in: header
      schema:
        type: string
      required: false
    X-Amz-Security-Token:
      name: X-Amz-Security-Token
      in: header
      schema:
        type: string
      required: false
    X-Amz-Signature:
      name: X-Amz-Signature
      in: header
      schema:
        type: string
      required: false
    X-Amz-Date:
      name: X-Amz-Date
      in: header
      schema:
        type: string
      required: false
    X-Amz-SignedHeaders:
      name: X-Amz-SignedHeaders
      in: header
      schema:
        type: string
      required: false
  securitySchemes:
    hmac:
      type: apiKey
      name: Authorization
      in: header
      description: Amazon Signature authorization v4
      x-amazon-apigateway-authtype: awsSigv4
externalDocs:
  description: Amazon Web Services documentation
  url: https://docs.aws.amazon.com/config/
x-hasEquivalentPaths: true