---
name: app-configuration-ac-configuration-aggregator
title: Configuration Aggregator
description: By default, recording is always set to be OFF.
last-updated: 2025-12-08
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/app-configuration?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Configuration Aggregator
{: #ac-configuration-aggregator}

Configuration Aggregator can be used to facilitate a Cloud Governance SME with up-to-date configuration data of IBM Cloud resources in one place so that comprehensive information is available for goverance and compliance initiatives. All the plans of the App Configuration service except the Lite Plan will have the Configuration Aggregator feature available. As an app owner, the user has to explicitly enable the Configuration Aggregator. It can be done on the App Configuration instance either via API, SDK or Dashboard. The App Configuration service will start the resource collection and periodically to keep the metadata current via reconciliation. User can use the query API to get the updated metadata of the service instances in the account.

Configuration Aggregator feature can be configured on an App Configuration instance at Enterprise account level to collect resource metadata from all the sub-accounts of the enterprise. A trusted profile template should be created providing access to App Configuration service instance to all the IAM enabled services. The trusted profile template should then be assigned to the required accounts in the Enterprise, which in turn creates the trusted profile in the respective sub-accounts providing access to App Configuration service instance to collect resource metadata.

By default, recording is always set to be OFF.
{: shortdesc}

![Default Configuration Aggregator](images/config-aggr-default.png "Default Configuration Aggregator"){: caption="Default Configuration Aggregator" caption-side="bottom"}


## Configuration aggregator used with Security and Compliance Center Workload Protection
{: #ac-configuration-aggregator-with-workload-protection}

The Configuration aggregator is the data source used by Security and Compliance Center Workload Protection to perform cloud security posture management (CSPM) of IBM Cloud resources.  When configuring IBM Cloud CSPM within Workload Protection, an instance of App Configuration with aggregation enabled is automatically connected to Workload Protection.  You do need to explicitly enable recording as mentioned above.  New instances of App Configuration created through workload protection are provisioned into the Basic Plan by default.  Aggregation within the Basic plan is free and will not add to the cost of Workload Protection.


When Context Based Restrictions are enabled for any resource in your IBM Cloud account, configuration cannot be collected unless access to that resource is provided. To provide access, you need to create a rule. When asked to add a context, create a network zone and select App Configuration as the reference service. 
   ![CBR](images/ac-cbr.png "CBR"){: caption="CBR for Configuration Aggregator" caption-side="bottom"}
{: note}


## Enable Configuration aggregator - Single Account
{: #ac-enable-configuration-aggregator-single-account}

To enable configuration aggregator, complete these steps:

1. In the App Configuration console, click **Configuration aggregator**.

1. Click on **Define an aggregation**. The side panel opens with fields for setting up recording details.

   ![Enable Configuration Aggregator - Set up recording](images/config-aggr-recording.png "Set up recording - Single Account"){: caption="Set up recording - Single Account" caption-side="bottom"}

1. Select either **all regions** or specific regions from the **region** list. Click on **Save** to complete. This will create a Trusted Profile on App Configuration instance having reader access for reading the configurations of the resources.

1. Click on toggle button to enable recording. It will ask for confirmation. Click on **Turn on** button.

   ![Enable Configuration Aggregator - Enable recording](images/config-aggr-enable.png "Enable Recording - Single Account"){: caption="Enable Recording - Single Account" caption-side="bottom"}

## Enable Configuration aggregator - Enterprise Account
{: #ac-enable-configuration-aggregator-enterprise-account}

**In order to enable configuration aggregator feature for enterprise account, user must complete following Pre-requisities**:

1. Create an App Configuration instance at the top-level of the enterprise i.e enterprise account.

1. Create a Trusted Profile Template providing access for the App Configuration service instance to the IAM enabled services and Account Management services. Refer [Creating Trusted Profile](https://cloud.ibm.com/docs/enterprise-management?topic=enterprise-management-tp-template-create&format=markdown)

   ![Enable Configuration Aggregator - Trusted Profile Template](images/tp-template.png "Trusted Profile Template - Enterprise Account"){: caption="Trusted Profile Template - Enterprise Account" caption-side="bottom"}

The trusted profile template cannot be assigned to the enterprise account i.e the top level account of the enterprise. If you choose to collect metadata of resources in the enterprise account, you should create a separate trusted profile that should be applied at the top level account additionally.
{: note}

1. Assign the Trusted profile template to the required accounts and account groups in the Enterprise.

The Enterprise IAM should be enabled in the sub-accounts of an Enterprise to be managed via Enterprise. For more details, refer [Opting in to enterprise-managed IAM](https://cloud.ibm.com/docs/enterprise-management?topic=enterprise-management-enterprise-managed-opt-in&format=markdown)
{: note}

To enable configuration aggregator for an enterprise account, complete the pre-requisites and following steps:

1. In the App Configuration console, click **Configuration aggregator**.

1. Click on **Define an aggregation**. The side panel opens with fields for setting up recording details.

   ![Enable Configuration Aggregator - Set up recording - Enterprise Account](images/config-aggr-ent-recording.png "Set up recording - Enterprise Account"){: caption="Set up recording - Enterprise Account" caption-side="bottom"}

1. Provide the Set up record details:
   - **Region** - regions from which user wants to collect configuration data.
   - **Enterprise ID** - enterprise account id.
   - **Trusted template ID** - trusted profile template id created as pre-requisite.
   - **Trusted profile ID** - trusted profile id created as pre-requisite.

1. Click **Save**.

1. Click on toggle button to enable recording. It will ask for confirmation. Click on **Turn on** button.

   ![Enable Configuration Aggregator - Enable Recording - Enterprise Account](images/config-aggr-ent-enable.png "Enable Recording - Enterprise Account"){: caption="Enable Recording - Enterprise Account" caption-side="bottom"}


## Retrieve Resource Metadata
{: #ac-enable-configuration-aggregator-query-configs}

We can query for the configurations of IBM Cloud resources using list API. It will provide with the detailed metadata of the resources when Configuration Aggregator is enabled for an App Configuration instance.

## List of Services Supported by Configuration Aggregator
{: #ac-list-of-services-configaggregator}

Configuration Aggregator supports the following services:

| Name of service |
|-----------------|
| [Cloud Object Storage](https://cloud.ibm.com/docs/cloud-object-storage?format=markdown) |
| [Kubernetes Service](https://cloud.ibm.com/docs/containers?format=markdown) |
| [Red Hat OpenShift](https://cloud.ibm.com/docs/openshift?format=markdown) |
| [Virtual server for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-creating-virtual-servers&format=markdown) |
| [Virtual Private Cloud](https://cloud.ibm.com/docs/vpc?format=markdown) |
| [Block storage volume for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-creating-block-storage&format=markdown) |
| [Block storage snapshots for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-snapshots-vpc-create&format=markdown) |
| [Secrets Manager](https://cloud.ibm.com/docs/secrets-manager?format=markdown) |
| [Databases for PostgreSQL](https://cloud.ibm.com/docs/databases-for-postgresql?format=markdown) |
| [Databases for Redis](https://cloud.ibm.com/docs/databases-for-redis?format=markdown) |
| [Databases for ElasticSearch](https://cloud.ibm.com/docs/databases-for-elasticsearch?format=markdown) |
| [Databases for MongoDB](https://cloud.ibm.com/docs/databases-for-mongodb?format=markdown) |
| [Databases for MySQL](https://cloud.ibm.com/docs/databases-for-mysql?format=markdown) |
| [Identity and Access Management](https://cloud.ibm.com/docs/iam?topic=iam-cloudaccess&format=markdown) |
| [Key Protect](https://cloud.ibm.com/docs/key-protect?format=markdown) |
| [Container Registry](https://cloud.ibm.com/docs/Registry?topic=Registry-getting-started&format=markdown) |
| [Load Balancer for VPC](https://cloud.ibm.com/docs/loadbalancer-service?format=markdown) |
| [Security Group for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-using-security-groups&format=markdown) |
| [SSH Keys for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-ssh-keys&format=markdown) |
| [Subnet for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-about-subnets-vpc&format=markdown) |
| [Virtual Private Endpoint (VPE) for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-ordering-endpoint-gateway&interface=ui&format=markdown) |
| [Auto Scale (Instance Group) for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-creating-auto-scale-instance-group&format=markdown) |
| [Bare Metal servers for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-planning-for-bare-metal-servers&format=markdown) |
| [Client VPN for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-vpn-client-to-site-overview&format=markdown) |
| [Dedicated Host for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-creating-dedicated-hosts-instances&format=markdown) |
| [Floating IP for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-fip-about&format=markdown) |
| [Flow Logs - VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-flow-logs&format=markdown) |
| [Custom image for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-planning-custom-images&format=markdown) |
| [Placement Groups for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-about-placement-groups-for-vpc&format=markdown) |
| [Code Engine](https://cloud.ibm.com/docs/codeengine?format=markdown) |
| [Network ACL - VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-using-acls&format=markdown) |
| [DNS Service - VPC](https://cloud.ibm.com/docs/dns-svcs?format=markdown) |
| [VPN for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-about-networking-for-vpc&format=markdown#external-connectivity) |
| [IBM Cloud Backup - VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-backup-service-about&format=markdown) |
| [Public Gateway](https://cloud.ibm.com/docs/vpc?topic=vpc-vpn-create-gateway&format=markdown) |
| [Event Streams (messagehub)](https://cloud.ibm.com/docs/EventStreams?format=markdown) |
| [IBM Cloud Direct Link](https://cloud.ibm.com/docs/dl?format=markdown) |
| [Transit Gateway](https://cloud.ibm.com/docs/transit-gateway?format=markdown) |
| [Toolchain](https://cloud.ibm.com/docs/ContinuousDelivery?format=markdown) |
| [IBM Cloudant](https://cloud.ibm.com/docs/Cloudant?format=markdown) |
| [IBM Cloud Internet Services (CIS)](https://cloud.ibm.com/docs/cis?format=markdown) |
| [IBM Cloud Logs](https://cloud.ibm.com/docs/cloud-logs?format=markdown) |
| [IBM Cloud Shell](https://cloud.ibm.com/docs/cloud-shell?topic=cloud-shell-getting-started&format=markdown) |
| [IBM Cloud Monitoring](https://cloud.ibm.com/docs/monitoring?topic=monitoring-getting-started&format=markdown#getting-started)|
| [Security and Compliance Center (SCC)](https://cloud.ibm.com/docs/security-compliance?format=markdown) |
| [SCC Workload Protection](https://cloud.ibm.com/docs/workload-protection?topic=workload-protection-getting-started&format=markdown) |
| [Hyper Protect Crypto Services (HPCS)](https://cloud.ibm.com/docs/hs-crypto?format=markdown) |
| [App ID](https://cloud.ibm.com/docs/appid?format=markdown) |
| [App Configuration](https://cloud.ibm.com/docs/app-configuration?format=markdown) |
| [Catalog Management](https://cloud.ibm.com/docs/account?topic=account-restrict-by-user&interface=ui&format=markdown) |
| [Event Notifications](https://cloud.ibm.com/docs/event-notifications?format=markdown) |
| [Messages for RabbitMQ](https://cloud.ibm.com/docs/messages-for-rabbitmq?format=markdown) |
| [IBM Cloud Projects](https://cloud.ibm.com/docs/secure-enterprise?topic=secure-enterprise-understanding-projects&format=markdown) |
| [IBM Cloud Activity Tracker Event Routing](https://cloud.ibm.com/docs/atracker?format=markdown) |
| [Enterprise](https://cloud.ibm.com/docs/enterprise-management?format=markdown) |
| [IBM Power Virtual Server](https://cloud.ibm.com/docs/power-iaas?format=markdown) |
| [Power Virtual Server networks](https://cloud.ibm.com/docs/power-iaas?format=markdown) |
| [Power Virtual Server network address groups](https://cloud.ibm.com/docs/power-iaas?format=markdown) |
| [Power Virtual Server network security groups](https://cloud.ibm.com/docs/power-iaas?format=markdown) |
| [Power Virtual Server instances](https://cloud.ibm.com/docs/power-iaas?format=markdown) |
| [Power Virtual Server volumes](https://cloud.ibm.com/docs/power-iaas?format=markdown) |
| [Virtual Network Interfaces for VPC](https://cloud.ibm.com/docs/vpc?group=virtual-network-interfaces&format=markdown) |
| [IBM Cloud Schematics](https://cloud.ibm.com/docs/schematics?format=markdown) |
| [IBM Cloud Schematics Workspace](https://cloud.ibm.com/docs/schematics?format=markdown) |
| [Billing](https://cloud.ibm.com/docs/account?topic=account-overview-billing&format=markdown) |
| [Global catalog collections](https://cloud.ibm.com/docs/account?topic=account-restrict-by-user&interface=ui&format=markdown) |
| [IAM Access Management](https://cloud.ibm.com/docs/iam?topic=iam-cloudaccess&format=markdown) |
| [IAM groups](https://cloud.ibm.com/docs/account?topic=account-account-services&interface=ui&format=markdown) |
| [IAM identity](https://cloud.ibm.com/docs/iam?topic=iam-identities&format=markdown) |
| [User management](https://cloud.ibm.com/docs/account?topic=account-iamuserinv&format=markdown) |
| [watsonx.ai Runtime](https://dataplatform.cloud.ibm.com/docs/content/wsj/analyze-data/ml-overview.html?context=cpdaas&format=markdown) |
{: caption="List of services supported by Configuration Aggregator" caption-side="bottom"}

Databases for EnterpriseDB (EDB) and Databases for etcd are deprecated and are no longer supported by Configuration Aggregator.
{: note}

Effective 20 March 2026, Hyper Protect Crypto Services will be deprecated. You will not be able to create any new instances starting 28 March 2026. All instances will be terminated by 20 March 2027.
{: note}