Configuration Aggregator

Configuration Aggregator can be used to facilitate a Cloud Governance SME with up-to-date configuration data of IBM Cloud resources in one place so that comprehensive information is available for governance and compliance initiatives. All the plans of the App Configuration service except the Lite plan will have the Configuration Aggregator feature available. As an app owner, the user has to explicitly enable the Configuration Aggregator. It can be done on the App Configuration instance either via API, SDK, or console. The App Configuration service will start the resource collection and periodically reconcile to keep the metadata current. Users can use the query API to get the updated metadata of the service instances in the account.

Configuration Aggregator feature can be configured on an App Configuration instance at Enterprise account level to collect resource metadata from all the sub-accounts of the enterprise. A trusted profile template should be created providing access to App Configuration service instance to all the IAM enabled services. The trusted profile template should then be assigned to the required accounts in the Enterprise, which in turn creates the trusted profile in the respective sub-accounts providing access to App Configuration service instance to collect resource metadata.

By default, recording is always set to be OFF.

Resource configuration collection

Configuration Aggregator uses two methods to collect and maintain up-to-date resource configuration:

  • Scheduled reconciliation - Periodic collection of resource configuration at scheduled intervals to ensure the configuration database remains current. Manual reconciliation (on-demand refresh outside the scheduled interval) is available only on the Enterprise plan.

  • Real-time configuration collection - Event-driven collection triggered by configuration changes detected through Activity Tracker events, enabling faster detection and remediation of security and compliance issues. Real-time resource collection is available only on the Standard and Enterprise plans. For more information about enabling real-time resource collection, see Enabling real-time configuration collection.

Default Configuration Aggregator
Default Configuration Aggregator

Configuration aggregator used with Security and Compliance Center Workload Protection

The Configuration aggregator is the data source used by Security and Compliance Center Workload Protection to perform cloud security posture management (CSPM) of IBM Cloud resources. When configuring IBM Cloud CSPM within Workload Protection, an instance of App Configuration with aggregation enabled is automatically connected to Workload Protection. You do need to explicitly enable recording as mentioned above. New instances of App Configuration created through workload protection are provisioned into the Basic Plan by default. Aggregation within the Basic plan is free and will not add to the cost of Workload Protection.

When Context Based Restrictions are enabled for any resource in your IBM Cloud account, configuration cannot be collected unless access to that resource is provided. To provide access, you need to create a rule. When asked to add a context, create a network zone and select App Configuration as the reference service.

CBR
CBR for Configuration Aggregator

Enable Configuration aggregator - Single Account

To enable configuration aggregator, complete these steps:

  1. In the App Configuration console, click Configuration aggregator.

  2. Click Define an aggregation. The side panel opens with fields for setting up recording details.

Enable Configuration Aggregator - Set up recording
Set up recording - Single Account

  1. Select either all regions or specific regions from the region list. Click Save to complete. This will create a Trusted Profile on the App Configuration instance with reader access for reading the configurations of the resources.

  2. Click the toggle button to enable recording. A confirmation prompt will appear. Click Turn on.

Enable Configuration Aggregator - Enable recording
Enable Recording - Single Account

Enable Configuration aggregator - Enterprise Account

To enable the Configuration Aggregator feature for an enterprise account, users must complete the following prerequisites:

  1. Create an App Configuration instance at the top-level of the enterprise, i.e., the enterprise account.

  2. Create a Trusted Profile Template providing access for the App Configuration service instance to the IAM enabled services and Account Management services. Refer to Creating Trusted Profile

Enable Configuration Aggregator - Trusted Profile Template
Trusted Profile Template - Enterprise Account

The trusted profile template cannot be assigned to the enterprise account, i.e., the top level account of the enterprise. If you choose to collect metadata of resources in the enterprise account, you should create a separate trusted profile that should be applied at the top level account additionally.

  1. Assign the Trusted profile template to the required accounts and account groups in the Enterprise.

The Enterprise IAM should be enabled in the sub-accounts of an Enterprise to be managed via Enterprise. For more details, refer to Opting in to enterprise-managed IAM

To enable configuration aggregator for an enterprise account, complete the pre-requisites and following steps:

  1. In the App Configuration console, click Configuration aggregator.

  2. Click Define an aggregation. The side panel opens with fields for setting up recording details.

Enable Configuration Aggregator - Set up recording - Enterprise Account
Set up recording - Enterprise Account

  1. Provide the details required to set up recording:

    • Region - regions from which the user wants to collect configuration data.
    • Enterprise ID - enterprise account id.
    • Trusted template ID - trusted profile template id created as pre-requisite.
    • Trusted profile ID - trusted profile id created as pre-requisite.
  2. Click Save.

  3. Click the toggle button to enable recording. A confirmation prompt will appear. Click Turn on.

    Enable Configuration Aggregator - Enable Recording - Enterprise Account
    Enable Recording - Enterprise Account

Billing and metering for Configuration Aggregator

When you enable Configuration Aggregator on a Standard or Enterprise plan App Configuration instance, usage is measured and billed against two metrics.

Configuration Aggregator billing metrics
Metric What is measured
Config items The total number of IBM Cloud resource configurations stored in the aggregator for your account. Each unique resource configuration record counts as one config item.
Accounts reconciled The number of accounts whose resource configurations are actively reconciled by the aggregator. For stand-alone accounts this is always 1. For enterprise instances it is 1 (the parent account) plus the number of active sub-accounts included in the collection.

Accounts reconciled billing

For each billing period, the maximum number of accounts reconciled across all runs in that period is used as the billed quantity. This means:

  • Adding a sub-account mid-period increases the count from the next billing run onward.
  • Removing a sub-account mid-period does not reduce the billed quantity for that period.

Plan changes

If your App Configuration plan changes during a billing period, usage is tracked independently for each plan. Each plan's usage is submitted to billing separately.

Enterprise accounts

For enterprise instances, all active sub-accounts included in the collection are counted toward the accounts reconciled metric. Config items from all sub-accounts are aggregated and counted toward the config items metric for the parent instance.

Viewing your usage

You can view Config Aggregator usage metrics on the IBM Cloud Billing and Usage dashboard.

Retrieve Resource Metadata

You can query for the configurations of IBM Cloud resources using the list API. It provides detailed metadata of the resources when Configuration Aggregator is enabled for an App Configuration instance.

List of Services Supported by Configuration Aggregator

Configuration Aggregator supports the following services:

List of services supported by Configuration Aggregator
Name of service Real-time resource collection support
Cloud Object Storage Checkmark icon
Kubernetes Service
Red Hat OpenShift
Virtual server for VPC
Virtual Private Cloud
Block storage volume for VPC Checkmark icon
Block storage snapshots for VPC Checkmark icon
Secrets Manager Checkmark icon
Databases for PostgreSQL
Databases for Redis
Databases for ElasticSearch
Databases for MongoDB Checkmark icon
Databases for MySQL
Identity and Access Management (IAM)
Key Protect
Container Registry
Load Balancer for VPC
Security Group for VPC
SSH Keys for VPC Checkmark icon
Subnet for VPC Checkmark icon
Virtual Private Endpoint (VPE) for VPC Checkmark icon
Auto Scale (Instance Group) for VPC
Bare Metal servers for VPC
Client VPN for VPC
Dedicated Host for VPC
Floating IP for VPC
Flow Logs - VPC Checkmark icon
Custom image for VPC Checkmark icon
Placement Groups for VPC
Code Engine
Network ACL - VPC Checkmark icon
DNS Service - VPC
VPN for VPC Checkmark icon
IBM Cloud Backup - VPC
Public Gateway Checkmark icon
Event Streams (messagehub)
IBM Cloud Direct Link
Transit Gateway
Toolchain Checkmark icon
IBM Cloudant
IBM Cloud Internet Services (CIS) Checkmark icon
IBM Cloud Logs
IBM Cloud Logs Router Checkmark icon
IBM Cloud Shell Checkmark icon
IBM Cloud Monitoring Checkmark icon
Security and Compliance Center (SCC)
SCC Workload Protection Checkmark icon
Hyper Protect Crypto Services (HPCS) Checkmark icon
App ID
App Configuration Checkmark icon
Catalog Management
Event Notifications
Messages for RabbitMQ
IBM Cloud Projects Checkmark icon
IBM Cloud Activity Tracker Event Routing Checkmark icon
Enterprise
IBM Power Virtual Server
Power Virtual Server networks
Power Virtual Server network address groups
Power Virtual Server network security groups
Power Virtual Server instances
Power Virtual Server volumes
Virtual Network Interfaces for VPC
IBM Cloud Schematics Checkmark icon
Billing Checkmark icon
Global catalog collections
IAM Access Management
IAM groups
IAM identity
User management
watsonx.ai Runtime

Databases for EnterpriseDB (EDB) and Databases for etcd are deprecated and are no longer supported by Configuration Aggregator.

Effective 20 March 2026, Hyper Protect Crypto Services will be deprecated. You will not be able to create any new instances starting 28 March 2026. All instances will be terminated by 20 March 2027.