Configuration Aggregator
Configuration Aggregator can be used to facilitate a Cloud Governance SME with up-to-date configuration data of IBM Cloud resources in one place so that comprehensive information is available for governance and compliance initiatives. All the plans of the App Configuration service except the Lite plan will have the Configuration Aggregator feature available. As an app owner, the user has to explicitly enable the Configuration Aggregator. It can be done on the App Configuration instance either via API, SDK, or console. The App Configuration service will start the resource collection and periodically reconcile to keep the metadata current. Users can use the query API to get the updated metadata of the service instances in the account.
Configuration Aggregator feature can be configured on an App Configuration instance at Enterprise account level to collect resource metadata from all the sub-accounts of the enterprise. A trusted profile template should be created providing access to App Configuration service instance to all the IAM enabled services. The trusted profile template should then be assigned to the required accounts in the Enterprise, which in turn creates the trusted profile in the respective sub-accounts providing access to App Configuration service instance to collect resource metadata.
By default, recording is always set to be OFF.
Resource configuration collection
Configuration Aggregator uses two methods to collect and maintain up-to-date resource configuration:
-
Scheduled reconciliation - Periodic collection of resource configuration at scheduled intervals to ensure the configuration database remains current. Manual reconciliation (on-demand refresh outside the scheduled interval) is available only on the Enterprise plan.
-
Real-time configuration collection - Event-driven collection triggered by configuration changes detected through Activity Tracker events, enabling faster detection and remediation of security and compliance issues. Real-time resource collection is available only on the Standard and Enterprise plans. For more information about enabling real-time resource collection, see Enabling real-time configuration collection.
Configuration aggregator used with Security and Compliance Center Workload Protection
The Configuration aggregator is the data source used by Security and Compliance Center Workload Protection to perform cloud security posture management (CSPM) of IBM Cloud resources. When configuring IBM Cloud CSPM within Workload Protection, an instance of App Configuration with aggregation enabled is automatically connected to Workload Protection. You do need to explicitly enable recording as mentioned above. New instances of App Configuration created through workload protection are provisioned into the Basic Plan by default. Aggregation within the Basic plan is free and will not add to the cost of Workload Protection.
When Context Based Restrictions are enabled for any resource in your IBM Cloud account, configuration cannot be collected unless access to that resource is provided. To provide access, you need to create a rule. When asked to add a context,
create a network zone and select App Configuration as the reference service.
Enable Configuration aggregator - Single Account
To enable configuration aggregator, complete these steps:
-
In the App Configuration console, click Configuration aggregator.
-
Click Define an aggregation. The side panel opens with fields for setting up recording details.
-
Select either all regions or specific regions from the region list. Click Save to complete. This will create a Trusted Profile on the App Configuration instance with reader access for reading the configurations of the resources.
-
Click the toggle button to enable recording. A confirmation prompt will appear. Click Turn on.
Enable Configuration aggregator - Enterprise Account
To enable the Configuration Aggregator feature for an enterprise account, users must complete the following prerequisites:
-
Create an App Configuration instance at the top-level of the enterprise, i.e., the enterprise account.
-
Create a Trusted Profile Template providing access for the App Configuration service instance to the IAM enabled services and Account Management services. Refer to Creating Trusted Profile
The trusted profile template cannot be assigned to the enterprise account, i.e., the top level account of the enterprise. If you choose to collect metadata of resources in the enterprise account, you should create a separate trusted profile that should be applied at the top level account additionally.
- Assign the Trusted profile template to the required accounts and account groups in the Enterprise.
The Enterprise IAM should be enabled in the sub-accounts of an Enterprise to be managed via Enterprise. For more details, refer to Opting in to enterprise-managed IAM
To enable configuration aggregator for an enterprise account, complete the pre-requisites and following steps:
-
In the App Configuration console, click Configuration aggregator.
-
Click Define an aggregation. The side panel opens with fields for setting up recording details.
-
Provide the details required to set up recording:
- Region - regions from which the user wants to collect configuration data.
- Enterprise ID - enterprise account id.
- Trusted template ID - trusted profile template id created as pre-requisite.
- Trusted profile ID - trusted profile id created as pre-requisite.
-
Click Save.
-
Click the toggle button to enable recording. A confirmation prompt will appear. Click Turn on.
Enable Recording - Enterprise Account
Billing and metering for Configuration Aggregator
When you enable Configuration Aggregator on a Standard or Enterprise plan App Configuration instance, usage is measured and billed against two metrics.
| Metric | What is measured |
|---|---|
| Config items | The total number of IBM Cloud resource configurations stored in the aggregator for your account. Each unique resource configuration record counts as one config item. |
| Accounts reconciled | The number of accounts whose resource configurations are actively reconciled by the aggregator. For stand-alone accounts this is always 1. For enterprise instances it is 1 (the parent account) plus the number of active sub-accounts included in the collection. |
Accounts reconciled billing
For each billing period, the maximum number of accounts reconciled across all runs in that period is used as the billed quantity. This means:
- Adding a sub-account mid-period increases the count from the next billing run onward.
- Removing a sub-account mid-period does not reduce the billed quantity for that period.
Plan changes
If your App Configuration plan changes during a billing period, usage is tracked independently for each plan. Each plan's usage is submitted to billing separately.
Enterprise accounts
For enterprise instances, all active sub-accounts included in the collection are counted toward the accounts reconciled metric. Config items from all sub-accounts are aggregated and counted toward the config items metric for the parent instance.
Viewing your usage
You can view Config Aggregator usage metrics on the IBM Cloud Billing and Usage dashboard.
Retrieve Resource Metadata
You can query for the configurations of IBM Cloud resources using the list API. It provides detailed metadata of the resources when Configuration Aggregator is enabled for an App Configuration instance.
List of Services Supported by Configuration Aggregator
Configuration Aggregator supports the following services:
Databases for EnterpriseDB (EDB) and Databases for etcd are deprecated and are no longer supported by Configuration Aggregator.
Effective 20 March 2026, Hyper Protect Crypto Services will be deprecated. You will not be able to create any new instances starting 28 March 2026. All instances will be terminated by 20 March 2027.