[ P2 ] PRODUCT: AWS CONFIG EXPLORER

See what is in your AWS accounts, and how it connects.

Config Explorer is a desktop app that reads the AWS Config data you already deliver to S3, for one account or a whole Control Tower organisation. It turns it into an inventory you can filter and group any way you like, a map of how your resources relate, and a change log that tells real edits from noise.

It runs on your machine and reads your bucket directly. Nothing is sent to Cloud Certainty.

WINDOWS DESKTOP APP · READS YOUR CONFIG BUCKET · READ-ONLY · EARLY ACCESS

CONFIG EXPLORER
⌕ Search name, id, ARN, tags… LIFECYCLE is not deleted TYPE is not ResourceCompliance + FILTER
GROUP BY Related VPC + LEVEL COLUMNS · 5 VIEWS CSV
NAME TYPE ACCOUNT COMPLIANCE
orders-alb LoadBalancer prod 1 NON-COMPLIANT
orders-db RDS DBInstance prod 2 COMPLIANT
prod-private-a Subnet prod 1,284 COMPLIANT
prod-private-b Subnet prod 1,206 COMPLIANT
orders-api-sg SecurityGroup prod 418 NON-COMPLIANT
invoice-worker Lambda Function prod 5 COMPLIANT
13 resources · 3 groups · 21 ms Click orders-api to see what it connects to.

Sample data. Click through Resources, Relationships and Changes.

[ A ] HOW IT WORKS: FROM CONFIG BUCKET TO RELATIONSHIP MAP

  1. 01

    Point it at your Config bucket

    Give it the S3 bucket AWS Config delivers to: one account’s bucket, or a Control Tower log archive with your whole organisation in it. It finds every account and Region under the prefix by itself.

    Read-only

    It lists and reads Config’s files and nothing else. It never writes to your AWS account.

    Your credentials

    An AWS profile, an SSO session, or access keys you paste in. Keys are encrypted with your operating system’s keychain.

  2. 02

    See the cost before anything downloads

    It prices every sync first: how many files, how many gigabytes, and what S3 will bill for the requests and data transfer. Start with the latest daily snapshots, which hold the full current state, and add as much history as you need.

    Priced up front

    A worst-case estimate before the first byte, as if your free transfer allowance were already used.

    Only what is new

    Re-syncs download only the files it has not imported yet.

  3. 03

    Explore the inventory

    Filter, group and pivot every resource by any field: type, account, Region, tags, compliance, values inside its configuration, or the resources it relates to. Group by related VPC and the inventory becomes a map of your network.

    Fast at organisation scale

    Tens of thousands of resources filter and regroup in milliseconds, on your machine.

    Saved views and CSV

    Keep the views you use, and export exactly what you are looking at.

  4. 04

    Follow the relationships

    Open any resource for its configuration, its relationships and every recorded version, or start a graph from it and expand outwards one hop at a time.

    More than Config records

    Links Config never records are inferred from ARNs and IDs in the configuration and from CloudFormation stacks, and labelled as inferred.

    Changes, not noise

    Each version says what changed: configuration, tags or relationships, with a field-level diff.

[ B ] WHAT YOU GET

AWS Config already records what exists in your accounts and every change to it. What it does not give you is a way to look at it: a question like “which non-compliant resources sit in the production VPC, and what changed on them this week” means stitching JSON files together. Config Explorer answers it in a few clicks.

Group table
Any field as a filter, a grouping or a column: tags, related resources and configuration values included. Every filter shows how many resources each value would match.
Relationships
Recorded by AWS Config, referenced in a resource’s configuration, or managed by the same CloudFormation stack. Resources with thousands of links fold, so a graph stays readable.
Change history
Every recorded version, marked as a configuration, tag or relationship change. Most VPC and subnet versions are ENIs coming and going; real edits stand out.
Compliance
AWS Config rule results on every resource. Filter to non-compliant and see which rules fail.
Organisations
Every member account of a Control Tower log archive in one inventory, named from AWS Organizations.
Housekeeping
Keep the last few days of history and drop the rest, or remove a source and everything it brought in. The database shrinks to match.
RELATIONSHIPS ecs service: orders-api
0recorded by AWS Config
8shown in Config Explorer
  • orders-api-tg TargetGroup inferred
  • prod-private-a Subnet inferred
  • prod-private-b Subnet inferred
  • orders-api-sg SecurityGroup inferred
  • orders-cluster ECS Cluster inferred
  • orders-api:42 TaskDefinition inferred
  • orders-task-role IAM Role inferred
  • orders-stack CloudFormation Stack CloudFormation
An example. Config records no relationships for ECS services; these come from ARNs and IDs in the service’s configuration and from its CloudFormation stack.

[ C ] DATA AND COST

4 MB
LATEST SNAPSHOTS · EIGHT-ACCOUNT ORGANISATION

The full current state of an eight-account AWS organisation we tested, against 3.7 GB for all of its history. Start from the snapshots, then add as many days of history as the questions you ask need.

What it reads

The files AWS Config writes to S3: daily snapshots, change history, and optionally oversized change notifications with Config’s own diff.

What it needs

s3:ListBucket and s3:GetObject on the Config prefix, plus kms:Decrypt if the bucket uses a customer-managed key. No write access to anything.

What it costs to run

S3 bills the bucket owner for the requests and the data transferred. The app shows the estimate before every sync. Syncing the snapshots of that eight-account organisation costs under a cent.

Where your data lives

In a local database on your machine. Credentials are encrypted with the operating system’s keychain. Nothing is sent to Cloud Certainty.

Amazon Web Services, AWS, AWS Config, AWS Control Tower, AWS Organizations and Amazon S3 are trademarks of Amazon.com, Inc. or its affiliates. Cloud Certainty Config Explorer is a product of Cloud Certainty OÜ and is not affiliated with or endorsed by Amazon.

Tell us what you have. We'll make it better and cheaper.

Send a short description of your current setup. We will tell you what we would improve, what it would cost, and where the savings are. A considered reply from an engineer, not a sales sequence.

TELL US ABOUT YOUR SETUP →