See what is in your AWS accounts, and how it connects.
Config Explorer is a desktop app that reads the AWS Config data you already deliver to S3, for one account or a whole Control Tower organisation. It turns it into an inventory you can filter and group any way you like, a map of how your resources relate, and a change log that tells real edits from noise.
It runs on your machine and reads your bucket directly. Nothing is sent to Cloud Certainty.
WINDOWS DESKTOP APP · READS YOUR CONFIG BUCKET · READ-ONLY · EARLY ACCESS
Sample data. Click through Resources, Relationships and Changes.
[ A ] HOW IT WORKS: FROM CONFIG BUCKET TO RELATIONSHIP MAP
- 01
Point it at your Config bucket
Give it the S3 bucket AWS Config delivers to: one account’s bucket, or a Control Tower log archive with your whole organisation in it. It finds every account and Region under the prefix by itself.
Read-only
It lists and reads Config’s files and nothing else. It never writes to your AWS account.
Your credentials
An AWS profile, an SSO session, or access keys you paste in. Keys are encrypted with your operating system’s keychain.
- 02
See the cost before anything downloads
It prices every sync first: how many files, how many gigabytes, and what S3 will bill for the requests and data transfer. Start with the latest daily snapshots, which hold the full current state, and add as much history as you need.
Priced up front
A worst-case estimate before the first byte, as if your free transfer allowance were already used.
Only what is new
Re-syncs download only the files it has not imported yet.
- 03
Explore the inventory
Filter, group and pivot every resource by any field: type, account, Region, tags, compliance, values inside its configuration, or the resources it relates to. Group by related VPC and the inventory becomes a map of your network.
Fast at organisation scale
Tens of thousands of resources filter and regroup in milliseconds, on your machine.
Saved views and CSV
Keep the views you use, and export exactly what you are looking at.
- 04
Follow the relationships
Open any resource for its configuration, its relationships and every recorded version, or start a graph from it and expand outwards one hop at a time.
More than Config records
Links Config never records are inferred from ARNs and IDs in the configuration and from CloudFormation stacks, and labelled as inferred.
Changes, not noise
Each version says what changed: configuration, tags or relationships, with a field-level diff.
[ B ] WHAT YOU GET
AWS Config already records what exists in your accounts and every change to it. What it does not give you is a way to look at it: a question like “which non-compliant resources sit in the production VPC, and what changed on them this week” means stitching JSON files together. Config Explorer answers it in a few clicks.
- Group table
- Any field as a filter, a grouping or a column: tags, related resources and configuration values included. Every filter shows how many resources each value would match.
- Relationships
- Recorded by AWS Config, referenced in a resource’s configuration, or managed by the same CloudFormation stack. Resources with thousands of links fold, so a graph stays readable.
- Change history
- Every recorded version, marked as a configuration, tag or relationship change. Most VPC and subnet versions are ENIs coming and going; real edits stand out.
- Compliance
- AWS Config rule results on every resource. Filter to non-compliant and see which rules fail.
- Organisations
- Every member account of a Control Tower log archive in one inventory, named from AWS Organizations.
- Housekeeping
- Keep the last few days of history and drop the rest, or remove a source and everything it brought in. The database shrinks to match.
- orders-api-tg TargetGroup inferred
- prod-private-a Subnet inferred
- prod-private-b Subnet inferred
- orders-api-sg SecurityGroup inferred
- orders-cluster ECS Cluster inferred
- orders-api:42 TaskDefinition inferred
- orders-task-role IAM Role inferred
- orders-stack CloudFormation Stack CloudFormation
[ C ] DATA AND COST
The full current state of an eight-account AWS organisation we tested, against 3.7 GB for all of its history. Start from the snapshots, then add as many days of history as the questions you ask need.
What it reads
The files AWS Config writes to S3: daily snapshots, change history, and optionally oversized change notifications with Config’s own diff.
What it needs
s3:ListBucket and s3:GetObject on the Config prefix, plus kms:Decrypt if the bucket uses a customer-managed key. No write access to anything.
What it costs to run
S3 bills the bucket owner for the requests and the data transferred. The app shows the estimate before every sync. Syncing the snapshots of that eight-account organisation costs under a cent.
Where your data lives
In a local database on your machine. Credentials are encrypted with the operating system’s keychain. Nothing is sent to Cloud Certainty.
Amazon Web Services, AWS, AWS Config, AWS Control Tower, AWS Organizations and Amazon S3 are trademarks of Amazon.com, Inc. or its affiliates. Cloud Certainty Config Explorer is a product of Cloud Certainty OÜ and is not affiliated with or endorsed by Amazon.