Amazon Web Services announces declarative policies
Share
Services
Today, AWS announces the general availability of declarative policies, a new management policy type within AWS Organizations. These policies simplify the way customers enforce durable intent, such as baseline configuration for AWS services within their organization. For example, customers can configure EC2 to allow instance launches using AMIs vended by specific providers and block public access in their VPC with a few simple clicks or commands for their entire organization using declarative policies.
Declarative policies are designed to prevent actions that are non-compliant with the policy. The configuration defined in the declarative policy is maintained even when services add new APIs or features, or when customers add new principals or accounts to their organization. With declarative policies, governance teams have access to the account status report which provides insight into the current configuration for an AWS service across their organization. This helps them asses readiness to enforce configuration at scale. Administrators can provide additional transparency to end users by configuring custom error messages to redirect them to internal wikis or ticketing systems through declarative policies.
To get started, navigate to the AWS Organizations console to create and attach declarative policies. You can also use AWS Control Tower, AWS CLI or CloudFormation templates to configure these policies. Declarative policies today support EC2, EBS and VPC configurations with support for other services coming soon. To learn more see [documentation](https://docs.aws.amazon.com/organizations/latest/userguide/orgs%5Fmanage%5Fpolicies%5Fdeclarative.html) and [blog post](https://aws.amazon.com/blogs/aws/simplify-governance-with-declarative-policies).
What else is happening at Amazon Web Services?
Amazon Bedrock Knowledge Bases now supports streaming responses
about 20 hours ago
Services
Share
Amazon Connect now provides the ability to record audio during IVR and other automated interactions
about 20 hours ago
Services
Share
Read update
Services
Share
Amazon Connect launches AI assistant for customer segments and trigger-based campaigns
about 20 hours ago
Services
Share
Announcing the general availability of Amazon MemoryDB Multi-Region
about 20 hours ago
Services
Share