Governance and Management Services
Config, Control Tower, Systems Manager, Service Catalog, License Manager, Compute Optimizer, Resource Groups, Launch Wizard, Health and Audit Manager.
What is it?
As accounts and resources multiply, you need to keep them compliant, tidy and efficient. These services help you govern (set and check rules) and manage (operate and optimise) your environment. They complement CloudWatch, CloudTrail and Trusted Advisor from the monitoring lesson.
- AWS Config: records resource configuration over time and evaluates it against rules (for example 'all S3 buckets must be encrypted').
- AWS Control Tower: sets up and governs a secure multi-account environment (a landing zone) with guardrails built on Organizations and SCPs.
- AWS Systems Manager: operations hub for fleets - Session Manager (shell without opening SSH), Patch Manager, Run Command, Parameter Store and Inventory.
- AWS Service Catalog: a catalog of pre-approved products (CloudFormation templates) that users can launch without broad permissions.
- AWS License Manager: tracks software licenses and enforces usage limits across AWS and on-premises.
- AWS Compute Optimizer: analyses utilisation and recommends right-sized EC2, EBS, Lambda and other resources.
- AWS Resource Groups and Tag Editor: group resources by tags and bulk-edit tags across Regions.
- AWS Launch Wizard: guided deployment of enterprise workloads such as SQL Server or SAP on AWS following best practices.
- AWS Health Dashboard: personal view of events affecting your resources (plus the AWS Health API to integrate alerts) and a service-health view of AWS overall.
- AWS Audit Manager: continuously collects evidence to help prepare for audits against frameworks.
- IAM access reports: last-accessed data and credential reports that show unused permissions.
Remember the split: CloudTrail answers who did what, Config answers what does it look like and was it compliant, CloudWatch answers how is it performing.
Explain like I'm 10
Running many AWS accounts is like managing an apartment building. Control Tower is the building code, Config is the inspector comparing each flat to it, Systems Manager is the maintenance crew with master keys, Service Catalog is the approved furniture list, Compute Optimizer suggests which flats are too big for their tenants, and Health Dashboard is the notice board of repairs affecting your floor.
Examples
A Config rule check from the CLI
# Which resources break the managed rule that requires S3 encryption?
aws configservice get-compliance-details-by-config-rule \
--config-rule-name s3-bucket-server-side-encryption-enabled \
--compliance-types NON_COMPLIANTConfig keeps a history, so you can see not only the current state but also when a resource drifted out of compliance.
Tag standard that Resource Groups can use
Key Value
------------- ------------------
Environment prod | staging | dev
CostCenter 4213
Owner payments-team
Application checkoutConsistent tags let Resource Groups, Tag Editor and cost allocation reports slice resources the same way.
How it works
Config takes a snapshot of a resource whenever it changes, stores it as a configuration item, and runs managed or custom rules against it, optionally triggering remediation. Control Tower applies preventive guardrails (SCPs) and detective guardrails (Config rules) to accounts it provisions. Systems Manager uses an agent on instances (or managed nodes) so you can patch and run commands without inbound ports.
Compute Optimizer reads CloudWatch utilisation metrics and uses machine learning to suggest cheaper or better-fitting resource types. Health Dashboard pushes events (maintenance, outages) that affect your own resources, and the Health API can feed them to chat or ticketing tools.
Organizations ── Control Tower (landing zone + guardrails)
|
accounts ── Config (what changed / compliant?) ── Audit Manager (evidence)
|
fleets ──── Systems Manager (patch, run, session, parameters)
|
cost/size ─ Compute Optimizer, License Manager, tags + Resource Groups
alerts ──── Health Dashboard / Health APIWhy does it exist?
Manual checks do not scale across hundreds of resources and many accounts. These services automate compliance checking, standard setup, patching and optimisation so governance is continuous instead of an annual scramble.
When to use it
Use Config for compliance rules and change history, Control Tower to start a multi-account setup, Systems Manager to patch and administer instances, Service Catalog to offer approved stacks, Compute Optimizer to rightsize, License Manager to track licenses, and Health Dashboard to stay ahead of events affecting you.
When not to use it
Do not use Config as a performance monitor (CloudWatch) or as an API audit log (CloudTrail). Do not use Control Tower for a single small account where plain Organizations or IAM rules suffice.
Common mistakes
Confusing Config (resource configuration and compliance) with CloudTrail (API activity).
Opening SSH ports for administration when Systems Manager Session Manager avoids it.
Believing Compute Optimizer changes resources for you - it only recommends.
Not tagging resources, which makes Resource Groups and cost allocation weak.
Practice exercises
- Easy:
For each of the eleven services, write one sentence on its job.
- Medium:
Explain how Config, CloudTrail and CloudWatch each help investigate an unexpectedly open S3 bucket.
- Medium:
Define a tagging standard for a company and say which services benefit from it.
- Hard:
Plan a landing zone for production, development and security accounts using Control Tower guardrails.
Interview questions
Exam-style: Which service evaluates resource configurations against desired rules and records changes over time?
AWS Config.
Exam-style: Which service sets up a governed multi-account environment with guardrails?
AWS Control Tower.
Exam-style: Which service lets administrators patch and run commands on many instances without SSH?
AWS Systems Manager.
Exam-style: Which service provides recommendations to rightsize EC2 instances?
AWS Compute Optimizer.
Exam-style: Which service lets administrators offer approved, pre-configured products to users?
AWS Service Catalog.
Exam-style: Which service shows events that affect your specific AWS resources?
AWS Health Dashboard (Personal Health).
Exam-style: Which service helps collect evidence for audits?
AWS Audit Manager.
Exam-style: Which service tracks software license usage?
AWS License Manager.