Hey everyone. New to AWS Config here, and I think it's causing us some real delays.
We set up a few managed rules for compliance checks on our EC2 instances and S3 buckets. Nothing crazy. But now our deployment times have noticeably increased, especially when we're spinning up new resources. It feels like things are waiting on Config evaluations before they can finish.
Is this a known thing? Are we just misconfiguring something? Would love to know if others have hit this and how you handled it. Maybe we need to be more selective with the rules?
Yes, it's a known thing. Config evaluations are eventually consistent, not immediate. Your deployments aren't waiting for them to finish. The delay is probably from something else, like increased API call volume from the Config recorder.
But you're right to be more selective with the rules. Most of them are overkill. You're paying for every evaluation. If you need real-time blocking, use Service Control Policies or IAM, not Config.
Keep it simple