The page has been translated by Gen AI.

How-to guides

The user can input the necessary information for the Config Inspection service and create the service by selecting detailed options through the Samsung Cloud Platform Console.

Create a certificate

To create and use the Config Inspection service in the Samsung Cloud Platform Console, authentication key creation is required in advance.

API key creation is available at My menu > My Info. > API key management > API key creation. For more information, please refer to API key management.

Note
  • The expiration period of the authentication key is up to 365 days.
  • To create an authentication key with no expiration date, it must be created as permanent.

Config Inspection creation

You can create and use the Config Inspection service in the Samsung Cloud Platform Console.

Reference
The user must be a member of the AdministratorGroup user group to use the services provided by Config Inspection service normally.

To create a Config Inspection, follow these steps.

  1. Click All Services > Security > Config Inspection menu. It moves to the Service Home page of Config Inspection.

  2. On the Service Home page, click the Config Inspection creation button. It moves to the Config Inspection creation page.

  3. Config Inspection Creation page where you enter the necessary inputs for service creation and select detailed options.

    • Enter Service Information area, enter or select the required information.
    Classification
    Necessity
    Detailed Description
    Diagnosis TypeRequiredConsole
    CloudRequiredSelect cloud to diagnose
    • SCP: Samsung Cloud Platform
    • AWS: Amazon Web Service
    • Azure: Microsoft Azure
    • Detailed input items may vary depending on the selected cloud type
    Diagnosis target > Diagnosis nameRequiredName to distinguish diagnosis target
    • Use the entered value as the resource name
    • Use English, numbers, and special characters (-, _) within 25 characters
    Diagnosis target > Diagnosis accountRequiredDiagnosis target is Console information
    • Select the Account ID to be diagnosed from the list
    • If you select the same Account ID, it will be duplicated and an additional fee will be incurred
    • If you select AWS, enter the Account ID in the diagnosis account (12-digit number)
    • If you select Azure, enter the Subscription ID in the diagnosis account (36 characters including letters, numbers, and special characters)
    Diagnosis Schedule > Check ListMandatoryAutomatically set when Using Diagnosis Schedule is selected
    Diagnosis Schedule > Diagnosis CycleRequiredDiagnosis Cycle Selection
    • Diagnosis is executed on the selected date according to the specified cycle
    • Monthly is selected, diagnosis may not be performed on the selected date
      • Example) Monthly 31st selected - February does not have that date, so diagnosis is not performed
    Diagnosis Schedule > Start TimeMandatoryDiagnosis start time selection
    • Set the hour and minute information to start the diagnosis
    Authentication KeyMandatorySelect the authentication key to use for Open API calls
    • Select button to select the corresponding authentication key from the authentication key list in the Authentication Key Selection popup window
    • If there are no selectable authentication keys, create a new authentication key through the Authentication Key Management button
    Rate PlanSelectionSelect the rate plan to use
    • General: Charges are based on the number of diagnoses
    • Monthly Fee: Charges are based on a fixed monthly amount regardless of the number of diagnoses (up to 30 diagnoses per month)
    • The rate plan cannot be changed after applying for the service
    Table. Config Inspection service information input items
    • Enter Additional Information Please enter or select the required information in the area.
    Classification
    Necessity
    Detailed Description
    TagSelectAdd Tag
    • Up to 50 can be added per resource
    • Click the Add Tag button and enter or select Key, Value
    Table. Additional Information Input Items for Config Inspection
  4. In the Summary panel, check the detailed information and estimated billing amount generated, and click the Create button.

    • Once creation is complete, check the created resource on the Config Inspection list page.

Config Inspection detailed information check

Config Inspection service can check and modify the entire resource list and detailed information. The Config Inspection details page consists of detailed information, tags, and work history tabs.

To check the detailed information of the Config Inspection service, follow the next procedure.

  1. Click on the menu of all services > Security > Config Inspection. It moves to the Service Home page of Config Inspection.
  2. On the Service Home page, click the Config Inspection menu. It moves to the Config Inspection list page.
  3. Config Inspection list page, click on the resource to check the detailed information. Move to the Config Inspection details page.
    • Config Inspection Details page displays status information and additional feature information, and consists of Details, Tags, Work History tabs.
      ClassificationDetailed Description
      StatusConfig Inspection status is displayed
      • Ready: after service creation, when there is no diagnosis request (diagnosis request possible)
      • In Progress: when a diagnosis request is being executed (diagnosis request/service cancellation not possible)
      • Error: when an error occurs in the diagnosis request (diagnosis request possible)
      • Completed: when the diagnosis request is completed normally (diagnosis request possible)
      Diagnostic RequestButton that can perform Console diagnosis
      Service CancellationButton to cancel the service
      Fig. Config Inspection status information and additional features

Detailed Information

On the Config Inspection List page, you can check the detailed information of the selected resource and modify the information if necessary.

DivisionDetailed Description
ServiceService Category
Resource TypeService Name
SRNUnique resource ID in Samsung Cloud Platform
Resource NameResource Title
Resource IDUnique resource ID in the service
CreatorService creator user
Creation TimeTime when the service was created
ModifierService information modified user
Modified TimeTime when service information was modified
Diagnosis TypeService-provided diagnosis type
CloudDiagnostic Target Type
Diagnosis TargetDiagnosis target is Console information
  • Provides diagnosis name and diagnosis account information of the diagnosis target
  • If the diagnosis target is AWS or Azure, you can modify the diagnosis account by clicking the Edit icon
Rate PlanSelected Rate Plan Type
Recently diagnosed timeLast executed diagnosis request time
Recent diagnosis resultLast executed diagnosis request result
  • Completed: The diagnosis request is completed normally
  • Error: The diagnosis request is not completed normally
    • UNAUTHORIZED: Need to check the key authority used for the diagnosis request
    • INVALID_INPUT_VALUE: Need to check the input values such as the diagnosis account
    • CONNECTION_FAIL: Need to check the console access control settings
    • ETC: Need to inquire through the service desk due to other errors such as the diagnosis engine
※ The diagnosis result can be checked in the Security > Config Inspection > Report menu
Authentication KeyRegistered user’s authentication key when the service is created
  • Access Key, User, Status information provided
  • Access Key information and edit icon are displayed only to the user who created the authentication key
    • Edit icon can be clicked to change the authentication key
  • If the authentication key is deleted, it is displayed as - status, and if it is expired, it is displayed as Expired
  • Authentication key information (Access Key, Status) of resources created by other users is displayed as -
Diagnosis ScheduleDisplays the selected diagnosis schedule information
  • If the diagnosis target is SCP, you can change the diagnosis schedule by clicking the Modify icon
Fig. Config Inspection detailed information tab items

Tag

On the Config Inspection 목록 page, you can check the tag information of the selected resource, and add, change, or delete it.

ClassificationDetailed Description
Tag ListTag List
  • Check Key, Value information of the tag
  • Up to 50 tags can be added per resource
  • When entering a tag, search and select from the existing list of created Key and Value
Fig. Config Inspection Tag Tab Items

Work History

Config Inspection 목록 page where you can check the operation history of the selected resource.

DivisionDetailed Description
Work history listResource change history
  • Check work time, resource ID, resource name, work details, event topic, work result, and worker information
Fig. Config Inspection job history tab detailed information items

Config Inspection Resource Management

Config Inspection resource status inquiry and diagnosis request are required in case of Config Inspection list or Config Inspection detail page where work can be performed.

Modifying the authentication key

You can select the authentication key to use for diagnosis by diagnosis target.

To modify the service authentication key, follow these steps.

  1. Click on the menu for all services > Security > Config Inspection. It moves to the Service Home page of Config Inspection.
  2. On the Service Home page, click the Config Inspection menu. It moves to the Config Inspection list page.
  3. Config Inspection list page, click the resource to modify the authentication key. Move to the Config Inspection details page.
  4. Check the authentication key and click the edit icon. The edit authentication key popup window appears.
  5. Modify Authentication Key popup window, select the registered authentication key and click the OK button.
    ClassificationDetailed Description
    Access KeyAccess Key information of the authentication key
    Creation DateAccess Key Creation Date
    Expiration DateAccess Key Expiration Date
    StatusAuthentication key status
    • In use: available status
    • Expired: expiration of usage period status
    Fig. Edit Authentication Key Popup Window Items
Reference
  • If the authentication key is deleted, it will be displayed as - state.
  • Authentication key information (Access Key, status) of resources created by other users will be displayed as -.

Request Diagnosis

You can request a diagnosis from the Console based on the set checklist.

To request a console diagnosis, follow these steps.

  1. Click on the menu for all services > Security > Config Inspection. It moves to the Service Home page of Config Inspection.

  2. On the Service Home page, click the Config Inspection menu. It moves to the Config Inspection list page.

  3. Config Inspection list page, click the resource to request diagnosis. Move to the Config Inspection details page.

  4. Config Inspection details page, click the Diagnosis Request button. Diagnosis Request popup window appears.

  5. Diagnosis Request In the diagnosis request popup window, enter the necessary information for diagnosis and click the Confirm button.

    • Diagnostic Request The items in the popup window vary depending on the Console you select.
      ClassificationDetailed Description
      Console access methodThe method of accessing the Console, with the authentication key method fixed
      Check ListFixed as Best Practice when SCP is selected
      Authentication KeySelect the authentication key created in advance if SCP is selected
      Access KeyIf you selected AWS, enter the Access Key
      Secret KeyIf you choose AWS, enter the Secret Key
      Client IDEnter Client ID if Azure is selected
      Client SecretIf Azure is selected, enter Client Secret
      Tenant IDIf Azure is selected, enter the Tenant ID
      Fig. Diagnostic Request Popup Window Items
  6. Check the Status value on the Config Inspection List page.

    • When the diagnosis request is completed, the status value is displayed as Completed or Error.
    • Completed case, you can check the diagnosis result in the diagnosis result menu. For more information, please refer to Report management.
Reference
For details on the preliminary setup required for running diagnostics by console, see Preparation.

Config Inspection disable

You can cancel the unused Config Inspection service. However, if you cancel Config Inspection, all saved diagnostic data will be deleted.

Caution
  • If you cancel the resource, all diagnostic data will be deleted and you will not be able to view the diagnostic results in the Report.
  • If the status of the Config Inspection service is In Progress, the service cannot be cancelled.

To disable Config Inspection, follow the next procedure.

  1. Click All Services > Security > Config Inspection menu. It moves to the Service Home page of Config Inspection.
  2. On the Service Home page, click the Config Inspection menu. It moves to the Config Inspection list page.
  3. Config Inspection list page, click the resource to be canceled. Move to the Config Inspection details page.
  4. Config Inspection details page, click the service cancellation button.
  5. Once the cancellation is complete, please check if the resource has been cancelled on the Config Inspection list page.
Overview
Dashboard Check