The page has been translated by Gen AI.

How-to guides

The user can enter the required information for the Config Inspection service through the Samsung Cloud Platform Console, select detailed options, and create the service.

Create Certificate

To create and use the Config Inspection service on the Samsung Cloud Platform Console, a prior authentication key generation is required.

Authentication key creation can be done from My Menu > My Info. > Authentication Key Management > Create Authentication Key. For more details, refer to Authentication Key Management.

Reference
  • The expiration period of the authentication key is up to 365 days.
  • To create an authentication key without an expiration date, you must create it permanently.

Config Inspection Create

You can create and use the Config Inspection service in the Samsung Cloud Platform Console.

Reference
The user must belong to the AdministratorGroup user group in order to use the services provided by the Config Inspection service properly.

To create a Config Inspection, follow these steps.

  1. All Services > Security > Config Inspection Click the menu. Navigate to Config Inspection’s Service Home page.
  2. On the Service Home page, click the Create Config Inspection button. You will be taken to the Create Config Inspection page.
  3. Config Inspection creation On the page, enter the inputs required to create the service, and select detailed options.
    • Service Information Input Enter or select the required information in the area.
      Category
      Required or not
      Detailed description
      Diagnosis Type-Automatically set with Console
      CloudRequiredSelect cloud to diagnose
      • SCP: Samsung Cloud Platform
      • AWS: Amazon Web Services
      • Azure: Microsoft Azure
      • Detailed input fields vary depending on the selected cloud type
      Diagnosis Target > Diagnosis NameRequiredName to distinguish the diagnosis target
      • Use the entered value as the resource name
      • Enter within 25 characters using English letters, numbers, and special characters(-, _)
      Diagnostic Target > Diagnostic AccountRequiredConsole information for the diagnostic target
      • Select the Account ID to diagnose from the list
      • If the same Account ID is selected, duplicate application occurs and additional charges will be incurred
      • If AWS is selected, enter the Account ID (12 digits) in the diagnostic account
      • If Azure is selected, enter the Subscription ID (36 characters including letters, numbers, and special characters) in the diagnostic account
      Diagnosis Schedule > ChecklistRequiredAutomatically set when Use Diagnosis Schedule is selected
      Diagnosis Schedule > Diagnosis CycleRequiredSelect Diagnosis Cycle
      • The diagnosis is executed on the selected date according to the specified cycle
      • Monthly is selected, the diagnosis may not be performed on the selected date
        • e.g., selecting the 31st of each month – February has no such date, so the diagnosis is not performed
      Diagnosis Schedule > Start TimeRequiredSelect Diagnosis Start Time
      • Set the hour and minute information to start the diagnosis
      Authentication KeyRequiredSelect authentication key to use for Open API calls
      • Click the **Select** button and choose the appropriate authentication key from the list in the **Select Authentication Key** popup.
      • If there are no selectable authentication keys, click **Authentication Key Management** to create a new authentication key.
      • For detailed information about authentication keys, refer to [Manage Authentication Keys](/userguide/management/iam/how_to_guides/myinfo.md/#인증키-관리하기).
      | Plan | Select | Select the plan to use
      • **Standard**: charge based on the number of diagnoses
      • **Monthly flat-rate**: charge a fixed amount each month regardless of the number of diagnoses (based on up to 30 diagnoses per month)
      • The plan cannot be changed after service application
      |
      Table. Config Inspection Service Information Input Items
    • Additional Information Input area, enter or select the required information.
      Category
      Required or not
      Detailed description
      TagSelectAdd Tag
      • Up to 50 can be added per resource
      • After clicking the Add Tag button, enter or select Key, Value values
      Table. Config Inspection Additional Information Input Items
  4. Summary In the panel, check the detailed information and estimated billing amount you created, and click the Create button.
  • When creation is complete, check the created resources on the Config Inspection List page.

Config Inspection Check detailed information

Config Inspection service allows you to view and edit the full resource list and detailed information. Config Inspection detailed page consists of Details, Tags, Work History tabs.

To view detailed information of the Config Inspection service, follow the steps below.

  1. All Services > Security > Config Inspection Click the menu. Navigate to Config Inspection’s Service Home page.
  2. Click the Config Inspection menu on the Service Home page. You will be taken to the Config Inspection list page.
  3. On the Config Inspection List page, click the resource to view detailed information. You will be taken to the Config Inspection Details page.
    • Config Inspection Detailed page displays status information and additional feature information, and consists of Detailed Information, Tags, Work History tabs.
      CategoryDetailed description
      StatusDisplays the status of Config Inspection
      • Ready: When there is no diagnostic request after service creation (diagnostic request possible)
      • In Progress: When a diagnostic request is in progress (diagnostic request/service termination not possible)
      • Error: When an error occurs in the diagnostic request (diagnostic request possible)
      • Completed: When the diagnostic request is completed successfully (diagnostic request possible)
      Diagnosis RequestButton that can perform Console diagnosis
      Service CancellationButton to cancel the service
      Table. Config Inspection status information and additional functions

Detailed Information

Config Inspection List page allows you to view detailed information of the selected resource and, if necessary, edit the information.

CategoryDetailed description
ServiceService Name
Resource TypeResource Type
SRNUnique resource ID in Samsung Cloud Platform
Resource NameResource Name
Resource IDUnique resource ID in the service
CreatorUser who created the service
Creation date/timeDate/time the service was created
EditorUser who modified the service information
Modification Date/TimeDate/Time when service information was modified
Diagnosis TypeDiagnosis types provided by the service
CloudDiagnosis Target Types
Diagnosis TargetConsole information of the diagnostic target
  • Provides the diagnostic name and diagnostic account information of the diagnostic target
  • If the diagnostic target is AWS or Azure, you can click the Edit icon to modify the diagnostic account
PlanSelected plan type
Recent diagnosis date/timeLast executed diagnostic request date/time
Recent Diagnosis ResultLast executed diagnosis request result
  • Completed: The diagnosis request has been completed successfully
  • Error: The diagnosis request was not completed successfully
    • UNAUTHORIZED: Key permission used for the diagnosis request needs to be verified
    • INVALID_INPUT_VALUE: Input values such as diagnosis account need to be verified
    • CONNECTION_FAIL: Console access control settings need to be verified
    • ETC: Other errors such as diagnosis engine require inquiry through the service desk
※ Diagnosis results can be viewed in the Security > Config Insepction > Report menu
Authentication KeyUser’s authentication key registered at service creation
  • Access Key, user, status information provided
  • Access Key information and edit icon are displayed only to the user who created the authentication key
    • Click the Edit icon to change the authentication key
  • If the authentication key is deleted, it is shown as - status; if expired, shown as Expired
  • Authentication key information (Access Key, status) of resources created by other users is displayed as -
Diagnosis ScheduleDisplay selected diagnosis schedule information
  • If the diagnosis target is SCP, you can click the Edit icon to change the diagnosis schedule.
Table. Config Inspection Detailed Information Tab Items

Tag

Config Inspection List page allows you to view the tag information of selected resources, and you can add, modify, or delete them.

CategoryDetailed description
Tag ListTag List
  • You can view the Key, Value information of tags
  • Up to 50 tags can be added per resource
  • When entering tags, search and select from the previously created Key and Value list
Table. Config Inspection Tag Tab Items

Work History

On the Config Inspection List page, you can view the operation history of the selected resource.

CategoryDetailed description
Work History ListResource Change History
  • Work date and time, Resource ID, Resource name, Work details, Event topic, Work result, Check worker information
Table. Config Inspection Work History Tab Items

Config Inspection Resource Management

If you need to view the status of Config Inspection resources and request a diagnosis, you can perform the task on the Config Inspection List or Config Inspection Details page.

Edit Authentication Key

You can select the authentication key to use for diagnosis for each diagnosis target.

To modify the service’s authentication key, follow the steps below.

  1. All Services > Security > Config Inspection Click the menu. Go to Config Inspection’s Service Home page.
  2. Click the Config Inspection menu on the Service Home page. You will be taken to the Config Inspection list page.
  3. Config Inspection List page, click the resource to edit the authentication key. You will be taken to the Config Inspection Details page.
  4. Check the authentication key and click the Edit icon. The Edit Authentication Key popup window opens.
  5. Edit Authentication Key Select the authentication key to use in the popup window and click the Confirm button.
    CategoryDetailed description
    Authentication KeyAuthentication Key Details
    Creation Date/TimeAuthentication Key Creation Date
    Expiration Date and TimeAuthentication Key Expiration Date
    StatusStatus of the authentication key
    • Use: Usable state
    • Expired: Expired usage period state
    Table. Authentication Key Edit Popup Items
Reference
  • If the authentication key is deleted, it is displayed as - status.
  • The authentication key information (authentication key, status) of resources created by other users is displayed as -.

Request Diagnosis

You can request a console diagnosis based on the configured checklist.

To request a console diagnosis, follow the steps below.

  1. All Services > Security > Config Inspection Click the menu. Go to Config Inspection’s Service Home page.

  2. Click the Config Inspection menu on the Service Home page. You will be taken to the Config Inspection list page.

  3. Config Inspection list page, click the resource to request a diagnosis. Config Inspection details page will be opened.

  4. Click the Diagnostic Request button on the Config Inspection Details page. The Diagnostic Request popup will open.

  5. Diagnosis Request Enter the information required for diagnosis in the popup window and click the Confirm button.

    • Diagnosis Request The items in the popup window vary depending on the selected Console.
      CategoryDetailed description
      Console Access MethodFixed to authentication key method as the way to access the Console
      ChecklistFix as Best Practice when selecting SCP
      Authentication KeyIf SCP is selected, choose the pre-generated authentication key
      Access KeyEnter Access Key if AWS is selected
      Secret KeyEnter Secret Key if AWS is selected
      Client IDEnter Client ID if Azure is selected
      Client SecretEnter Client Secret if Azure is selected
      Tenant IDEnter Tenant ID if Azure is selected
      Table. Diagnosis Request Popup Items
  6. On the Config Inspection List page, check the Status value.

    • When the diagnostic request is completed, the status value is displayed as Completed or Error.
    • Completed: You can view the diagnosis request results in the diagnosis results menu. For more details, see Report Management.
Reference
For detailed information on the prerequisite settings required to run diagnostics per console, refer to Set Up Prerequisites.

Config Inspection Cancel

You can cancel the unused Config Inspection service. However, if you cancel Config Inspection, all stored diagnostic data will be deleted.

Caution
  • If you cancel the resource, all diagnostic data will be deleted, and you will not be able to view the diagnostic results in the Report.
  • Config Inspection service cannot be terminated if its status is In Progress.

To cancel Config Inspection, follow the steps below.

  1. Click the All Services > Security > Config Inspection menu. Go to Config Inspection’s Service Home page.
  2. Click the Config Inspection menu on the Service Home page. Navigate to the Config Inspection List page.
  3. On the Config Inspection List page, click the resource to be terminated. Navigate to the Config Inspection Details page.
  4. Click the Service Termination button on the Config Inspection Details page.
  5. When termination is complete, check on the Config Inspection List page whether the resource has been terminated.
Overview
Dashboard Check