The page has been translated by Gen AI.

How-to guides

Users can create the Config Inspection service by entering the required information and selecting detailed options through the Samsung Cloud Platform Console.

Create Certificate

To create and use the Config Inspection service in the Samsung Cloud Platform Console, you must first generate an authentication key.

Authentication key generation can be created in My menu > My Info. Authentication Key Management > Authentication Key Creation. For more details, refer to Manage Authentication Keys.

Reference
  • The expiration period of the authentication key is up to 365 days.
  • To create an authentication key without an expiration date, it must be generated permanently.

Create Config Inspection

You can create and use the Config Inspection service in the Samsung Cloud Platform Console.

Reference
Users must belong to the AdministratorGroup user group to use the services provided by the Config Inspection service properly.

To create a Config Inspection, follow these steps.

  1. All Services > Security > Config Inspection Click the menu. 1. Navigate to the Service Home page of Config Inspection.
  2. On the Service Home page, click the Create Config Inspection button. 2. Navigate to the Create Config Inspection page.
  3. Create Config Inspection On the page, enter the inputs required to create the service, and select detailed options.
    • Enter or select the required information in the Service Information Input area.
      Category
      required status
      Detailed description
      Diagnostic Type-Automatic configuration via Console
      CloudRequiredSelect cloud to diagnose
      • SCP: Samsung Cloud Platform
      • AWS: Amazon Web Services
      • Azure: Microsoft Azure
      • Detailed input fields vary depending on the selected cloud type
      Diagnosis target > Diagnosis nameRequiredName to distinguish the diagnostic target
      • Use the entered value as the resource name
      • Enter within 25 characters using English letters, numbers, and special characters (-, _)
      Diagnostic target > Diagnostic accountRequiredConsole information to be diagnosed
      • Select the Account ID to diagnose from the list
      • Selecting the same Account ID will result in duplicate requests and additional charges
      • If AWS is selected, enter the Account ID (12 digits) for the diagnostic account
      • If Azure is selected, enter the Subscription ID (36 characters, including letters, numbers, and special characters) for the diagnostic account
      Diagnostic Schedule > ChecklistRequiredAutomatically configure when Use is selected for the diagnostic schedule
      Diagnostic Schedule > Diagnostic CycleRequiredSelect diagnostic interval
      • Diagnostics run on the selected date according to the specified interval
      • Monthly selection may result in diagnostics not being performed on the selected date
        • Example) Selecting the 31st of each month – February has no such date, so diagnostics are not performed
      Diagnostic Schedule > Start TimeRequiredSelect diagnostic start time
      • Set the hour and minute information for starting the diagnostic
      authentication keyRequiredSelect authentication key to use for Open API calls
      • Click the Select button and, in the Select Authentication Key popup, select the appropriate key from the authentication key list
      • If no selectable authentication key is available, click Authentication Key Management to create a new authentication key
      Pricing planSelectionSelect a plan
      • Standard: Billing is based on the number of diagnoses
      • Monthly subscription: Billing is a fixed amount each month regardless of the number of diagnoses (based on up to 30 diagnoses per month)
      • The plan cannot be changed after the service is requested
      Table. Config Inspection Service Information Input Items
    • Enter or select the required information in the Additional Information Input area.
      Category
      required status
      Detailed description
      tagSelectionAdd Tag
      • Up to 50 per resource can be added
      • After clicking the Add Tag button, input or select Key, Value values
      Table. Config Inspection additional information input fields
  4. Summary Check the detailed information and estimated charges generated in the panel, and click the Create button.
    • When creation is complete, check the created resources on the Config Inspection List page.

View Config Inspection detailed information

The Config Inspection service allows you to view and edit the full list of resources and detailed information. The Config Inspection Details page consists of Detail Information, Tags, Operation History tabs.

To view detailed information of the Config Inspection service, follow these steps.

  1. Click the All Services > Security > Config Inspection menu. 1. Navigate to the Service Home page of Config Inspection.
  2. On the Service Home page, click the Config Inspection menu. 2. Go to the Config Inspection List page.
  3. On the Config Inspection List page, click the resource to view detailed information. 3. Go to the Config Inspection Details page.
    • Config Inspection Details page displays status information and additional feature information, and consists of Details, Tags, Activity History tabs.
      CategoryDetailed description
      statusIndicates the status of Config Inspection
      • Ready: When there is no diagnostic request after the service is created (diagnostic request possible)
      • In Progress: When a diagnostic request is being executed (diagnostic request/service termination not allowed)
      • Error: When an error occurs in the diagnostic request (diagnostic request possible)
      • Completed: When the diagnostic request completes successfully (diagnostic request possible)
      Diagnostic requestButton to perform console diagnostics
      Service terminationCancel service button
      Table. Config Inspection status information and additional functions

Detailed Information

Config Inspection List page lets you view detailed information of the selected resource and modify it if needed.

CategoryDetailed description
serviceService Name
Resource TypeResource Type
SRNUnique resource ID in Samsung Cloud Platform
Resource nameResource Name
Resource IDUnique resource ID in the service
ConstructorUser who created the service
Creation Date/TimeService creation date and time
EditorUser who edited the service information
Modification date and timeDate and time the service information was modified
Diagnostic typeDiagnostic types offered by the service
CloudDiagnostic target types
Diagnostic TargetConsole information for the diagnostic target
  • Provides the diagnostic name and diagnostic account information of the diagnostic target
  • If the diagnostic target is AWS or Azure, you can click the Edit icon to modify the diagnostic account
Pricing planSelected plan type
Recent diagnosis date and timeTimestamp of the last executed diagnostic request
Recent diagnostic resultsResult of the most recent diagnostic request
  • Completed: The diagnostic request has been completed successfully
  • Error: The diagnostic request was not completed successfully
    • UNAUTHORIZED: Key permissions used for the diagnostic request need to be verified
    • INVALID_INPUT_VALUE: Check the diagnostic account and other input values
    • CONNECTION_FAIL: Console access control settings need to be verified
    • ETC: Other errors such as diagnostic engine issues require contacting the service desk
※ Diagnostic results can be viewed in the Security > Config Insepction > Report menu
authentication keyThe authentication key of the user registered when creating the service
  • Access Key, user, status information provided
  • Access Key information and the edit icon are displayed only to the user who created the authentication key
    • edit icon can be clicked to change the authentication key
  • If the authentication key is deleted, it is shown as - status; if it is expired, it is shown as expired
  • Authentication key information (Access Key, status) of resources created by other users is displayed as -
Diagnostic ScheduleDisplay selected diagnostic schedule information
  • If the diagnostic target is SCP, you can click the Edit icon to change the diagnostic schedule
Table. Config Inspection detailed information tab items

Tag

Config Inspection list page lets you view the tag information of the selected resource, and you can add, modify, or delete it.

CategoryDetailed description
Tag listTag list
  • You can view the Key, Value information of the tag
  • Up to 50 tags can be added per resource
  • When entering a tag, you can search and select from the list of previously created Keys and Values
Table. Config Inspection tag tab items

Job History

On the Config Inspection List page, you can view the operation history of the selected resource.

CategoryDetailed description
Task History ListResource Change History
  • Operation Date/Time, Resource ID, Resource Name, Operation Details, Event Topic, Operation Result, Check Operator Information
Table. Config Inspection job history tab items

Config Inspection Resource Management

If you need to view the status of a Config Inspection resource and request a diagnosis, you can perform the task on the Config Inspection List or Config Inspection Details page.

Modify authentication key

You can select the authentication key to use for each diagnostic target.

To modify the service’s authentication key, follow these steps.

  1. All Services > Security > Config Inspection Click the menu. 1. Navigate to the Service Home page of Config Inspection.
  2. On the Service Home page, click the Config Inspection menu. 2. Navigate to the Config Inspection List page.
  3. Config Inspection List page, click the resource to modify the authentication key. 3. Navigate to the Config Inspection Details page.
  4. Check the authentication key and click the Edit icon. 4. Edit Authentication Key The popup window opens.
  5. Edit Authentication Key Select the authentication key to use in the popup window and click the Confirm button.
    CategoryDetailed description
    authentication keyAuthentication Key Details
    Creation Date/TimeAuthentication key creation date
    Expiration date and timeAuthentication key expiration date
    statusAuthentication key status
    • Used: Available
    • Expired: Usage period expired
    Table. Authentication key edit popup items
Reference
  • When the authentication key is deleted, it is displayed as - status.
  • The authentication key information (key, status) of resources created by other users is displayed as -.

Request Diagnosis

You can request a diagnosis from the Console based on the configured checklist.

To request a console diagnosis, follow these steps.

  1. Click the All Services > Security > Config Inspection menu. 1. Navigate to the Service Home page of Config Inspection.

  2. On the Service Home page, click the Config Inspection menu. 2. Go to the Config Inspection List page.

  3. On the Config Inspection List page, click the resource you want to diagnose. 3. Navigate to the Config Inspection Details page.

  4. Click the Diagnosis Request button on the Config Inspection Details page. 4. Diagnostic Request popup window opens.

  5. Diagnosis Request In the popup window, enter the information required for the diagnosis and click the Confirm button.

    • Diagnostic Request popup window items vary depending on the selected Console.
      CategoryDetailed description
      Console access methodFix the authentication key method as the console access method.
      ChecklistWhen selecting SCP, set it as the Best Practice.
      authentication keyIf you selected SCP, choose the pre‑generated authentication key.
      Access KeyIf AWS is selected, enter Access Key
      Secret KeyIf AWS is selected, enter Secret Key
      Client IDIf Azure is selected, enter the Client ID
      Client SecretIf Azure is selected, enter the Client Secret
      Tenant IDIf Azure is selected, enter Tenant ID
      Table. Diagnosis request popup items
  6. On the Config Inspection List page, check the status value.

    • When the diagnostic request is completed, the status value is displayed as Completed or Error.
    • When the status is Completed, you can view the diagnosis request results in the diagnosis results menu. * For more details, refer to Report Management.
Reference
For detailed information on the prerequisite settings required to run diagnostics for each console, refer to Prerequisite Settings.

Terminate Config Inspection

You can cancel the Config Inspection service that you are not using. However, disabling Config Inspection will delete all stored diagnostic data.

Caution
  • If you terminate the resource, all diagnostic data will be deleted, and you will not be able to view the diagnostic results in the Report.
  • If the status of the Config Inspection service is In Progress, the service cannot be terminated.

To disable Config Inspection, follow these steps.

  1. Click the All Services > Security > Config Inspection menu. 1. Navigate to the Service Home page of Config Inspection.
  2. On the Service Home page, click the Config Inspection menu. 2. Go to the Config Inspection List page.
  3. On the Config Inspection List page, click the resource to be terminated. 3. Go to the Config Inspection Details page.
  4. On the Config Inspection Details page, click the Service Termination button.
  5. When termination is complete, check on the Config Inspection List page whether the resource has been terminated.
Checklist
Check dashboard