Strategic Consolidation of Multiple Landing zones and Networks into a Unified Architecture

1

What is the optimal strategy for consolidating multiple master accounts, each with a unique landing zone and associated VPCs linked to separate Transit Gateways, into a unified landing zone where all VPCs are connected to a single Transit Gateway?

1 Antwort
1

Currently its not possible to have multiple control tower accounts under one org, there can be only one of in the management account. I would take below steps:

  1. So if you are looking for unifying all accounts under one management, you can either create a new Control tower account or promote one of the existing account.
  2. enroll your existing accounts - https://docs.aws.amazon.com/controltower/latest/userguide/enroll-account.html
  3. decommission unused management account - https://docs.aws.amazon.com/controltower/latest/userguide/how-to-decommission.html

Next part of unifying Networking - This will be little tricky if you have production workload running. see this - https://docs.aws.amazon.com/vpc/latest/tgw/tgw-best-design-practices.html Also have a look at AWS IPAM for managing your VPC and IPs- https://aws.amazon.com/blogs/mt/using-amazon-ipam-to-enhance-aws-control-tower-governance-for-networking-resources/

Thanks

AWS
beantwortet vor 3 Monaten

Du bist nicht angemeldet. Anmelden um eine Antwort zu veröffentlichen.

Eine gute Antwort beantwortet die Frage klar, gibt konstruktives Feedback und fördert die berufliche Weiterentwicklung des Fragenstellers.

Richtlinien für die Beantwortung von Fragen