AWS Control Tower setup stuck

0

What can I do if I tried to redo the Control Tower setup but didn't remove the old audit and log-archive accounts? The setup is locked and can't change the names of the log-archive and audit accounts. Can't even access those accounts to remove the S3 buckets.

StefanG
preguntada hace 7 meses209 visualizaciones
2 Respuestas
0

Try this. If drift repair does not fix your landing zone please post the error messages to provide additional context. Also, if you are redoing everything from scratch. You can go to the CloudFormation console, and delete all stack sets related to your Control Tower installation. You may have to go into multiple accounts to delete everything.

AWS
respondido hace 7 meses
  • Can't repair the drift because the setup is locked and the landing zone wan't set. I tried to suspend the audit and log-archive accounts without knowing that you can't revert that. And now the setup is locked. Don't understand why you can't change the setting of the control tower setup if it fails. Tried to remove the CloudFormation stack sets but I guess it doesn't do anything because the accounts are suspended. I think my only solution would be to unsuspend the accounts somehow.

  • What is the specific error you get when you retry creating the landing zone? I recently ran into a similar issue, and I had to delete AWSControlTowerBP-BASELINE-CONFIG stack set. You will need the account numbers of your Log and Audit accounts. You can retrieve those from the organization console. Got to your CloudFormation console, and click on "Stacksets" in the side navigation. You will have to "Delete the stacks from Stackset" and then delete the Stackset itself. Give that a try, and then retry creating your landing zone. If that fails, please post the specific error here so we can provide more guidance.

0

i think you need to unmanage old account first and then rebuild the control tower. then Deploy Control Tower with existing accounts. https://aws.amazon.com/blogs/mt/use-existing-logging-and-security-account-with-aws-control-tower/

Sachin
respondido hace 7 meses

No has iniciado sesión. Iniciar sesión para publicar una respuesta.

Una buena respuesta responde claramente a la pregunta, proporciona comentarios constructivos y fomenta el crecimiento profesional en la persona que hace la pregunta.

Pautas para responder preguntas