How to proceed after failed landing zone creation through control tower

1

I created a management account and proceeded to create landing zone through control tower. Opted for most default options except KMS encryption with single region. The creation process part succeeded - AWSControlTowerBP-BASELINE-CONFIG-MASTER completed successfully while AWSControlTowerBP-BASELINE-CLOUDTRAIL-MASTER failed.

Failiure message

Resource handler returned message: "Invalid request provided: Insufficient permissions to access S3 bucket aws-controltower-logs-xxxxxxxx-us-east-1 or KMS key arn:aws:kms:us-east-1:xxxxxxx:key/xxxxxx. (Service: CloudTrail, Status Code: 400

The rollback for the failed stack failed too. So, I deleted the stack manually and retried the operation. Now I am with a different error as below.

Resource handler returned message: "User: arn:aws:sts::xxxxxxx:assumed-role/AWSControlTowerAdmin/AssumeAdminRole is not authorized to perform: logs:DeleteLogGroup on resource: arn:aws:logs:us-east-1:xxxxxxxxx:log-group:aws-controltower/CloudTrailLogs:log-stream: because no identity-based policy allows the logs:DeleteLogGroup action (Service: CloudWatchLogs, Status Code: 400

I could try to address these issues one by one. But will the landing zone be ever able to complete successfully now considering it was partially done and I manually deleted the stack? Or should I just delete the root and everything under it and start over?

Grog
質問済み 1年前2816ビュー
3回答
4
acollao
回答済み 1年前
1

Hi There

I recommend performing the steps in Decommission Control Tower and manually removing resources. Specifically, check this section that outlines the resources that need to be manually removed before setting up CT again: https://docs.aws.amazon.com/controltower/latest/userguide/known-issues-decommissioning.html

profile pictureAWS
エキスパート
Matt-B
回答済み 1年前
0

Thanks. Will try this out

Grog
回答済み 1年前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ