- Newest
- Most votes
- Most comments
Hi @rePost-User-7903133:
I got the same error. I forgot to set permissions in KMS using the following instructions https://docs.aws.amazon.com/en_us/controltower/latest/userguide//kms-guidance.html.
After that, I needed to remove two cloudformations AWSControlTowerBP-BASELINE-CLOUDTRAIL-MASTER
and restart the process.
I hope this can help someone.
Hi User,
very strange behaviour. Normally there should not be a problem when setting up control tower. The logging bucket should be located in the "log archive" account wich was created with control tower. Check out the Cloudformation-Stack-Events for more details.
Also check out the documentation, it explains that there could be problems if you immediatly create a landing zone with control tower in a freshly created account: https://docs.aws.amazon.com/controltower/latest/userguide/troubleshooting.html
Landing Zone Launch Failed
Common causes of landing zone launch failure:
Lack of response to a confirmation email message.
AWS CloudFormation StackSet failure.
Confirmation email messages: If your management account is less than an hour old, you may encounter issues when the additional accounts are created.
Action to take
If you encounter this issue, check your email. You might have been sent confirmation email that is awaiting response. Alternatively, we recommend that you wait an hour, and then try again. If the issue persists, contact AWS Support
.
Failed StackSets: Another possible cause of landing zone launch failure is AWS CloudFormation StackSet failure. AWS Security Token Service (STS) regions must be enabled in the management account for all AWS Regions that AWS Control Tower is governing, so that the provisioning can be successful; otherwise, stack sets will fail to launch.
Action to take
Be sure to enable all of your required AWS Security Token Service (STS) endpoint regions
before you launch AWS Control Tower.
Currently, AWS Control Tower is supported in the following AWS Regions:
US East (N. Virginia)
US East (Ohio)
US West (Oregon)
Canada (Central) Region
Asia Pacific (Sydney)
Asia Pacific (Singapore) Region
Europe (Frankfurt) Region
Europe (Ireland)
Europe (London) Region
Europe (Stockholm) Region
Asia Pacific (Mumbai) Region
Asia Pacific (Seoul) Region
Asia Pacific (Tokyo) Region
Europe (Paris) Region
South America (São Paulo) Region
AWS Support is probably your best bet in the end.
Sincerely Heiko
Relevant content
- asked 2 years ago
- asked 2 years ago
- asked a year ago
- asked 2 months ago
- How can I troubleshoot issues when I use the AWS Load Balancer Controller to create a load balancer?AWS OFFICIALUpdated 2 years ago
- AWS OFFICIALUpdated a year ago
- AWS OFFICIALUpdated 2 years ago