Unable to update Control Tower landing zone, when config recorder managed in audit account has been deleted

0

Steps to reproduce issue :

  • Control tower landing zone is configured
  • Config recorder for audit account has been accidentally deleted through CLI
  • Try to Update Landing zone
  • Failed with error : "AWS Control Tower could not find the configuration recorder for account <audit_account_id> in region <region>. It may have been deleted. Update account under OU the try again, or contact AWS Support. My question is how is the best way to re-create this config recorder.

Thank you for your help.

profile picture
aolfa
已提问 10 个月前290 查看次数
1 回答
1
已接受的回答

Hello aolfa, I think redeploying the StackSet 'AWSControlTowerBP-BASELINE-CONFIG' to your audit account would be helpful in resolving your issue I recommend deleting the stack instance for your audit account by following the steps outlined in this document [1], and then recreating the stack instance by updating the StackSet "AWSControlTowerBP-BASELINE-CONFIG" [2]. [1] - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/stackinstances-delete.html [2] - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/stackinstances-create.html I hope this method works. :)

profile pictureAWS
已回答 10 个月前
profile picture
专家
已审核 14 天前
profile picture
专家
已审核 10 个月前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则