Control Tower Automation

0

We start using Control Tower via console and it automatically sets security account and sandbox account. And Im using AFT for additional account requests. Is there any way I can automate the setup of control tower itself like setting security account and sandbox account

已提问 7 个月前216 查看次数
2 回答
1
已接受的回答

Hi, unfortunately there is no API call or automation that can do the initial setup of Control Tower and it's Landing Zone at this time. We hope to add that functionality in the future. You can automate Control Tower control configuration using Terraform against the Organization Management Account (Where Control Tower resides) https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/controltower_control

To configure resources in the Log-Archive or Audit accounts, you can add them to AFT using the same process you would to provision a new account. Create a new account request but use the existing account details (Account Name, Account email address and Organizational Unit)

profile pictureAWS
已回答 7 个月前
profile picture
专家
已审核 7 天前
profile picture
专家
已审核 1 个月前
  • Hello ,can we implement new OU with AFT

0

Checkout this blog. You may also want to take a look at the Landing Zone Accelerator if your organization has complex compliance requirement.

Let me know if you have any other questions or if you run into issues walking through the blog.

AWS
已回答 7 个月前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则