Control Tower 3 Flashcards
Baselines and Blueprints
What is Baselining?
Load all the stuff into a newly-created or newly-enrolled “blank” AWS Account.
Baselines and Blueprints
What is an account Baseline?
The resources that you just set up in a new account
Baselines and Blueprints
At it’s core, what is a Blueprint?
Just a CloudFormation Template
Baselines and Blueprints
Where are Blueprints kept?
In a hub account (just a Blueprints term) as a Service Catalog item
Baselines and Blueprints
What is a good candidate to be your hub account?
Not the CT Management account! Any other works
Baselines and Blueprints
Where are Blueprints used?
Customization to a default Account Factory set up or update existing account
Baselines and Blueprints
Where can you get Blueprints?
Go to Service Catalog, choose CT Blueprints for pre-built Blueprints from AWS Partners
Identity
How does Control Tower help with login and identity?
Uses IAM Identity Center to federate and manage all logins to all accounts
Identity
How does Control Tower control logins across all accounts?
Sets up federation with IAM Identity Center (né SSO)
Drift
What does Compliance mean in CT?
“In compliance” means resource has zero drift.
Drift
How is CT Compliance related to government compliance frameworks?
It isn’t. Name clash.
Drift
How does Drift work?
Happens automatically – detects when things change.
Drift
How is Drift surfaced?
CT in Member accounts posts to local SNS. Lambda pushes to audit account.
Drift
Why this two-stage drift notification?
So member account admins can get alerts for their account.
Drift
How does Control Tower automatically fix Drift?
It doesn’t.
Drift
How can you correct some types of Drift in an account?
Click “Repair” button on LZ Settings web page.
Drift
How can you wholesale try to repair drift across many accounts?
Re-register an OU: all accounts get re-registered, re-applies account factory stuff.
Drift
What things are detected by Drift scanning?
Controls set up by CT when the LZ/Account was created
Landing Zone Accelerator
LZ Accelerator in a nutshell?
Extend Control Tower: set up MANY more AWS services, best practices for mulit-account + security
Landing Zone Accelerator
How do you set up LZ Accelerator?
It’s a CloudFormation template, deploy it
Landing Zone Accelerator
What’s the technical difference between LZA and Control Tower?
Control Tower is AWS service. LZA is open-source CF Template you deploy.
Landing Zone Accelerator
What does LZA deploy into Organizations Management account?
CodeCommit, CodePipeline, CodeBuild, Lambda functions, DDB tables
Landing Zone Accelerator
How do you use LZA to change things in your accounts?
Edit config files, commit to CodeCommit, pipeline CI/CD deploys the configuration across accounts.
Landing Zone Accelerator
Does LZA need Control Tower?
No, can deploy LZA stand-alone. LZA complements CT.
Landing Zone Accelerator
What’s the long-term plan for Control Tower vs. LZA?
Over time, an deprecate LZA features in favor of native AWS services
Landing Zone Accelerator
Major feature of LZA for workload accounts?
Sets up streaming of CloudWatch Log Groups to Kineiss Data Stream in Log Archive account, store centrally in S3.