Control Tower 3 Flashcards
Baselines and Blueprints
What is Baselining?
Load all the stuff into a newly-created or newly-enrolled “blank” AWS Account.
Baselines and Blueprints
What is an account Baseline?
The resources that you just set up in a new account
Baselines and Blueprints
At it’s core, what is a Blueprint?
Just a CloudFormation Template
Baselines and Blueprints
Where are Blueprints kept?
In a hub account (just a Blueprints term) as a Service Catalog item
Baselines and Blueprints
What is a good candidate to be your hub account?
Not the CT Management account! Any other works
Baselines and Blueprints
Where are Blueprints used?
Customization to a default Account Factory set up or update existing account
Baselines and Blueprints
Where can you get Blueprints?
Go to Service Catalog, choose CT Blueprints for pre-built Blueprints from AWS Partners
Identity
How does Control Tower help with login and identity?
Uses IAM Identity Center to federate and manage all logins to all accounts
Identity
How does Control Tower control logins across all accounts?
Sets up federation with IAM Identity Center (né SSO)
Drift
What does Compliance mean in CT?
“In compliance” means resource has zero drift.
Drift
How is CT Compliance related to government compliance frameworks?
It isn’t. Name clash.
Drift
How does Drift work?
Happens automatically – detects when things change.
Drift
How is Drift surfaced?
CT in Member accounts posts to local SNS. Lambda pushes to audit account.
Drift
Why this two-stage drift notification?
So member account admins can get alerts for their account.
Drift
How does Control Tower automatically fix Drift?
It doesn’t.