Getting to know AWS Control Tower
BWI Air Control Tower designed by TSP

Getting to know AWS Control Tower

I first attended training on Landing Zones back in August 2018 when it was introduced to APN partners. My immediate thought was that it is a great concept. It had all the features that you can think of for creating AWS accounts that were compliant with company polices, had centralised logging, auditing and SSO for providing access.

But, yes there was a but, at that time it was very rough around the edges. For example, we could not actually finish our training because AWS had restrictions on launching resources in newly created accounts. Creating Landing Zones required you to have full-blown Microsoft AD servers provisioned with RDS Gateway and RDS Host. AD management console was installed on RDS Host and was used for creating/managing users and groups. Basically it was not a turn key solution and had limitations. However, you could tweak the provided CloudFormation scripts and lambda functions to make it work the way you wanted it to, given you had intimate knowledge of AWS services and were willing to break things few times before getting it right.

Fast forward a year and AWS have released Control Tower. This service wraps initial Landing Zones concept in a nicely presented service that hides away all the inner workings and presents you with a central console as below for managing your AWS environments.

AWS Control Tower Console

AWS Control Tower concept is very simple, create a central location for individuals who are responsible for managing your AWS environments and give them all the tools required for

  • Creating new OUs
  • Changing new Account settings e.g. default VPC subnet
  • Applying global policies to all accounts
  • Creating users/groups for various accounts

It did take me couple of tries to get it setup though. Mostly because it is new service and like any other new service, AWS is still working on smoothing out the process. First of all, you cannot create a Landing Zone on any of your existing AWS accounts. It has to be setup on a new account with none of the AWS services that would be auto configured via Landing Zone creation. For example, you cannot have any organisations created, audit trail enabled or SSO configured. Second thing I noticed was that as soon as you start the process, your main account will get an email to be authorised for consolidated billing. This should be accepted as soon as it arrives otherwise the whole process has trouble creating child accounts and setting up billing for them. In my first attempt, I missed that email and by the time I got to accept it the whole process had failed.

 Once it is configured and setup, it works really well. You can easily create new accounts and give various groups/users access to them. You get a self-service portal to create new AWS accounts which comply with company policies and have features like central logging and auditing enabled as well as mandatory guardrails e.g. AWS config rules. This means as a business, risk of rouge AWS account without mandatory company polices goes away.

 Out of the box, AWS Control Tower uses a newly created AWS SSO Directory for managing users and groups. This however can easily be changed via SSO console to a Managed AD Directory. Which allows large organisations to use their existing central identity store for managing access to various AWS accounts.

 Overall, AWS Control Tower is what I call a second-level service i.e. service which is built on top of existing services. It provides a simple way to setup your AWS environments which are easy to manage and are complaint. There are however some improvements still be made.

You need a brand new or almost new AWS account to setup Control Tower. I am sure this will change in due time and AWS will at least allow you to connect existing AWS accounts into your Control Tower managed organisations.

 AWS Control Tower is only available in four regions, N. Virginia, Ohio, Oregon and Ireland. This doesn’t mean any AWS accounts created via Control Tower cannot have workloads created in other regions but all the shared account resources e.g. SSO directory, s3 logging bucket can only be created in your AWS Control Tower region. This is not a big deal if you have spread out workloads but can be a hindrance for organisations that only have workloads in a single region. 

Fabio Rizzi

Cyber Security Engineer Sr. Consultant @ Pismo (Visa Inc.)

5 年

I couldn't find nowhere on the Internet besides here this information: "This doesn’t mean any AWS accounts created via Control Tower cannot have workloads created in other regions". That was what I was looking for :) Thanks

回复

要查看或添加评论,请登录

Imran Sadiq的更多文章

  • An honest review of AWS DataSync

    An honest review of AWS DataSync

    To start off with, its a great service if you want to continuously sync or a one time copy of data from one location to…

    1 条评论
  • My Shortlist Of re:Invent 2021 Announcements

    My Shortlist Of re:Invent 2021 Announcements

    AWS is in its third wave of services evaluation. First wave was the base services e.

    4 条评论
  • What does it mean to have a local AWS region

    What does it mean to have a local AWS region

    With the latest announcement from AWS on opening of their new Region in Auckland, I thought I should share some…

    6 条评论
  • Web client for AWS SFTP

    Web client for AWS SFTP

    FTP has been around for a long time and still is a strong contender when it comes to transferring data between ad-hoc…

    2 条评论
  • AWS's static stability and recent outage

    AWS's static stability and recent outage

    On January 22nd 2020 between 4:07 PM and 11:20PM PST, you could not create new resources in a VPC for AWS Sydney…

  • Eventful Days in Seattle

    Eventful Days in Seattle

    Sitting here in Starbucks Reserve (one of the best places to visit if you area coffee lover), I am going over the last…

    5 条评论
  • Recap from AWS Sydney Summit

    Recap from AWS Sydney Summit

    Since 2018, AWS has stepped up its game when it comes to hosting a tech conference in Southern hemisphere. AWS Sydney…

    7 条评论
  • Lancom Tech Talk: How to deploy S3 Static Websites to Test, UAT, or Production AWS Accounts from CodePipeline

    Lancom Tech Talk: How to deploy S3 Static Websites to Test, UAT, or Production AWS Accounts from CodePipeline

    In this blog post, I will demonstrate how to create a continuous deployment pipeline for Static Website deployment into…

    1 条评论
  • Why I abandoned Facebook...

    Why I abandoned Facebook...

    I abandoned Facebook couple of years back. Well, almost abandoned it.

    9 条评论
  • Off to re:Invent

    Off to re:Invent

    Its that time of the year again for me to pack my bags and head off to #re:Invent. It is perhaps the largest global…

    3 条评论

社区洞察

其他会员也浏览了