Maintained with ☕️ by
IcePanel logo

AWS Control Tower’s Account Factory for Terraform increases customization

Share

Services

AWS Control Tower Account Factory for Terraform (AFT) now allows you to customize the resources deployed and recorded by AFT. You can now choose whether or not to deploy AFT using a virtual private cloud (VPC). You can also customize the retention periods for AWS Backup recovery points, Amazon Cloudwatch log groups, and Amazon S3 log archive buckets to meet your unique data retention needs. This release includes enhancements to AFT VPC default security group to align with [AWS Foundational Security Best Practices](https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-2). Account Factory for Terraform (AFT) sets up a Terraform pipeline to help you provision and customize accounts in AWS Control Tower. To learn more, visit the [Account Factory for Terraform](https://docs.aws.amazon.com/controltower/latest/userguide/taf-account-provisioning.html) page in the [AWS Control Tower User Guide](https://docs.aws.amazon.com/controltower/) or review the release notes on the [AFT Github page](https://github.com/aws-ia/terraform-aws-control%5Ftower%5Faccount%5Ffactory/releases). AFT is supported in all commercial regions with some exceptions. See the list of AFT Region limitations [here](https://docs.aws.amazon.com/controltower/latest/userguide/limits.html) and AWS GovCloud (US) Region limitations [here](https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-controltower.html).