IGlobalConfig / IControlTowerConfig / IControlTowerControlConfig

Description

Control Tower controls

See

ControlTowerControlConfig

This allows you to enable Strongly Recommended or Elective Controls https://docs.aws.amazon.com/controltower/latest/userguide/optional-controls.html

Remarks

AWS Control Tower is limited to 10 concurrent operations, where enabling a control for one Organizational Unit constitutes a single operation. To avoid throttling, please enable controls in batches of 10 or fewer each pipeline run. Keep in mind other Control Tower operations may use up some of the available quota.

Example

controlTowerControls:
- identifier: AWS-GR_RESTRICT_ROOT_USER_ACCESS_KEYS
enable: true
deploymentTargets:
organizationalUnits:
- Workloads

Hierarchy

  • ControlTowerControlConfig

Implements

Constructors

Properties

deploymentTargets: DeploymentTargets = ...

Control Tower control deployment targets, controls can only be deployed to Organizational Units

enable: boolean = true

Control enabled

identifier: string = ''

Control Tower control identifier, for Strongly Recommended or Elective controls this should start with AWS-GR

regions: undefined | ("af-south-1" | "ap-east-1" | "ap-south-1" | "ap-south-2" | "ap-southeast-1" | "ap-southeast-2" | "ap-southeast-3" | "ap-northeast-1" | "ap-northeast-2" | "ap-northeast-3" | "ca-central-1" | "eu-central-1" | "eu-central-2" | "eu-west-1" | "eu-west-2" | "eu-west-3" | "eu-north-1" | "eu-south-1" | "eu-south-2" | "me-central-1" | "me-south-1" | "sa-east-1" | "us-east-1" | "us-east-2" | "us-west-1" | "us-west-2" | "cn-north-1" | "cn-northwest-1" | "us-gov-west-1" | "us-gov-east-1" | "us-iso-east-1" | "us-iso-west-1" | "us-isob-east-1" | "ap-southeast-4" | "il-central-1" | "ca-west-1")[] = undefined

(Optional) Region(s) where this service quota increase will be requested. Service Quota increases will be requested in the home region only if this property is not defined.

Generated using TypeDoc