ReadonlydeploymentControl Tower control deployment targets, controls can only be deployed to Organizational Units
ReadonlyenableControl enabled
ReadonlyidentifierControl Tower control identifier. For Strongly Recommended or Elective controls this should start with AWS-GR. For Global Control Tower Controls, this should be the CONTROL_TOWER_OPAQUE_ID, please see this page for more information: https://docs.aws.amazon.com/controltower/latest/controlreference/all-global-identifiers.html.
Optional Readonlyregions(Optional) Region(s) where this service quota increase will be requested. Service Quota increases will be requested in the home region only if this property is not defined. If this property is defined, the regions must also be listed in the enabledRegions section or the change will not be applied.
IGlobalConfig / IControlTowerConfig / IControlTowerControlConfig
Description
Control Tower controls
See
ControlTowerControlConfig
This allows you to enable Strongly Recommended or Elective Controls https://docs.aws.amazon.com/controltower/latest/userguide/optional-controls.html
Remarks
AWS Control Tower is limited to 10 concurrent operations, where enabling a control for one Organizational Unit constitutes a single operation. To avoid throttling, please enable controls in batches of 10 or fewer each pipeline run. Keep in mind other Control Tower operations may use up some of the available quota.
Not all controls can be deployed to Security OU. Please see this page for more information: https://docs.aws.amazon.com/controltower/latest/controlreference/exception-to-controls-security-ou.html.
Example