{"repo":"aws-samples/aws-control-tower-account-setup-using-step-functions","free":true,"listed":false,"github":"https://github.com/aws-samples/aws-control-tower-account-setup-using-step-functions","clone":"git clone https://github.com/aws-samples/aws-control-tower-account-setup-using-step-functions.git","description":"Automated AWS account hardening with AWS Control Tower and AWS Step Functions","language":"Python","stars":38,"topics":["aws","security","automation","aws-web-services","control-tower","eventbridge"],"license":"MIT-0","category":"workflow-automation","readme_excerpt":"Automate activities in Control Tower provisioned AWS accounts Table of contents 1. Introduction 2. Architecture 3. Prerequisites 4. Tools and services 5. Usage 6. Clean up 7. Reference 8. Contributing 9. License Introduction This project will configure the following settings on a new AWS account provisioned by AWS Control Tower: 1. Deletes the default VPC in every region 2. Adds a CloudWatch Logs resource policy that allows Route53 to log DNS requests to CloudWatch in the us-east-1 (Northern Virginia) region 3. Enables the account-wide public S3 block setting 4. Modifies account-level ECS settings 5. Associates specific principals to shared AWS Service Catalog portfolios 6. Grants specific AWS SSO groups access to the new account 7. Blocks public SSM document sharing 8. Enables EBS encryption by default 9. Applies an IAM password policy that complies with the CIS AWS Foundations Benchmark Architecture 1. When AWS Control Tower provisions a new account, a CreateManagedAccount event is sent to the Amazon EventBridge default event bus. 2. An Amazon EventBridge rule matches the CreateManagedAccount event and triggers an AWS Step Functions state machine that executes AWS Lambda functions. 3. Step Functions assumes the AWSControlTowerExecution IAM role in the new account and uses the AWS SDK service integration to set the password policy using iam:UpdateAccountPasswordPolicy , adds the account-level S3 public block setting, creates a CloudWatch Logs resource policy in the us-east-1","default_branch":null,"files":null,"tree":[],"storefront":"/r/aws-samples","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/aws-samples/aws-control-tower-account-setup-using-step-functions/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}