Skip to content

Latest commit

 

History

History
14 lines (11 loc) · 1.31 KB

NOTES_ACCOUNTS.md

File metadata and controls

14 lines (11 loc) · 1.31 KB

AWS Account management - Organizations, OUs, SCPs

  • Must have AWS account to access services and create any resources. By default creates a root account.
  • Recommended to have multiple accounts for serving different environments like dev, test, prod, sandbox.
  • Managing multiple accounts become cumbersome so can use AWS Organisations. One account can become manager account and others become member accounts.
  • Can have multiple dev, test, prod accounts. All can be logically grouped as Organisation Units (OUs) and apply policies and permissions that the members of the OU may share in the organization.
  • You can apply Service Control Policies (SCPs), that act as guard rails on what services can be consumed in each AWS account. Written in JSON. SCPs can also restrict which regions those accounts can provision resources in.
  • One key trick to manage so many accounts by a single user is by using a Gmail email id. It allows you to have many sub user accounts which are ultimately linked to a common gmail account. This is achieved by adding a + letter in your email address ex. [email protected], [email protected], [email protected]... etc.

Multiple AWS Accounts strategy

alt text

OUs & SCPs

alt text