binbashar / le-tf-infra-aws

Terraform code for Leverage Reference Architecture for AWS, designed under optimal configs for the most popular modern web and mobile applications needs.
https://www.binbash.co/leverage
Apache License 2.0
24 stars 7 forks source link

ISSUE-495 | Enhancement: sync LZ Template into Ref-Arch Mgmt Org layer #509

Closed rodriguez-matias closed 1 year ago

rodriguez-matias commented 1 year ago

What?

Update and test the Ref Architecture organization layer with the latest Landing Zone Template code.

Environment Versions

Layers

/management/global/organizations

Why?

References

GitHub issue https://github.com/binbashar/le-tf-infra-aws/issues/495

github-actions[bot] commented 1 year ago

💰 Infracost estimate: monthly cost will not change

Project Previous New Diff
All projects $1,761 $1,761 $0

129 projects have no cost estimate changes.

Infracost output ``` ────────────────────────────────── The following projects have no cost estimate changes: binbashar/le-tf-infra-aws/apps-devstg/global/base-identities (Module path: apps-devstg/global/base-identities), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/backups -- (Module path: apps-devstg/us-east-1/backups --), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/base-network (Module path: apps-devstg/us-east-1/base-network), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/base-tf-backend (Module path: apps-devstg/us-east-1/base-tf-backend), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/cdn-s3-frontend -- (Module path: apps-devstg/us-east-1/cdn-s3-frontend --), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/databases-aurora (Module path: apps-devstg/us-east-1/databases-aurora), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/databases-mysql -- (Module path: apps-devstg/us-east-1/databases-mysql --), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/databases-pgsql -- (Module path: apps-devstg/us-east-1/databases-pgsql --), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/ec2-fleet-ansible -- (Module path: apps-devstg/us-east-1/ec2-fleet-ansible --), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-eks-demoapps/cluster (Module path: apps-devstg/us-east-1/k8s-eks-demoapps/cluster), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-eks-demoapps/identities (Module path: apps-devstg/us-east-1/k8s-eks-demoapps/identities), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-eks-demoapps/k8s-components (Module path: apps-devstg/us-east-1/k8s-eks-demoapps/k8s-components), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-eks-demoapps/k8s-workloads (Module path: apps-devstg/us-east-1/k8s-eks-demoapps/k8s-workloads), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-eks-demoapps/network (Module path: apps-devstg/us-east-1/k8s-eks-demoapps/network), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-eks-v1.17/cluster (Module path: apps-devstg/us-east-1/k8s-eks-v1.17/cluster), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-eks-v1.17/identities (Module path: apps-devstg/us-east-1/k8s-eks-v1.17/identities), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-eks-v1.17/k8s-resources (Module path: apps-devstg/us-east-1/k8s-eks-v1.17/k8s-resources), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-eks-v1.17/k8s-workloads (Module path: apps-devstg/us-east-1/k8s-eks-v1.17/k8s-workloads), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-eks-v1.17/network (Module path: apps-devstg/us-east-1/k8s-eks-v1.17/network), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-eks/cluster (Module path: apps-devstg/us-east-1/k8s-eks/cluster), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-eks/identities (Module path: apps-devstg/us-east-1/k8s-eks/identities), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-eks/k8s-components (Module path: apps-devstg/us-east-1/k8s-eks/k8s-components), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-eks/k8s-workloads (Module path: apps-devstg/us-east-1/k8s-eks/k8s-workloads), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-eks/network (Module path: apps-devstg/us-east-1/k8s-eks/network), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-kind/k8s-resources (Module path: apps-devstg/us-east-1/k8s-kind/k8s-resources), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-kops --/1-prerequisites (Module path: apps-devstg/us-east-1/k8s-kops --/1-prerequisites), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/k8s-kops --/2-kops (Module path: apps-devstg/us-east-1/k8s-kops --/2-kops), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/notifications (Module path: apps-devstg/us-east-1/notifications), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/security-audit (Module path: apps-devstg/us-east-1/security-audit), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/security-base (Module path: apps-devstg/us-east-1/security-base), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/security-certs (Module path: apps-devstg/us-east-1/security-certs), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/security-compliance -- (Module path: apps-devstg/us-east-1/security-compliance --), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/security-firewall -- (Module path: apps-devstg/us-east-1/security-firewall --), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/security-keys (Module path: apps-devstg/us-east-1/security-keys), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/storage/s3-bucket-demo-files -- (Module path: apps-devstg/us-east-1/storage/s3-bucket-demo-files --), binbashar/le-tf-infra-aws/apps-devstg/us-east-1/tools-cloud-nuke (Module path: apps-devstg/us-east-1/tools-cloud-nuke), binbashar/le-tf-infra-aws/apps-devstg/us-east-2/k8s-eks-v1.17/cluster (Module path: apps-devstg/us-east-2/k8s-eks-v1.17/cluster), binbashar/le-tf-infra-aws/apps-devstg/us-east-2/k8s-eks-v1.17/identities (Module path: apps-devstg/us-east-2/k8s-eks-v1.17/identities), binbashar/le-tf-infra-aws/apps-devstg/us-east-2/k8s-eks-v1.17/k8s-resources (Module path: apps-devstg/us-east-2/k8s-eks-v1.17/k8s-resources), binbashar/le-tf-infra-aws/apps-devstg/us-east-2/k8s-eks-v1.17/k8s-workloads (Module path: apps-devstg/us-east-2/k8s-eks-v1.17/k8s-workloads), binbashar/le-tf-infra-aws/apps-devstg/us-east-2/k8s-eks-v1.17/network (Module path: apps-devstg/us-east-2/k8s-eks-v1.17/network), binbashar/le-tf-infra-aws/apps-devstg/us-east-2/security-compliance -- (Module path: apps-devstg/us-east-2/security-compliance --), binbashar/le-tf-infra-aws/apps-devstg/us-east-2/security-keys (Module path: apps-devstg/us-east-2/security-keys), binbashar/le-tf-infra-aws/apps-prd/global/base-identities (Module path: apps-prd/global/base-identities), binbashar/le-tf-infra-aws/apps-prd/us-east-1/backups -- (Module path: apps-prd/us-east-1/backups --), binbashar/le-tf-infra-aws/apps-prd/us-east-1/base-network (Module path: apps-prd/us-east-1/base-network), binbashar/le-tf-infra-aws/apps-prd/us-east-1/base-tf-backend (Module path: apps-prd/us-east-1/base-tf-backend), binbashar/le-tf-infra-aws/apps-prd/us-east-1/cdn-s3-frontend -- (Module path: apps-prd/us-east-1/cdn-s3-frontend --), binbashar/le-tf-infra-aws/apps-prd/us-east-1/ec2-fleet -- (Module path: apps-prd/us-east-1/ec2-fleet --), binbashar/le-tf-infra-aws/apps-prd/us-east-1/notifications (Module path: apps-prd/us-east-1/notifications), binbashar/le-tf-infra-aws/apps-prd/us-east-1/security-audit (Module path: apps-prd/us-east-1/security-audit), binbashar/le-tf-infra-aws/apps-prd/us-east-1/security-base (Module path: apps-prd/us-east-1/security-base), binbashar/le-tf-infra-aws/apps-prd/us-east-1/security-certs (Module path: apps-prd/us-east-1/security-certs), binbashar/le-tf-infra-aws/apps-prd/us-east-1/security-compliance -- (Module path: apps-prd/us-east-1/security-compliance --), binbashar/le-tf-infra-aws/apps-prd/us-east-1/security-keys (Module path: apps-prd/us-east-1/security-keys), binbashar/le-tf-infra-aws/management/global/base-identities (Module path: management/global/base-identities), binbashar/le-tf-infra-aws/management/global/cost-mgmt (Module path: management/global/cost-mgmt), binbashar/le-tf-infra-aws/management/global/organizations (Module path: management/global/organizations), binbashar/le-tf-infra-aws/management/global/sso (Module path: management/global/sso), binbashar/le-tf-infra-aws/management/us-east-1/backups (Module path: management/us-east-1/backups), binbashar/le-tf-infra-aws/management/us-east-1/base-tf-backend (Module path: management/us-east-1/base-tf-backend), binbashar/le-tf-infra-aws/management/us-east-1/firewall-manager (Module path: management/us-east-1/firewall-manager), binbashar/le-tf-infra-aws/management/us-east-1/notifications (Module path: management/us-east-1/notifications), binbashar/le-tf-infra-aws/management/us-east-1/security-audit (Module path: management/us-east-1/security-audit), binbashar/le-tf-infra-aws/management/us-east-1/security-base (Module path: management/us-east-1/security-base), binbashar/le-tf-infra-aws/management/us-east-1/security-compliance (Module path: management/us-east-1/security-compliance), binbashar/le-tf-infra-aws/management/us-east-1/security-keys (Module path: management/us-east-1/security-keys), binbashar/le-tf-infra-aws/management/us-east-1/security-monitoring (Module path: management/us-east-1/security-monitoring), binbashar/le-tf-infra-aws/management/us-east-2/security-monitoring -- (Module path: management/us-east-2/security-monitoring --), binbashar/le-tf-infra-aws/network/global/base-identities (Module path: network/global/base-identities), binbashar/le-tf-infra-aws/network/us-east-1/base-network (Module path: network/us-east-1/base-network), binbashar/le-tf-infra-aws/network/us-east-1/base-tf-backend (Module path: network/us-east-1/base-tf-backend), binbashar/le-tf-infra-aws/network/us-east-1/network-firewall (Module path: network/us-east-1/network-firewall), binbashar/le-tf-infra-aws/network/us-east-1/notifications (Module path: network/us-east-1/notifications), binbashar/le-tf-infra-aws/network/us-east-1/security-audit (Module path: network/us-east-1/security-audit), binbashar/le-tf-infra-aws/network/us-east-1/security-base (Module path: network/us-east-1/security-base), binbashar/le-tf-infra-aws/network/us-east-1/security-compliance -- (Module path: network/us-east-1/security-compliance --), binbashar/le-tf-infra-aws/network/us-east-1/security-keys (Module path: network/us-east-1/security-keys), binbashar/le-tf-infra-aws/network/us-east-1/transit-gateway (Module path: network/us-east-1/transit-gateway), binbashar/le-tf-infra-aws/network/us-east-2/base-network (Module path: network/us-east-2/base-network), binbashar/le-tf-infra-aws/network/us-east-2/network-firewall (Module path: network/us-east-2/network-firewall), binbashar/le-tf-infra-aws/network/us-east-2/security-compliance -- (Module path: network/us-east-2/security-compliance --), binbashar/le-tf-infra-aws/network/us-east-2/security-keys (Module path: network/us-east-2/security-keys), binbashar/le-tf-infra-aws/network/us-east-2/transit-gateway (Module path: network/us-east-2/transit-gateway), binbashar/le-tf-infra-aws/security/global/base-identities (Module path: security/global/base-identities), binbashar/le-tf-infra-aws/security/us-east-1/base-tf-backend (Module path: security/us-east-1/base-tf-backend), binbashar/le-tf-infra-aws/security/us-east-1/firewall-manager (Module path: security/us-east-1/firewall-manager), binbashar/le-tf-infra-aws/security/us-east-1/notifications (Module path: security/us-east-1/notifications), binbashar/le-tf-infra-aws/security/us-east-1/security-audit (Module path: security/us-east-1/security-audit), binbashar/le-tf-infra-aws/security/us-east-1/security-base (Module path: security/us-east-1/security-base), binbashar/le-tf-infra-aws/security/us-east-1/security-compliance -- (Module path: security/us-east-1/security-compliance --), binbashar/le-tf-infra-aws/security/us-east-1/security-keys (Module path: security/us-east-1/security-keys), binbashar/le-tf-infra-aws/security/us-east-1/security-monitoring (Module path: security/us-east-1/security-monitoring), binbashar/le-tf-infra-aws/security/us-east-2/security-audit (Module path: security/us-east-2/security-audit), binbashar/le-tf-infra-aws/security/us-east-2/security-compliance -- (Module path: security/us-east-2/security-compliance --), binbashar/le-tf-infra-aws/security/us-east-2/security-monitoring -- (Module path: security/us-east-2/security-monitoring --), binbashar/le-tf-infra-aws/shared/global/base-dns/binbash.com.ar (Module path: shared/global/base-dns/binbash.com.ar), binbashar/le-tf-infra-aws/shared/global/base-identities (Module path: shared/global/base-identities), binbashar/le-tf-infra-aws/shared/us-east-1/backups (Module path: shared/us-east-1/backups), binbashar/le-tf-infra-aws/shared/us-east-1/base-network (Module path: shared/us-east-1/base-network), binbashar/le-tf-infra-aws/shared/us-east-1/base-tf-backend (Module path: shared/us-east-1/base-tf-backend), binbashar/le-tf-infra-aws/shared/us-east-1/container-registry (Module path: shared/us-east-1/container-registry), binbashar/le-tf-infra-aws/shared/us-east-1/ec2-fleet -- (Module path: shared/us-east-1/ec2-fleet --), binbashar/le-tf-infra-aws/shared/us-east-1/ec2-fleet-bastions -- (Module path: shared/us-east-1/ec2-fleet-bastions --), binbashar/le-tf-infra-aws/shared/us-east-1/k8s-eks-demoapps/identities (Module path: shared/us-east-1/k8s-eks-demoapps/identities), binbashar/le-tf-infra-aws/shared/us-east-1/notifications (Module path: shared/us-east-1/notifications), binbashar/le-tf-infra-aws/shared/us-east-1/secrets-manager (Module path: shared/us-east-1/secrets-manager), binbashar/le-tf-infra-aws/shared/us-east-1/security-audit (Module path: shared/us-east-1/security-audit), binbashar/le-tf-infra-aws/shared/us-east-1/security-base (Module path: shared/us-east-1/security-base), binbashar/le-tf-infra-aws/shared/us-east-1/security-compliance -- (Module path: shared/us-east-1/security-compliance --), binbashar/le-tf-infra-aws/shared/us-east-1/security-keys (Module path: shared/us-east-1/security-keys), binbashar/le-tf-infra-aws/shared/us-east-1/storage/backup-gdrive -- (Module path: shared/us-east-1/storage/backup-gdrive --), binbashar/le-tf-infra-aws/shared/us-east-1/storage/object-file-shares-for-users-list -- (Module path: shared/us-east-1/storage/object-file-shares-for-users-list --), binbashar/le-tf-infra-aws/shared/us-east-1/storage/object-file-shares-sftp-transfer-service -- (Module path: shared/us-east-1/storage/object-file-shares-sftp-transfer-service --), binbashar/le-tf-infra-aws/shared/us-east-1/tools-cloud-scheduler-stop-start (Module path: shared/us-east-1/tools-cloud-scheduler-stop-start), binbashar/le-tf-infra-aws/shared/us-east-1/tools-eskibana -- (Module path: shared/us-east-1/tools-eskibana --), binbashar/le-tf-infra-aws/shared/us-east-1/tools-github-selfhosted-runners (Module path: shared/us-east-1/tools-github-selfhosted-runners), binbashar/le-tf-infra-aws/shared/us-east-1/tools-jenkins -- (Module path: shared/us-east-1/tools-jenkins --), binbashar/le-tf-infra-aws/shared/us-east-1/tools-managedeskibana -- (Module path: shared/us-east-1/tools-managedeskibana --), binbashar/le-tf-infra-aws/shared/us-east-1/tools-prometheus-grafana -- (Module path: shared/us-east-1/tools-prometheus-grafana --), binbashar/le-tf-infra-aws/shared/us-east-1/tools-vault -- (Module path: shared/us-east-1/tools-vault --), binbashar/le-tf-infra-aws/shared/us-east-1/tools-vpn-server (Module path: shared/us-east-1/tools-vpn-server), binbashar/le-tf-infra-aws/shared/us-east-1/tools-webhooks -- (Module path: shared/us-east-1/tools-webhooks --), binbashar/le-tf-infra-aws/shared/us-east-2/base-network (Module path: shared/us-east-2/base-network), binbashar/le-tf-infra-aws/shared/us-east-2/container-registry (Module path: shared/us-east-2/container-registry), binbashar/le-tf-infra-aws/shared/us-east-2/security-compliance -- (Module path: shared/us-east-2/security-compliance --), binbashar/le-tf-infra-aws/shared/us-east-2/security-keys (Module path: shared/us-east-2/security-keys), binbashar/le-tf-infra-aws/shared/us-east-2/tools-eskibana -- (Module path: shared/us-east-2/tools-eskibana --), binbashar/le-tf-infra-aws/shared/us-east-2/tools-prometheus-grafana -- (Module path: shared/us-east-2/tools-prometheus-grafana --) Run the following command to see their breakdown: infracost breakdown --path=/path/to/code ────────────────────────────────── 2288 cloud resources were detected: ∙ 575 were estimated, 443 of which include usage-based costs, see https://infracost.io/usage-file ∙ 1566 were free: ∙ 161 x aws_iam_role_policy_attachment ∙ 141 x aws_iam_role ∙ 121 x aws_security_group_rule ∙ 104 x aws_iam_policy ∙ 96 x aws_cloudwatch_log_metric_filter ∙ 58 x aws_route_table_association ∙ 58 x aws_subnet ∙ 52 x aws_route ∙ 47 x aws_iam_role_policy ∙ 40 x aws_network_acl_rule ∙ 34 x aws_ecr_lifecycle_policy ∙ 34 x aws_ecr_repository_policy ∙ 33 x aws_s3_bucket_public_access_block ∙ 32 x aws_security_group ∙ 30 x aws_lambda_permission ∙ 27 x aws_s3_bucket_policy ∙ 26 x aws_iam_access_key ∙ 26 x aws_iam_user ∙ 24 x aws_network_acl ∙ 24 x aws_route_table ∙ 24 x aws_vpc_peering_connection_options ∙ 22 x aws_iam_group_policy_attachment ∙ 20 x aws_vpc_endpoint ∙ 16 x aws_iam_user_login_profile ∙ 16 x aws_sns_topic_subscription ∙ 15 x aws_kms_alias ∙ 14 x aws_vpc_peering_connection_accepter ∙ 13 x aws_cloudwatch_event_target ∙ 13 x aws_kms_ciphertext ∙ 12 x aws_iam_instance_profile ∙ 12 x aws_internet_gateway ∙ 12 x aws_vpc ∙ 12 x aws_vpc_peering_connection ∙ 9 x aws_iam_group ∙ 9 x aws_iam_group_membership ∙ 9 x aws_iam_openid_connect_provider ∙ 9 x aws_iam_policy_attachment ∙ 8 x aws_config_configuration_recorder_status ∙ 8 x aws_config_delivery_channel ∙ 8 x aws_key_pair ∙ 7 x aws_cloudwatch_event_rule ∙ 7 x aws_route53_zone_association ∙ 7 x aws_ssm_parameter ∙ 6 x aws_ebs_encryption_by_default ∙ 6 x aws_ec2_tag ∙ 6 x aws_iam_account_alias ∙ 6 x aws_iam_account_password_policy ∙ 6 x aws_s3_account_public_access_block ∙ 5 x aws_s3_bucket_ownership_controls ∙ 4 x aws_eip ∙ 4 x aws_flow_log ∙ 4 x aws_iam_service_linked_role ∙ 4 x aws_iam_user_policy ∙ 4 x aws_launch_template ∙ 4 x aws_s3_bucket_acl ∙ 4 x aws_s3_bucket_server_side_encryption_configuration ∙ 3 x aws_backup_plan ∙ 3 x aws_backup_selection ∙ 3 x aws_cloudfront_origin_access_identity ∙ 3 x aws_networkfirewall_rule_group ∙ 3 x aws_s3_bucket_replication_configuration ∙ 3 x aws_sns_topic_policy ∙ 2 x aws_acm_certificate ∙ 2 x aws_acm_certificate_validation ∙ 2 x aws_db_parameter_group ∙ 2 x aws_db_subnet_group ∙ 2 x aws_eip_association ∙ 2 x aws_s3_bucket_versioning ∙ 2 x aws_transfer_ssh_key ∙ 2 x aws_transfer_user ∙ 1 x aws_accessanalyzer_analyzer ∙ 1 x aws_apigatewayv2_integration ∙ 1 x aws_apigatewayv2_route ∙ 1 x aws_apigatewayv2_stage ∙ 1 x aws_backup_global_settings ∙ 1 x aws_backup_vault_notifications ∙ 1 x aws_cloudwatch_log_resource_policy ∙ 1 x aws_config_configuration_aggregator ∙ 1 x aws_db_option_group ∙ 1 x aws_lambda_event_source_mapping ∙ 1 x aws_lb_listener ∙ 1 x aws_networkfirewall_firewall_policy ∙ 1 x aws_s3_bucket_logging ∙ 1 x aws_s3_bucket_notification ∙ 1 x aws_secretsmanager_secret_policy ∙ 1 x aws_secretsmanager_secret_version ∙ 1 x aws_sqs_queue_policy ∙ 1 x aws_wafv2_web_acl_association ∙ 1 x aws_wafv2_web_acl_logging_configuration ∙ 147 are not supported yet, see https://infracost.io/requested-resources: ∙ 29 x aws_identitystore_group_membership ∙ 15 x aws_identitystore_user ∙ 15 x aws_ssoadmin_account_assignment ∙ 13 x aws_organizations_policy_attachment ∙ 10 x aws_guardduty_member ∙ 7 x aws_route53_vpc_association_authorization ∙ 7 x aws_ssoadmin_permission_set ∙ 6 x aws_identitystore_group ∙ 6 x aws_organizations_account ∙ 6 x aws_ssoadmin_managed_policy_attachment ∙ 5 x aws_fms_policy ∙ 5 x aws_organizations_organizational_unit ∙ 4 x aws_guardduty_detector ∙ 4 x aws_organizations_policy ∙ 2 x aws_budgets_budget ∙ 2 x aws_guardduty_organization_admin_account ∙ 2 x aws_guardduty_organization_configuration ∙ 2 x aws_ssoadmin_permission_set_inline_policy ∙ 1 x aws_fms_admin_account ∙ 1 x aws_organizations_delegated_administrator ∙ 1 x aws_organizations_organization ∙ 1 x aws_route53_resolver_firewall_domain_list ∙ 1 x aws_route53_resolver_firewall_rule ∙ 1 x aws_route53_resolver_firewall_rule_group ∙ 1 x aws_s3_object ```

This comment will be updated when the cost estimate changes.

Is this comment useful? Yes, No, Other

rodriguez-matias commented 1 year ago

terraform commands

leverage terraform init

[11:55:58.950] INFO     Checking environment name definition in account.tfvars...
[11:55:58.958] INFO     ✔ OK
[11:55:58.961] WARNING  ‼ Account directory name does not match environment name.
                          Expected root, found management
[11:55:58.964] INFO     Checking backend key...
[11:55:58.967] INFO     Found: 'root/organizations/terraform.tfstate'
[11:55:58.969] INFO     ✔ OK
[11:55:58.973] INFO     Checking backend.tfvars:
[11:55:58.975] INFO     Checking if profile starts with bb-root...
[11:55:58.978] INFO     ✔ OK
[11:55:58.981] INFO     Checking if bucket starts with bb-root...
[11:55:58.982] INFO     ✔ OK
[11:55:58.985] INFO     Checking if dynamodb table starts with bb-root...
[11:55:58.989] INFO     ✔ OK
[14:56:01]    INFO      Attempting to get temporary credentials for root account.
[14:56:03]    INFO      Using already configured temporary credentials.

Initializing the backend...

Initializing provider plugins...
- Finding latest version of hashicorp/null...
- Finding hashicorp/aws versions matching "~> 4.0"...
- Installing hashicorp/null v3.2.1...
- Installed hashicorp/null v3.2.1 (signed by HashiCorp)
- Installing hashicorp/aws v4.67.0...
- Installed hashicorp/aws v4.67.0 (signed by HashiCorp)

Terraform has created a lock file .terraform.lock.hcl to record the provider
selections it made above. Include this file in your version control repository
so that Terraform can guarantee to make the same selections by default when
you run "terraform init" in the future.

Terraform has been successfully initialized!

You may now begin working with Terraform. Try running "terraform plan" to see
any changes that are required for your infrastructure. All Terraform commands
should now work.

If you ever set or change modules or backend configuration for Terraform,
rerun this command to reinitialize your working directory. If you forget, other
commands will detect it and remind you to do so if necessary.
rodriguez-matias commented 1 year ago

leverage terraform plan

[14:49:59]    INFO      Attempting to get temporary credentials for root account.
[14:50:01]    INFO      Using already configured temporary credentials.
null_resource.ram_enable_sharing_with_aws_organization: Refreshing state... [id=66666666666]
aws_organizations_policy.delete_protection: Refreshing state... [id=p-ffffffff]
aws_organizations_account.root: Refreshing state... [id=777777777777]
aws_organizations_organization.main: Refreshing state... [id=o-6666666]
aws_organizations_policy.standard: Refreshing state... [id=p-ggggggg]

aws_organizations_policy.default: Refreshing state... [id=p-5656556]
aws_organizations_organizational_unit.units["security"]: Refreshing state... [id=ou-xxxxxx-0r3x4pz3]
aws_organizations_organizational_unit.units["network"]: Refreshing state... [id=ou-xxxxx-xyr6h0er]
aws_organizations_organizational_unit.units["bbl_apps_devstg"]: Refreshing state... [id=ou-xxxxx-yl3npduj]
aws_organizations_organizational_unit.units["bbl_apps_prd"]: Refreshing state... [id=ou-xxxxxx-78mid8ji]
aws_organizations_organizational_unit.units["shared"]: Refreshing state... [id=ou-xxxxx-tbfuw3cz]
aws_organizations_account.accounts["shared"]: Refreshing state... [id=7777777777]
aws_organizations_policy_attachment.delete_protection["bbl_apps_devstg"]: Refreshing state... [id=ou-xxxxxx-yl3npduj:p-m6li7ssz]
aws_organizations_policy_attachment.delete_protection["bbl_apps_prd"]: Refreshing state... [id=ou-xxxxxxxxxx-78mid8ji:p-m6li7ssz]
aws_organizations_policy_attachment.policy_attachments["bbl_apps_devstg"]: Refreshing state... [id=ou-xxxxxxxxxx-yl3npduj:p-]
aws_organizations_account.accounts["apps-devstg"]: Refreshing state... [id=55555555555]
aws_organizations_account.accounts["apps-prd"]: Refreshing state... [id=88888888888]
aws_organizations_policy_attachment.delete_protection["network"]: Refreshing state... [id=ou-xxxxxxxxxx-:p-m6li7ssz]
aws_organizations_account.accounts["network"]: Refreshing state... [id=222222222]
aws_organizations_policy_attachment.delete_protection["shared"]: Refreshing state... [id=ou-xxxxxxxxxx-:p-m6li7ssz]
aws_organizations_account.accounts["security"]: Refreshing state... [id=9999999]
aws_organizations_policy_attachment.policy_attachments["bbl_apps_prd"]: Refreshing state... [id=ou-xxxxxxxxxx-78mid8ji:p-b85e42hx]
aws_organizations_policy_attachment.policy_attachments["network"]: Refreshing state... [id=ou-xxxxxxxxxx-xyr6h0er:p-up97og9o]
aws_organizations_policy_attachment.policy_attachments["security"]: Refreshing state... [id=ou-xxxxxxxxxx-0r3x4pz3:p-up97og9o]
aws_organizations_policy_attachment.policy_attachments["shared"]: Refreshing state... [id=ou-xxxxxxxxxx-tbfuw3cz:p-b85e42hx]
aws_organizations_policy.tag_protection: Refreshing state... [id=p-77777ggg]
aws_organizations_policy_attachment.tag_protection["bbl_apps_devstg"]: Refreshing state... [id=ou-xxxxxxxxxx-yl3npduj:p-7nyj6n2n]
aws_organizations_policy_attachment.tag_protection["bbl_apps_prd"]: Refreshing state... [id=ou-xxxxxxxxxx-:p-7nyj6n2n]
aws_organizations_policy_attachment.tag_protection["shared"]: Refreshing state... [id=ou-xxxxxxxxxx-tbfuw3cz:p-7nyj6n2n]
aws_organizations_policy_attachment.tag_protection["network"]: Refreshing state... [id=ou-xxxxxxxxxx-:p-7nyj6n2n]

Terraform used the selected providers to generate the following execution plan. Resource actions are indicated with the following symbols:
  + create

Terraform will perform the following actions:

  # aws_iam_service_linked_role.access_analyzer will be created
  + resource "aws_iam_service_linked_role" "access_analyzer" {
      + arn              = (known after apply)
      + aws_service_name = "access-analyzer.amazonaws.com"
      + create_date      = (known after apply)
      + id               = (known after apply)
      + name             = (known after apply)
      + path             = (known after apply)
      + tags_all         = (known after apply)
      + unique_id        = (known after apply)
    }

  # aws_organizations_delegated_administrator.access_analyzer_administrator will be created
  + resource "aws_organizations_delegated_administrator" "access_analyzer_administrator" {
      + account_id              = "9999999"
      + arn                     = (known after apply)
      + delegation_enabled_date = (known after apply)
      + email                   = (known after apply)
      + id                      = (known after apply)
      + joined_method           = (known after apply)
      + joined_timestamp        = (known after apply)
      + name                    = (known after apply)
      + service_principal       = "access-analyzer.amazonaws.com"
      + status                  = (known after apply)
    }

Plan: 2 to add, 0 to change, 0 to destroy.
rodriguez-matias commented 1 year ago

leverage terraform plan

image