Skip to main content

Python package to automatically build the AWS Control Tower Manifest given Cloud Formation templates as input.

Project description

AWS Control Tower Manifest Builder

https://img.shields.io/pypi/v/aws_control_tower_manifest_builder.svg https://github.com/gabrielbac/aws_control_tower_manifest_builder/actions/workflows/test.yaml/badge.svg https://github.com/gabrielbac/aws_control_tower_manifest_builder/actions/workflows/release.yaml/badge.svg Documentation Status

Python package to automatically build the AWS Control Tower Manifest given Cloud Formation templates and SCPs as input.

Features

Pipeline.drawio.png

Quick start

  1. Run pip install aws-control-tower-manifest-builder

  2. Download sample template and SCPs from S3 “Add link”. Extract to directory

  3. Run aws_control_tower_manifest_builder --input-cf sample_templates --input-scp sample_scp --output output_manifest

    Note: the sample template includes incorrecly formatted templates.

For Developers - before pushing a branch

  1. Clone the repo

  2. make venv

  3. make black

  4. make lint

  5. make test

  6. make local-test

To bump version: 1. Update HISTORY.rst 2. git fetch to fetch all tags 3. make bump-<patch-minor-major> 4. Make a release in Github and add a tag.

  • Cloud Formation templates require a metadata section with the following info:

Metadata:
  manifest_parameters: # can be customized with --metadata-name
  name: detailed_template # Optional. Defaults to the file name. a-z, A-Z, 0-9, and "-"
  description: string # Required for SCPs
  deploy_method: stackset # Optional. All file in the template directory use "stackset" and in policy directory use "scp".
  accounts: ["123456789012", "987456123989"] # Requires "accounts" and/or "organizational_unit". If accounts is used, enforce only account
                                             # IDs with --enforce-account-number-only
  organizational_units: ["dev", "prod"] # Requires "accounts" and/or "organizational_unit".
  regions: ["us-east-1" , "us-east-2"] # Optional. Defaults to us-east-1.
  parameters: # Optional. List of parameters [SSM, Alfred, Values]
  - parameter_key: parameter1
    parameter_value: value1
  - parameter_key: parameter2
    parameter_value: value2
  export_outputs: # Optional. list of ssm parameters to store output values
  - name: /org/member/test-ssm/app-id
    value: $[output_ApplicationId]

History

0.3.1 (2022-03-03)

  • First release on PyPI.

0.4.0 (2022-03-27)

  • Change to mantain order, comments and support exclamation marks in Cloudformation

0.4.1 (2022-03-27)

  • Fix for the default region option

0.5.0 (2022-03-29)

  • Add argument to set schema version

0.5.1 (2022-03-24)

  • Fix issue when leaving region blank not picking default value

0.5.2 (2022-04-08)

  • Fail if files name or name in metadata dont match regex

0.5.3 (2022-04-09)

  • Fix in logging and update to Readme

0.5.4 (2022-04-18)

  • Exit with error when there is an issue in any manifest file

0.6.0 (2022-05-18)

  • Enforce description in SCP and correct extension

0.7.0 (2022-08-28)

  • Added 2 new options

    –metadata-name -> to customize the name in the metadata –enforce-account-number-only -> Allows to enforce use of 12 digit account numbers The input scps folder is not mandatory anymore

0.8.0 (2022-09-08)

  • Added 1 new option

    –enable_stack_set_deletion -> defaults to False. Set to True to enable the CT pipeline to delete stacksets.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distribution

aws_control_tower_manifest_builder-0.10.0-py2.py3-none-any.whl (11.8 kB view details)

Uploaded Python 2 Python 3

File details

Details for the file aws_control_tower_manifest_builder-0.10.0-py2.py3-none-any.whl.

File metadata

File hashes

Hashes for aws_control_tower_manifest_builder-0.10.0-py2.py3-none-any.whl
Algorithm Hash digest
SHA256 19a91e4eef8399416ccba34bc1106ce97dec4c53e3bf40aa507709ec553061ee
MD5 ee7db00de0d2c86663feff21a6273cda
BLAKE2b-256 f0a3be5b234c7e6f54a968ed93e555ddde3e0a5139d0aa61dee36c6d7761480d

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page