Python package to automatically build the AWS Control Tower Manifest given Cloud Formation templates as input.
Project description
AWS Control Tower Manifest Builder
Python package to automatically build the AWS Control Tower Manifest given Cloud Formation templates and SCPs as input.
Free software: MIT license
Documentation: https://aws-control-tower-manifest-builder.readthedocs.io.
Features
Reads Cloud Formation templates and Service Control Policies from specified directories and produces the AWS Control Tower manifest.yaml file.
Quick start
Run pip install aws-control-tower-manifest-builder
Download sample template and SCPs from S3 “Add link”. Extract to directory
- Run aws_control_tower_manifest_builder --input-cf sample_templates --input-scp sample_scp --output output_manifest
Note: the sample template includes incorrecly formatted templates.
For Developers - before pushing a branch
Clone the repo
make venv
make black
make lint
make test
make local-test
To bump version: 1. Update HISTORY.rst 2. git fetch to fetch all tags 3. make bump-<patch-minor-major> 4. Make a release in Github and add a tag.
Cloud Formation templates require a metadata section with the following info:
Metadata:
manifest_parameters: # can be customized with --metadata-name
name: detailed_template # Optional. Defaults to the file name. a-z, A-Z, 0-9, and "-"
description: string # Required for SCPs
deploy_method: stackset # Optional. All file in the template directory use "stackset" and in policy directory use "scp".
accounts: ["123456789012", "987456123989"] # Requires "accounts" and/or "organizational_unit". If accounts is used, enforce only account
# IDs with --enforce-account-number-only
organizational_units: ["dev", "prod"] # Requires "accounts" and/or "organizational_unit".
regions: ["us-east-1" , "us-east-2"] # Optional. Defaults to us-east-1.
parameters: # Optional. List of parameters [SSM, Alfred, Values]
- parameter_key: parameter1
parameter_value: value1
- parameter_key: parameter2
parameter_value: value2
export_outputs: # Optional. list of ssm parameters to store output values
- name: /org/member/test-ssm/app-id
value: $[output_ApplicationId]
History
0.3.1 (2022-03-03)
First release on PyPI.
0.4.0 (2022-03-27)
Change to mantain order, comments and support exclamation marks in Cloudformation
0.4.1 (2022-03-27)
Fix for the default region option
0.5.0 (2022-03-29)
Add argument to set schema version
0.5.1 (2022-03-24)
Fix issue when leaving region blank not picking default value
0.5.2 (2022-04-08)
Fail if files name or name in metadata dont match regex
0.5.3 (2022-04-09)
Fix in logging and update to Readme
0.5.4 (2022-04-18)
Exit with error when there is an issue in any manifest file
0.6.0 (2022-05-18)
Enforce description in SCP and correct extension
0.7.0 (2022-08-28)
- Added 2 new options
–metadata-name -> to customize the name in the metadata –enforce-account-number-only -> Allows to enforce use of 12 digit account numbers The input scps folder is not mandatory anymore
0.8.0 (2022-09-08)
- Added 1 new option
–enable_stack_set_deletion -> defaults to False. Set to True to enable the CT pipeline to delete stacksets.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distributions
Built Distribution
Hashes for aws_control_tower_manifest_builder-0.10.0-py2.py3-none-any.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 19a91e4eef8399416ccba34bc1106ce97dec4c53e3bf40aa507709ec553061ee |
|
MD5 | ee7db00de0d2c86663feff21a6273cda |
|
BLAKE2b-256 | f0a3be5b234c7e6f54a968ed93e555ddde3e0a5139d0aa61dee36c6d7761480d |