Comments (4)
Hello @FlemmingBehrend,
error: undefined
in the prepare stage generally points to issues fetching account IDs for your organization based on the email addresses entered in accounts-config.yaml.
We are actively working to improve our error messaging here to make that clear. In the meantime, can you please verify the email addresses for your mandatory and workload accounts match exactly what is in AWS Organizations?
Note: email addresses for the mandatory accounts are pushed to the config file from the installer stack parameters, so you may update those there if any of the emails differ. For workload accounts, you may update the accounts-config.yaml
directly.
Thanks, and please keep us updated!
from landing-zone-accelerator-on-aws.
Hi @awsclemj
It was as you said a typo in the account email for the management account. There are a couple of things that I was wondering about.
-
Why do we need to specify the email address for the management account?
My assumption here is the ALZ is always installed in the management account or can it be deployed in another account. The account number could just be looked up. -
If the email is wrong could you fail earlier?
If the management account email is wrong could the solution fail in theAWSAccelerator-Installer
pipeline instead of waiting until the prepare script in theAWSAccelerator-Pipeline
-
The
aws-accelerator-config
repo was not updated
Running theAWSAccelerator-Installer
again with the correct email in the stack parameters did not update theaccounts-config.yaml
, I had to do that manually afterwards before running theAWSAccelerator-Pipeline
Thanks for the help 👍
Looking forward to better error messages 😄
from landing-zone-accelerator-on-aws.
Hello @FlemmingBehrend Thank you for the valuable feedback.
- Why do we need to specify the email address for the management account?
This is needed so that the aws-accelerator-config repository can populate the correct email addresses when generating the base configuration. It is designed to be compatible with partitions that may not have organizations support.
- If the email is wrong could you fail earlier?
It is possible for us to fail sooner than the prepare stage. Our team will evaluate this and add it to our feature requests.
- The
aws-accelerator-config
repo was not updated
This is the expected behavior of the LZA. As of today, we do not programmatically modify the aws-accelerator-config after initial installation.
from landing-zone-accelerator-on-aws.
is the management account = root account? it is very unclear what account is what?! In the code is says "root" in the CFT is says "management account" which is very inconsistent!
from landing-zone-accelerator-on-aws.
Related Issues (20)
- Bootstrap stage fails with SCP implicit deny (v1.7.0) HOT 1
- Logging stack fails upgrade from 1.6.3 to 1.7.0 HOT 6
- As of LZA v 1.7.0 having a forward slash in OU name now breaks LZA with an error HOT 1
- Still having issues with Disabling Security hub Controls in LZA (1.7.0) HOT 2
- Typedocs for v1.7.0 are missing examples and remarks HOT 1
- FEATURE: Dynamic Tagging Framework HOT 2
- IMSDV2 Account Settings
- AWS Config delegated account clarification
- Enabling ca-west-1 throws an error in boostrap stage
- Enable GuardDuty delegated admin Malware Protection policy option in management account HOT 1
- Referring dynamic IP ranges allocated by IPAM to VPCs in the route tables HOT 1
- Change to guard duty check - Ensure aws config is enabled - now failing
- LZA Patch for GovCloud Feature Request HOT 1
- Default VPCs no deleted in GovCloud HOT 1
- Add support to tag network interfaces HOT 2
- GovCloud Upgrade issue v1.7.1 from v.1.6.2 HOT 1
- Management of (external) Transit Gateway Attachments HOT 1
- Safe to delete stack AWSAccelerator-LoggingStack-XXX ? HOT 1
- Pushing updates via specific stages only HOT 1
- OUs not deleted when removed from organization-config.yaml HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from landing-zone-accelerator-on-aws.