AWS Control Tower Landing Zone 4.0 में अपग्रेड करना
परिचय
यदि आप AWS Control Tower Landing Zone 3.x का उपयोग कर रहे हैं, तो अब आप version 4.0 में अपग्रेड कर सकते हैं ताकि आप अपने AWS organization में governance controls लागू करने में अधिक flexibility प्राप्त कर सकें। यह पोस्ट प ्रमुख architectural changes के बारे में मार्गदर्शन करती है, migration impact को समझने में मदद करती है, और एक सफल upgrade के लिए step-by-step मार्गदर्शन प्रदान करती है।
AWS Control Tower के पिछले versions (3.x और पहले) में, landing zone को सक्षम करने के लिए आपको mandatory service integrations के साथ एक predefined organizational structure स्वीकार करनी होती थी। Landing Zone 4.0 इन constraints को हटाता है, जिससे आप:
- अपनी मौजूदा organization को restructure किए बिना AWS Control Catalog से 1,200 से अधिक controls तक पहुंच प्राप्त कर सकते हैं
- अब आपके पास अपनी विशिष्ट आवश्यकताओं के आधार पर कौन सी AWS services सक्षम करनी हैं यह चुनने की स्वतंत्रता है। Service integrations अब mandatory नहीं हैं, जिससे आप:
- केवल आवश्यकता पड़ने पर detective controls के लिए AWS Config सक्षम कर सकते हैं
- यदि आपके पास मौजूदा audit logging solutions हैं तो AWS CloudTrail को स्वतंत्र रूप से प्रबंधित कर सकते हैं
- अपनी identity management strategy के आधार पर AWS IAM Identity Center में opt-in कर सकते हैं
- अपनी backup आवश्यकताओं के अनुसार AWS Backup integration को control कर सकते हैं
- AWS Control Tower governance लागू करते हुए अपनी own organizational unit (OU) hierarchy परिभाषित कर सकते हैं
- Dedicated service integration accounts की आवश्यकता के बिना केवल AWS Organizations integration और controls के साथ एक minimal landing zone deploy कर सकते हैं
यह controls-dedicated model विशेष रूप से मौजूदा landing zones वाले enterprises के लिए मूल्यवान है, क्योंकि यह आपको AWS Control Tower governance को incrementally अपनाने की अनुमति देता है। आप पिछले versions में आवश्यक extensive restructuring के बिना controls और compliance monitoring लागू कर सकते हैं।
AWS Control Catalog से अधिकतम मूल्य प्राप्त करने पर अतिरिक्त मार्गदर्शन के लिए, AWS documentation देखें: Search and discover governance controls with Control Catalog in AWS Control Tower।
Benefits और architectural changes
Landing Zone 4.0 महत्वपूर्ण सुधार प्रस्तुत करता है जो अधिक flexibility और operational efficiency प्रदान करते हैं। निम्नलिखित comparison version 3.x और 4.0 के बीच प्रमुख अंतरों को highlight करता है:
| Feature | Version 3.x | Version 4.0 |
|---|---|---|
| Service integrations | Mandatory | Optional |
| AWS Config S3 bucket | AWS CloudTrail के साथ Shared | Dedicated bucket |
| AWS Config aggregator | Organization + Account aggregators | Service-linked aggregator |
| Delegated administrator | None | AWS Config के लिए Audit account |
| OU structure | Mandatory Security OU | Flexible, customer-defined |
| Manifest field | Required | Optional |
| Config baseline | AWSControlTowerBaseline का हिस्सा | Standalone ConfigBaseline |
| Drift notifications | Amazon SNS | Amazon EventBridge |
Prerequisites
AWS Control Tower Landing Zone 4.0 में upgrade करने से पहले, सुनिश्चित करें कि आप निम्नलिखित आवश्यकताओं को पूरा करते हैं:
महत्वपूर्ण: यह upgrade irreversible है। AWS Control Tower पिछले landing zone version में downgrade का समर्थन नहीं करता। एक बार Landing Zone 4.0 में upgrade करने के बाद, आप version 3.x पर वापस नहीं जा सकते। पहले non-production environment में upgrade का परीक्षण करने और आगे बढ़ने से पहले comprehensive backups लेने की दृढ़ता से अनुशंसा की जाती है।
सामान्य prerequisites
-
Organizational drift को resolve करें: Landing Zone 4.0 में upgrade करने से पहले सभी organizational drifts को resolve करने की दृढ़ता से अनुशंसा की जाती है। आप AWS Control Tower console में drift check कर सकते हैं। Upgrade से पहले unresolved drift upgrade के बाद और OU re-registration के बाद भी persist हो सकती है, जिसे resolve करने के लिए AWS Support case की आवश्यकता हो सकती है।
-
AWS Control Tower prerequisites की समीक्षा करें: सुनिश्चित करें कि आपका environment सभी standard AWS Control Tower prerequisites को पूरा करता है।
-
Service integration dependencies की समीक्षा करें: Baselines के बीच dependencies को समझें। यदि आप भविष्य में AWS Config integration अक्षम करने की योजना बनाते हैं, तो service dependencies के कारण आपको Security Roles, AWS IAM Identity Center, और AWS Backup integrations भी अक्षम करने होंगे।
-
Comprehensive backups लें: Upgrade करने से पहले, अपनी वर्तमान configuration को document और back up करें:
- Organizational structure (OUs, accounts, account-to-OU mappings) export करें
- वर्तमान Landing Zone settings, Config aggregator views, और SNS topic configurations का screenshot या export करें
- Config rules और aggregator configurations export करें
- CloudFormation StackSet templates और parameters export करें
- प्रति OU current baseline versions और प्रति OU control enablement status document करें
- यदि applicable हो तो CfCT CloudFormation templates save करें
# Export organizational units
aws organizations list-organizational-units-for-parent \
--parent-id <ROOT_ID> > org_units_backup.json
# Export all accounts
aws organizations list-accounts > accounts_backup.json
# Export Config rules
aws configservice describe-config-rules > config_rules_backup.json
# Export Config aggregators
aws configservice describe-configuration-aggregators > aggregators_backup.json
# Export Control Tower IAM roles
aws iam get-role --role-name AWSControlTowerExecution > ct_exec_role_backup.json
aws iam get-role --role-name AWSControlTowerCloudTrailRole > ct_cloudtrail_role_backup.json
AWS CloudFormation StackSet prerequisites
Closed/suspended account stack instances हटाएं
जब AWS accounts close किए जाते हैं, तो management account के AWSControlTowerBP-* StackSets में उनके AWS CloudFormation stack instances स्वचालित रूप से हटाए नहीं जाते। Upgrade के दौरान, AWS Control Tower इन StackSets को update करने का प्रयास करता है और विफल हो जाता है क्योंकि यह closed accounts में AWSControlTowerExecution assume नहीं कर सकता। यह एक documented limitation है।
Pre-flight check:
# Identify closed/suspended accounts
CLOSED=$(aws organizations list-accounts \
--query "Accounts[?Status!='ACTIVE'].Id" --output text)
# Check for orphaned stack instances in AWS Control Tower StackSets
for SS in $(aws cloudformation list-stack-sets --status ACTIVE \
--query "Summaries[?starts_with(StackSetName,'AWSControlTowerBP-')].StackSetName" \
--output text); do
for ACCT in $CLOSED; do
COUNT=$(aws cloudformation list-stack-instances --stack-set-name "$SS" \
--query "length(Summaries[?Account=='${ACCT}'])" --output text)
[ "$COUNT" -gt 0 ] && echo "BLOCKER: $SS has $COUNT instances for closed account $ACCT"
done
done
सुझावित Remediation:
# For each StackSet flagged as BLOCKER in the pre-flight check above,
# remove the orphaned instances for the closed account
aws cloudformation delete-stack-instances \
--stack-set-name "<stackset-name>" \
--accounts '["<closed-account-id>"]' \
--regions '["us-east-1","us-west-2"]' \
--retain-stacks \
--no-cli-pager
महत्वपूर्ण:
--retain-stacksflag आवश ्यक है। इसके बिना, AWS CloudFormation stack delete करने के लिए closed account मेंAWSControlTowerExecutionassume करने का प्रयास करता है, जो विफल होगा।
AWS Control Tower baseline stacks पर termination protection verify करें
v4.0 upgrade member accounts में कुछ AWS CloudFormation stacks (विशेष रूप से AWS Config-related baselines) को delete या replace करता है। यदि उन stacks पर termination protection सक्षम है, तो StackSet operations विफल हो जाते हैं और upgrade stall हो जाता है।
Pre-flight check (management account से चलाएं):
# Assume role into a member account
CREDS=$(aws sts assume-role \
--role-arn "arn:aws:iam::<member-account-id>:role/AWSControlTowerExecution" \
--role-session-name "tp-check" --query Credentials --output json)
export AWS_ACCESS_KEY_ID=$(echo $CREDS | jq -r .AccessKeyId)
export AWS_SECRET_ACCESS_KEY=$(echo $CREDS | jq -r .SecretAccessKey)
export AWS_SESSION_TOKEN=$(echo $CREDS | jq -r .SessionToken)
# Check AWS Control Tower baseline stacks for termination protection
aws cloudformation describe-stacks --region <region> \
--query "Stacks[?starts_with(StackName,'StackSet-AWSControlTowerBP-')].\
[StackName,EnableTerminationProtection]" --output table
सुझावित Remediation:
aws cloudformation update-termination-protection \
--no-enable-termination-protection \
--stack-name "<stack-name>" --region <region>
AWS CloudTrail prerequisites
यदि आप API के माध्यम से upgrade कर रहे हैं और AWS CloudTrail integration सक्षम है:
- IAM role policy अपडेट करें:
AWSControlTowerCloudTrailRoleसे मौजूदा inline policy detach करें और नई managed policyAWSControlTowerCloudTrailRolePolicyattach करें।
# Detach inline policy
aws iam delete-role-policy \
--role-name AWSControlTowerCloudTrailRole \
--policy-name <inline-policy-name>
# Attach new managed policy
aws iam attach-role-policy \
--role-name AWSControlTowerCloudTrailRole \
--policy-arn arn:aws:iam::aws:policy/service-role/AWSControlTowerCloudTrailRolePolicy