How to proceed after failed landing zone creation through control tower

1

I created a management account and proceeded to create landing zone through control tower. Opted for most default options except KMS encryption with single region. The creation process part succeeded - AWSControlTowerBP-BASELINE-CONFIG-MASTER completed successfully while AWSControlTowerBP-BASELINE-CLOUDTRAIL-MASTER failed.

Failiure message

Resource handler returned message: "Invalid request provided: Insufficient permissions to access S3 bucket aws-controltower-logs-xxxxxxxx-us-east-1 or KMS key arn:aws:kms:us-east-1:xxxxxxx:key/xxxxxx. (Service: CloudTrail, Status Code: 400

The rollback for the failed stack failed too. So, I deleted the stack manually and retried the operation. Now I am with a different error as below.

Resource handler returned message: "User: arn:aws:sts::xxxxxxx:assumed-role/AWSControlTowerAdmin/AssumeAdminRole is not authorized to perform: logs:DeleteLogGroup on resource: arn:aws:logs:us-east-1:xxxxxxxxx:log-group:aws-controltower/CloudTrailLogs:log-stream: because no identity-based policy allows the logs:DeleteLogGroup action (Service: CloudWatchLogs, Status Code: 400

I could try to address these issues one by one. But will the landing zone be ever able to complete successfully now considering it was partially done and I manually deleted the stack? Or should I just delete the root and everything under it and start over?

Grog
질문됨 일 년 전2752회 조회
3개 답변
4
acollao
답변함 일 년 전
1

Hi There

I recommend performing the steps in Decommission Control Tower and manually removing resources. Specifically, check this section that outlines the resources that need to be manually removed before setting up CT again: https://docs.aws.amazon.com/controltower/latest/userguide/known-issues-decommissioning.html

profile pictureAWS
전문가
Matt-B
답변함 일 년 전
0

Thanks. Will try this out

Grog
답변함 일 년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠