Unable to update Control Tower landing zone, when config recorder managed in audit account has been deleted

0

Steps to reproduce issue :

  • Control tower landing zone is configured
  • Config recorder for audit account has been accidentally deleted through CLI
  • Try to Update Landing zone
  • Failed with error : "AWS Control Tower could not find the configuration recorder for account <audit_account_id> in region <region>. It may have been deleted. Update account under OU the try again, or contact AWS Support. My question is how is the best way to re-create this config recorder.

Thank you for your help.

profile picture
aolfa
asked 10 months ago289 views
1 Answer
1
Accepted Answer

Hello aolfa, I think redeploying the StackSet 'AWSControlTowerBP-BASELINE-CONFIG' to your audit account would be helpful in resolving your issue I recommend deleting the stack instance for your audit account by following the steps outlined in this document [1], and then recreating the stack instance by updating the StackSet "AWSControlTowerBP-BASELINE-CONFIG" [2]. [1] - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/stackinstances-delete.html [2] - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/stackinstances-create.html I hope this method works. :)

profile pictureAWS
answered 10 months ago
profile picture
EXPERT
reviewed 13 days ago
profile picture
EXPERT
reviewed 10 months ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions