Skip to content

Conversation

@batzel
Copy link

@batzel batzel commented Apr 30, 2024

Issue #25 fix, Look at AWSControlTowerBP-BASELINE-CLOUDWATCH since cloudtrail stackset changed.
Added some comments to manifest.yaml to clarify multi-region deployment options.
Updated bucket policy to make it non-Public so it works with newer default s3 bucket settings.
Changed the bucket policy to allow accounts to see and read only data that account had logged. (Previously let any account read all flowlogs in the organization.)
Moved management_prep.template out of templates/ to make zipping easier: zip -r cfct-aws-ct-vpc-flowlogs.zip manifest.yaml templates/

The bucket policy was being refused with an "Access Denied" which turned out to be because the policy didn't lock the logging service down to being in the source organization.

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

…et changed.

Add comments and examples about managing multiple regions and the main region.
…r: zip -r cfct-aws-ct-vpc-flowlogs.zip manifest.yaml templates/
@wellsiau-aws wellsiau-aws self-assigned this May 9, 2024
@wellsiau-aws wellsiau-aws added bug Something isn't working enhancement New feature or request labels May 9, 2024
@wellsiau-aws
Copy link
Collaborator

@batzel , thank you for opening the pull request. I have assigned myself to review this. However, please expect delay in my response.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants