https://pulumi.com logo
#aws
Title
# aws
l

loud-nest-15724

10/06/2021, 3:27 PM
Hi all, has anyone used Pulumi to setup an AWS account vending machine? i.e. an automated way for teams to create and manage AWS accounts themselves for the components they own I've had a quick look at AWS Control Tower, and org-formation, but I'd prefer to do this with Pulumi
b

billowy-army-68599

10/06/2021, 3:59 PM
i haven't seen this so far, but it should be possible, as it's been done with terraform
one thing I will say is that the AWS Org deletion API doesn't work very well with IaC, so spinning things up should be easy, tearing them down is another thing..
👍 1
l

loud-nest-15724

10/06/2021, 4:23 PM
yeah, I think org-formation doesn't actually support deleting, which maybe makes sense in terms of wanting to be more careful with it
b

bumpy-grass-54508

10/06/2021, 6:27 PM
l

loud-nest-15724

10/06/2021, 7:17 PM
Wow 🙈 didn't realise it was so complicated to do it the manual way, and slightly scary that you can actually automate those things
f

freezing-van-87649

10/06/2021, 8:18 PM
I’ve been thinking about it a lot
not doing full creation of the account via pulumi, but doing a lot of foundational stuff after creation (like adding cross account roles from a pipeline account, standing up privileged gitlab runners, granting users access