View cross-account executions
Operation Orchestration Service (OOS) integrates with Resource Directory to let a delegated administrator view execution lists and details for member accounts from a central location, without logging in to each account individually.
How it works
Cross-account viewing in OOS relies on trusted service integration with Resource Directory and consists of two stages:
-
OOS accesses Resource Directory as a management account or delegated administrator to retrieve the organization's member list and folder structure.
-
The management account or delegated administrator can then query execution data from each managed account.
When you view the cross-account execution list, OOS concurrently fetches and aggregates execution data from each member account.
Prerequisites
Ensure that you meet the following prerequisites:
-
Resource Directory is enabled. For more information, see Enable Resource Directory.
-
Your current account must be either the management account of Resource Directory or a delegated administrator for OOS.
Procedure
Step 1: Set up a delegated administrator
A delegated administrator can manage OOS cross-account features for the entire organization.
You must perform this operation using the management account of your Resource Directory.
-
Log on to the Resource Management console using the management account.
-
In the navigation pane on the left, click Trusted Services.
-
In the list of trusted services, find CloudOps Orchestration Service and click Manage.
-
On the delegated administrator page, add a member account and designate it as the delegated administrator for OOS.
Step 2: Enable multi-account management
Log on to the OOS console as the delegated administrator and enable the Multi-Account Management feature.
-
Log on to the OOS console.
-
In the navigation pane on the left, click Multi-Account Management.
-
On the Multi-Account Management page, click Enable Multi-Account Management.
Step 3: Configure managed accounts
After you enable Multi-Account Management, select the folders that contain the accounts to manage.
-
On the Multi-Account Management page, click Configure Managed Accounts.
-
In the list of folders, select the folders to manage.
-
If you select the Root folder, OOS will manage all member accounts in your Resource Directory.
-
If you select a specific folder, OOS will manage only the member accounts within that folder.
-
-
Click OK.
You can find the folder ID on the Management page in the Resource Management console. For more information, see View basic information about a resource folder.
Step 4: View the cross-account execution list
After you configure managed accounts, view execution records for all member accounts on the Task Execution Management page.
-
In the OOS console, click Task Execution Management in the navigation pane on the left.
-
In the filter bar, click the Resource Directory filter and select a target folder or member account.
-
The execution list displays the execution records for all member accounts in the selected scope. The account ID column identifies the account for each execution.
Step 5: View execution details
Viewing cross-account execution details follows the same process as for a single account, but the data comes from the target member account.
-
In the execution list, click the target execution ID.
-
On the execution details page, you can view the following information:
-
task execution status: The result of each task step.
-
execution logs: The complete logs for the execution.
-
Trigger History: The source and time of the trigger.
-