Automatically deploy stacks

更新时间:
复制 MD 格式

After enabling a resource directory, you can configure automatic deployment when you create a stack group with service-managed permissions by using the management account or a delegated administrator account. When you enable automatic deployment, ROS automatically deploys stacks to new member accounts added to a target folder and deletes stacks from accounts removed from that folder. This feature lets you centrally manage stacks in your member accounts. You can also modify the automatic deployment settings.

Prerequisites

Ensure that you have created a stack group with service-managed permissions. For more information, see Step 3: Create a stack group.

Use cases

After you enable automatic deployment, when you add a new member account to a target folder, the stack group automatically deploys stacks to that account. When you remove a member account from a target folder, the stack group automatically deletes the stacks from that account.

The following scenarios describe how automatic deployment works:

  • Scenario 1: A member account is moved between folders.

    Assume that automatic deployment is enabled for a stack group that targets Folder 1 and Folder 2 in your resource directory. Moving a member account from Folder 1 to Folder 2 triggers an automatic deployment. ROS deletes the stacks from the target regions of the member account in Folder 1 and creates identical stacks in the target regions of the account in Folder 2.

  • Scenario 2: A new member account is added to a folder.

    Assume that automatic deployment is enabled for a stack group that targets a folder. Adding a new member account, Account A, to the folder triggers an automatic deployment to create stacks in its target regions. If you add another member account, Account B, while stacks are being deployed to Account A, the stack group finishes the deployment for Account A before starting the deployment for Account B.

Note

You can enable automatic deployment only for stack groups. You cannot enable this feature for individual folders, member accounts, or regions.

Regions

When you add a new or existing member account to a target folder, the deployment targets the regions specified for the stacks in the stack group.

If the stack group already contains stack instances, the deployment targets all regions where those instances exist. If the stack group has no stack instances, the deployment targets the regions that you specify when you create the first stack instances.

Procedure

  1. Log on to the ROS console using the management account or a delegated administrator account of your resource directory.

    Note The logon account must be the same account that was used to create the stack group.
  2. In the navigation pane on the left, click Stack Groups.

  3. From the region drop-down list in the top navigation bar, select the region where your stack group is located.

  4. Click the name of the target stack group.

  5. On the Stack Group Information tab, in the Deployment Configurations section, click Edit Automatic Deployment.

  6. In the Edit Automatic Deployment dialog box, set Automatic Deployment to Enabled and configure the Account Removal Behavior.

    For more information about automatic deployment and account removal behavior, see Parameter descriptions.

    Important

    If you set Account Removal Behavior to Retain Stacks, the stacks and their related resources are retained after the account is removed from the target folders. The resources remain in their current state but are no longer part of the stack group. The retained stacks cannot be reassociated with the original or a new stack group.

  7. Click Save.