Supplement · AWS
Organizations, Control Tower và landing zone
Multi-account là isolation primitive: tách production, security, log archive, networking và sandbox để giảm blast radius, phân quyền và chi phí rõ ràng.
Hierarchy và guardrail
- Organization chứa Organizational Unit (OU) và account. OU phản ánh policy boundary/lifecycle, không nên sao chép org chart quá chi tiết.
- Service Control Policy (SCP) đặt permission ceiling; SCP không cấp quyền và không thay resource policy. Deny sai ở root có thể chặn cả break-glass.
- Control Tower dựng landing zone và preventive/detective/proactive controls; vẫn cần account vending, network baseline, centralized logs và lifecycle offboarding.
Thiết kế vận hành
Dùng management account tối thiểu; delegated administrator cho security services. Log archive cần immutable-enough retention và quyền tách biệt. Account factory phải tạo owner, tags, budgets, identity federation, baseline IaC và evidence. Mọi exception cần owner, expiry và compensating control.
Anti-pattern: một account chung cho mọi môi trường; SCP deny theo tên service mà không test deployment/recovery path; security team vừa quản log vừa có quyền xóa log.