Skip to content

Create Amplify resources in acc to Control Tower enforced policies #1566

Open
@vishal-dms

Description

@vishal-dms

Environment information

N/A

Description

S3 buckets used for storing metadata like data schema does not follow Control Tower enforced policies as they are the best recommendations documented by AWS -

For e.g. the buckets don't have the following -

  • There's no versioning enabled.
  • No logging policy is applied.

This discrepancy between AWS's recommended deployment practices with Amplify Gen 2 vs the Control Tower's enforced policies

https://docs.aws.amazon.com/controltower/latest/controlreference/s3-rules.html

Same as Gen1 FR - aws-amplify/amplify-cli#13617

Metadata

Metadata

Assignees

No one assigned

    Labels

    feature-requestNew feature or requestneeds-product-inputNeeds non-technical requirements or direction to proceed

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions