AWS Control Tower Infrastructure Overview
Document Control​
| Field | Details |
|---|---|
| Project | AWS Control Tower Landing Zone |
| Version | 1.0 |
| Author | Anmol Nagpal |
| Last updated | 2026-07-01 |
Summary​
AWS Control Tower provides the governed foundation for a multi-account AWS environment. It orchestrates AWS Organizations, IAM Identity Center, AWS Service Catalog, AWS CloudFormation StackSets, AWS Config, AWS CloudTrail, and related services to create a landing zone with centralized logging, security auditing, account vending, and policy controls.
The architecture separates management, security, shared services, sandbox, and workload accounts into organizational units (OUs). This separation keeps central governance and audit functions isolated while allowing application teams to operate in governed member accounts.
Architecture​
Diagram Link​
| Diagram | Link |
|---|---|
| Architecture | Architecture diagram |
High-Level Flow​
- Cloud administrators configure AWS Control Tower from the management account.
- AWS Control Tower creates or registers the landing zone, OUs, shared accounts, baselines, and mandatory controls.
- Account Factory provisions enrolled member accounts through AWS Service Catalog and AWS Organizations.
- AWS Control Tower baselines each enrolled account with required IAM roles, logging, monitoring, and controls.
- AWS CloudTrail, AWS Config, and lifecycle events provide auditability and automation triggers.
- Security services such as GuardDuty and Security Hub can be delegated to security accounts for organization-wide visibility.
Components/Resources​
| Component/Technology | Name/Identifier | Notes |
|---|---|---|
| AWS Control Tower | Landing zone | Governance orchestration layer for the multi-account environment. |
| AWS Organizations | Organization root | Parent container for OUs, accounts, service control policies, and delegated administration. |
| Management account | Existing payer/management account | Hosts AWS Control Tower administration and organization-level orchestration. Keep workloads out of this account. |
| Security OU | Security | Contains the Log Archive and Audit accounts by default. |
| Log Archive account | Log Archive | Central account for organization audit logs such as AWS CloudTrail and AWS Config delivery. |
| Audit account | Audit | Central security review account for cross-account audit access and delegated security tooling. |
| Sandbox OU | Sandbox | Optional OU created during landing zone setup for experimentation and non-production accounts. |
| Workload OUs | Development, Staging, Production, or client standard | Registered OUs that contain enrolled workload accounts. Names should follow the client's operating model. |
| Account Factory | AWS Service Catalog product | Standardized account provisioning workflow for new governed accounts. |
| Controls | Preventive, detective, proactive | OU-level governance policies. Controls were previously called guardrails in some AWS material. |
| Baselines | AWSControlTowerBaseline | Applies required account and OU configuration for managed accounts and OUs. |
| IAM Identity Center | Identity directory or external IdP integration | Central access portal and permission set assignment model for users and groups. |
| IAM roles | AWSControlTowerExecution, audit roles, service roles | Cross-account roles used by AWS Control Tower and audit workflows. |
| AWS CloudFormation StackSets | AWS Control Tower managed StackSets | Deploys baseline resources into enrolled accounts and Regions. |
| AWS CloudTrail | Organization trails and lifecycle events | Records account, governance, and lifecycle activity for audit and automation. |
| AWS Config | Recorders, rules, aggregators | Tracks resource configuration and detective control compliance. |
| Amazon EventBridge | Control Tower lifecycle rules | Triggers automation after landing zone, account, OU, baseline, and control events. |
| Amazon S3 | Log archive buckets | Stores centralized audit and configuration logs with encryption and restricted access. |
| AWS KMS | Customer managed keys or AWS managed keys | Encrypts supported logs, buckets, and security service data according to client policy. |
| Amazon SNS | Notifications | Optional alerting target for account vending, drift, and security workflows. |
| AWS Security Hub CSPM | Delegated admin in Audit/security account | Aggregates security posture and compliance findings across accounts and Regions. |
| Amazon GuardDuty | Delegated admin in Audit/security account | Centralizes threat detection findings across enrolled accounts. |
Deployments​
Application​
| Field | Details |
|---|---|
| Tool | Not applicable unless custom landing zone applications are added. Common options: GitHub Actions, AWS CodePipeline, Argo CD, Helm. |
| Repository | [Repository link] |
| How it deploys | Application deployments should target workload accounts only. Shared landing zone accounts should be changed through approved infrastructure workflows. |
For application workloads, the recommended flow is: application change -> pull request -> build and test -> artifact publish -> deploy to the target workload account and environment. Production deployments should require approval and use role-based access through IAM Identity Center or CI/CD OIDC federation.
Terraform​
| Field | Details |
|---|---|
| Repository | [Terraform repository link] |
| How it deploys | Pull request -> Terraform plan in CI -> review -> controlled apply per environment. |
| State | [S3 backend bucket and DynamoDB lock table, or Terraform Cloud workspace] |
Terraform should manage customer-owned extensions around the landing zone, such as custom OUs, delegated administrator setup, account customizations, security integrations, networking baselines, and workload account resources. Avoid directly changing AWS Control Tower managed resources outside supported AWS Control Tower, Organizations, or baseline APIs.
Environment Model​
| Environment | Account/OUs | Purpose |
|---|---|---|
| Management | Management account | AWS Control Tower administration, Organizations management, billing, and landing zone orchestration. |
| Security | Security OU | Central logging, security audit, delegated security services, and security automation. |
| Shared Services | Shared Services OU/account | Shared DNS, networking, CI/CD, artifact repositories, and platform services. |
| Non-production | Development, QA, Staging OUs/accounts | Build, test, and pre-production workloads. |
| Production | Production OU/accounts | Customer-facing or business-critical workloads with stricter controls and approvals. |
| Sandbox | Sandbox OU/accounts | Time-boxed experiments and proof-of-concept work with spend controls. |
Governance Model​
| Governance Area | Implementation |
|---|---|
| Account creation | Use Account Factory or account vending automation integrated with Account Factory. |
| OU registration | Register OUs in AWS Control Tower before treating accounts as governed. |
| Controls | Enable mandatory controls everywhere; add strongly recommended and elective controls by OU risk profile. |
| Identity | Use IAM Identity Center with least-privilege permission sets and break-glass controls. |
| Logging | Send organization logs to the Log Archive account. Restrict write/delete access. |
| Audit | Use the Audit account for cross-account review and delegated security administration. |
| Drift | Review AWS Control Tower dashboard and lifecycle events; remediate drift through supported workflows. |
| Exceptions | Track exceptions with owner, business justification, expiry date, and compensating control. |
Operational Notes​
| Area | Recommendation |
|---|---|
| Change management | Treat the landing zone as a controlled platform. Use pull requests, plans, approvals, and maintenance windows for shared changes. |
| Management account | Do not deploy application workloads in the management account. Limit access to platform administrators. |
| Shared accounts | Do not rename Log Archive or Audit accounts after landing zone launch. Confirm naming before initial setup. |
| Controls | Apply controls at the OU level. Validate impact in non-production OUs before production rollout. |
| StackSets | Do not manually modify AWS Control Tower managed StackSets or stack instances. |
| Account enrollment | Existing accounts require required roles and prerequisites before enrollment. |
| Event automation | Use EventBridge rules for post-account-creation automation after successful lifecycle events. |
| Documentation | Keep OU design, account inventory, control matrix, and exception register current. |