Skip to main content

AWS Control Tower Infrastructure Overview

Document Control​

FieldDetails
ProjectAWS Control Tower Landing Zone
Version1.0
AuthorAnmol Nagpal
Last updated2026-07-01

Summary​

AWS Control Tower provides the governed foundation for a multi-account AWS environment. It orchestrates AWS Organizations, IAM Identity Center, AWS Service Catalog, AWS CloudFormation StackSets, AWS Config, AWS CloudTrail, and related services to create a landing zone with centralized logging, security auditing, account vending, and policy controls.

The architecture separates management, security, shared services, sandbox, and workload accounts into organizational units (OUs). This separation keeps central governance and audit functions isolated while allowing application teams to operate in governed member accounts.

Architecture​

DiagramLink
ArchitectureArchitecture diagram

High-Level Flow​

  1. Cloud administrators configure AWS Control Tower from the management account.
  2. AWS Control Tower creates or registers the landing zone, OUs, shared accounts, baselines, and mandatory controls.
  3. Account Factory provisions enrolled member accounts through AWS Service Catalog and AWS Organizations.
  4. AWS Control Tower baselines each enrolled account with required IAM roles, logging, monitoring, and controls.
  5. AWS CloudTrail, AWS Config, and lifecycle events provide auditability and automation triggers.
  6. Security services such as GuardDuty and Security Hub can be delegated to security accounts for organization-wide visibility.

Components/Resources​

Component/TechnologyName/IdentifierNotes
AWS Control TowerLanding zoneGovernance orchestration layer for the multi-account environment.
AWS OrganizationsOrganization rootParent container for OUs, accounts, service control policies, and delegated administration.
Management accountExisting payer/management accountHosts AWS Control Tower administration and organization-level orchestration. Keep workloads out of this account.
Security OUSecurityContains the Log Archive and Audit accounts by default.
Log Archive accountLog ArchiveCentral account for organization audit logs such as AWS CloudTrail and AWS Config delivery.
Audit accountAuditCentral security review account for cross-account audit access and delegated security tooling.
Sandbox OUSandboxOptional OU created during landing zone setup for experimentation and non-production accounts.
Workload OUsDevelopment, Staging, Production, or client standardRegistered OUs that contain enrolled workload accounts. Names should follow the client's operating model.
Account FactoryAWS Service Catalog productStandardized account provisioning workflow for new governed accounts.
ControlsPreventive, detective, proactiveOU-level governance policies. Controls were previously called guardrails in some AWS material.
BaselinesAWSControlTowerBaselineApplies required account and OU configuration for managed accounts and OUs.
IAM Identity CenterIdentity directory or external IdP integrationCentral access portal and permission set assignment model for users and groups.
IAM rolesAWSControlTowerExecution, audit roles, service rolesCross-account roles used by AWS Control Tower and audit workflows.
AWS CloudFormation StackSetsAWS Control Tower managed StackSetsDeploys baseline resources into enrolled accounts and Regions.
AWS CloudTrailOrganization trails and lifecycle eventsRecords account, governance, and lifecycle activity for audit and automation.
AWS ConfigRecorders, rules, aggregatorsTracks resource configuration and detective control compliance.
Amazon EventBridgeControl Tower lifecycle rulesTriggers automation after landing zone, account, OU, baseline, and control events.
Amazon S3Log archive bucketsStores centralized audit and configuration logs with encryption and restricted access.
AWS KMSCustomer managed keys or AWS managed keysEncrypts supported logs, buckets, and security service data according to client policy.
Amazon SNSNotificationsOptional alerting target for account vending, drift, and security workflows.
AWS Security Hub CSPMDelegated admin in Audit/security accountAggregates security posture and compliance findings across accounts and Regions.
Amazon GuardDutyDelegated admin in Audit/security accountCentralizes threat detection findings across enrolled accounts.

Deployments​

Application​

FieldDetails
ToolNot applicable unless custom landing zone applications are added. Common options: GitHub Actions, AWS CodePipeline, Argo CD, Helm.
Repository[Repository link]
How it deploysApplication deployments should target workload accounts only. Shared landing zone accounts should be changed through approved infrastructure workflows.

For application workloads, the recommended flow is: application change -> pull request -> build and test -> artifact publish -> deploy to the target workload account and environment. Production deployments should require approval and use role-based access through IAM Identity Center or CI/CD OIDC federation.

Terraform​

FieldDetails
Repository[Terraform repository link]
How it deploysPull request -> Terraform plan in CI -> review -> controlled apply per environment.
State[S3 backend bucket and DynamoDB lock table, or Terraform Cloud workspace]

Terraform should manage customer-owned extensions around the landing zone, such as custom OUs, delegated administrator setup, account customizations, security integrations, networking baselines, and workload account resources. Avoid directly changing AWS Control Tower managed resources outside supported AWS Control Tower, Organizations, or baseline APIs.

Environment Model​

EnvironmentAccount/OUsPurpose
ManagementManagement accountAWS Control Tower administration, Organizations management, billing, and landing zone orchestration.
SecuritySecurity OUCentral logging, security audit, delegated security services, and security automation.
Shared ServicesShared Services OU/accountShared DNS, networking, CI/CD, artifact repositories, and platform services.
Non-productionDevelopment, QA, Staging OUs/accountsBuild, test, and pre-production workloads.
ProductionProduction OU/accountsCustomer-facing or business-critical workloads with stricter controls and approvals.
SandboxSandbox OU/accountsTime-boxed experiments and proof-of-concept work with spend controls.

Governance Model​

Governance AreaImplementation
Account creationUse Account Factory or account vending automation integrated with Account Factory.
OU registrationRegister OUs in AWS Control Tower before treating accounts as governed.
ControlsEnable mandatory controls everywhere; add strongly recommended and elective controls by OU risk profile.
IdentityUse IAM Identity Center with least-privilege permission sets and break-glass controls.
LoggingSend organization logs to the Log Archive account. Restrict write/delete access.
AuditUse the Audit account for cross-account review and delegated security administration.
DriftReview AWS Control Tower dashboard and lifecycle events; remediate drift through supported workflows.
ExceptionsTrack exceptions with owner, business justification, expiry date, and compensating control.

Operational Notes​

AreaRecommendation
Change managementTreat the landing zone as a controlled platform. Use pull requests, plans, approvals, and maintenance windows for shared changes.
Management accountDo not deploy application workloads in the management account. Limit access to platform administrators.
Shared accountsDo not rename Log Archive or Audit accounts after landing zone launch. Confirm naming before initial setup.
ControlsApply controls at the OU level. Validate impact in non-production OUs before production rollout.
StackSetsDo not manually modify AWS Control Tower managed StackSets or stack instances.
Account enrollmentExisting accounts require required roles and prerequisites before enrollment.
Event automationUse EventBridge rules for post-account-creation automation after successful lifecycle events.
DocumentationKeep OU design, account inventory, control matrix, and exception register current.

References​