Optional
Readonly
devAWS member account for collecting logs from development accounts
Readonly
developmentSecurity Organizational Unit for Development accounts
Readonly
infrastructureOUInfrastructure Organizational Unit
Optional
Readonly
networkAWS member account for network related infrastructure such as Route53 HostedZone etc
Optional
Readonly
prodAWS member account for collecting logs from production accounts
Readonly
prodSecurity Organizational Unit for Production accounts
Readonly
quarantineOUQuarantine Organizational Unit, for deleted accounts
Readonly
rootRoot Organization
Readonly
securityOUSecurity Organizational Unit
Optional
Readonly
sourceAWS member account for source code git repository of all the applications.
Readonly
workloadsOUWorkloads Organizational Unit, to group all the application workloads
Private
enableGenerated using TypeDoc
Construct to set up organizational hierarchy in management account based on best practice recommendations. Best practice recommendation is to use management account for all the management related tasks and have a separate member account for each of your application. X8OrganizationSetup construct will do the following tasks.
SecurityOU is used to group security related accounts such as logs and cloudtrail events from all the accounts, only security team has view only access to it.
InfrastructureOU is used to group infrastructure related accounts such as network etc that are shared between all member accounts
WorkloadsOU is used to group all the application workloads.
QuarantineOU is used to group all the deleted accounts
Default Alarms
Examples
Default Usage
Custom Configuration
Compliance
It addresses the following compliance requirements