Deploying organization
You use the deploy organization command to make your AWS organization match the configuration found in the organization configuration file.

Example

This is how you deploy your configuration:
1
tkm org deploy
Copied!

Organization admin role

By default, Takomo uses the credentials currently available in the terminal session to execute operations that query information from the organization and alter its state.
You can also instruct Takomo to use a specific IAM role to perform these organization management operations by setting the organizationAdminRoleName property in the organization configuration.
Please note that you need to give only a role name and not a full role ARN.

Example

This is how you set the organization admin role.
organization/organization.yml
1
masterAccountId: "098765432100"
2
3
# This is how you tell Takomo to use an IAM role
4
# named 'MyOrganizationAdminRole' when executing
5
# organization management actions.
6
organizationAdminRoleName: MyOrganizationAdminRole
7
8
serviceControlPolicies:
9
restrict-by-regions:
10
description: Restrict regions
11
FullAWSAccess:
12
description: AWS managed default policy
13
awsManaged: true
14
15
backupPolicies:
16
MyBackups:
17
description: Backup policy
18
19
organizationalUnits:
20
Root:
21
serviceControlPolicies: FullAWSAccess
22
accounts:
23
- "098765432100"
24
Root/Workloads:
25
serviceControlPolicies: restrict-by-regions
26
Root/Workloads/Dev: {}
27
Root/Workloads/Test: {}
28
Root/Workloads/Prod:
29
accounts:
30
- id: "876754648373"
31
name: MyAccount
33
description: This is a production account
34
Root/Sandbox:
35
accounts:
36
- id: "123456789012"
37
backupPolicies:
38
- MyBackups
39
- "448873940474"
Copied!
Last modified 3mo ago
Copy link