How to Import Existing AWS Accounts, Including Management, Into AFT Without Starting Fresh
A developer who inherited nine manually created AWS accounts documented how to adopt Account Factory for Terraform (AFT) on top of an already-live Control Tower environment, rather than starting from a clean slate. The process works by submitting an account request file with a matching email address, prompting AFT to recognise the existing account instead of creating a new one, then building out its pipeline downstream. Six standard workload accounts onboarded without issue, but key pitfalls include ensuring the account email matches AWS Organizations rather than Service Catalog, and understanding that only changes to control_tower_parameters trigger re-provisioning. Contrary to advice reportedly given by AWS Support, the Control Tower management account is not unsupported — it is explicitly enumerated as a shared account in AFT's own source code via shared_account.py. The author notes this capability has existed since AFT version 1.3.3, released in February 2022, but remains largely undocumented.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in