Step 1: Deploy the Hub stack
Deploy the Hub stack to the member account that you selected as the Hub account.
-
Review the changes that AWS CDK deploys.
$ npm run cdk -- diff account-assessment-for-aws-organizations-hub \ --profile "${PROFILE_HUB}" \ --no-change-set -
Deploy the stack.
$ npm run deploy -- \ --parameters DeploymentNamespace="${DEPLOYMENT_NAMESPACE}" \ --parameters UserEmail="${USER_EMAIL}" \ --parameters AllowListedIPRanges="${ALLOW_LISTED_IP_RANGES}" \ --parameters OrganizationID="${ORGANIZATION_ID}" \ --parameters ManagementAccountId="${MANAGEMENT_ACCOUNT_ID}" \ --profile "${PROFILE_HUB}" -
Review the IAM changes when prompted, and confirm the deployment.
-
Wait for the stack to reach
CREATE_COMPLETEorUPDATE_COMPLETE.
The default DynamoDB item lifetime is 90 days, and the default Amazon Cognito multi-factor authentication setting is OPTIONAL. To override these values, add the DynamoTimeToLive or MultiFactorAuthentication parameter when you run the deploy command.
Custom-resource Lambda functions
In addition to its primary Lambda functions, this guidance includes custom-resource Lambda functions that configure the Amazon Cognito domain and deploy the web UI. These functions run when the Hub stack is created, updated, or deleted. Do not delete them because they manage associated resources.