Skip to content

Steps to migrate from traditional to multi account CloudTrail #28

Discussion options

You must be logged in to vote

From a grunt

Hi person,

I'd actually advise you to use v0.48.1 or later due to a couple of bugs in the initial release of the Organizations CloudTrail feature. The bugs were resolved in that version. Do note the WARNING about undeleting the KMS key to ensure that old CloudTrail logs remain readable after updating.

No other specific steps are required to migrate. You can bump the version of terraform-aws-security (being sure to review the release notes between your current version and v0.48.1 in case something else changed), then add cloudtrail_is_organization_trail = true to account-baseline-root, which I assume you're using, and set enable_cloudtrail = false in account-baseline-app and a…

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@gruntwork-support
Comment options

@gruntwork-support
Comment options

Answer selected by gruntwork-support
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Help
Labels
None yet
1 participant