โ Getting Started with AWS Control Tower and Account Factory for Terraform (AFT)

AWS Control Tower makes it easier to set up and govern a secure, multi-account AWS environment based on AWS best practices. When combined with Account Factory for Terraform (AFT), it becomes even more powerfulโenabling automated, Git-driven, scalable AWS account provisioning and customization.
In this article, weโll walk through all the prerequisites you need to prepare before deploying AFT successfully.
๐ What is AFT?
Account Factory for Terraform (AFT) is an AWS solution that uses Terraform and DevOps principles to automate account creation, configuration, and governance in an AWS Control Tower environment. It enables you to define account templates and customizations via Git repositories.
โ Prerequisites for AFT Deployment
Before deploying AFT, ensure you meet all of the following requirements
1๏ธโฃ AWS Control Tower Landing Zone
You must have a fully deployed AWS Control Tower landing zone, which includes:
A Management Account (payer account in your AWS Organization).
One or more Organizational Units (OUs).
Governance guardrails (mandatory or optional) applied.
AWS IAM Identity Center (formerly AWS SSO) configured and enabled.
2๏ธโฃ AFT Management Account
You need a dedicated AWS account just for running the AFT infrastructure. This is called the AFT Management Account.
Must be created using Control Tower's Account Factory.
Assign it to an appropriate OU (e.g.,
Infrastructure
).This account will host:
Terraform modules
CodePipeline and CodeBuild
Lambda functions used by AFT
3๏ธโฃ Email Addresses
You need two unique email addresses:
One for the AFT Management Account (e.g.,
user+aft@yourdomain.com
)One for the test (vending) account that youโll create using AFT (e.g.,
user+vending1@yourdomain.com
)
๐ก Tip: Many email providers (like Gmail) support the
+alias
trick to create email variations.
4๏ธโฃ Git Repositories (VCS)
AFT requires four separate Git repositories hosted in a supported Version Control System (VCS) like GitHub, GitLab, or Bitbucket.
Import the following repositories from the AWS samples into your personal or organization Git account:
Purpose | Sample Repo | Rename To |
Account Requests | aft-sample-account-request | aft-account-request |
Global Customizations | aft-sample-global-customizations | aft-global-customizations |
Account Customizations | aft-sample-account-customizations | aft-account-customizations |
Provisioning Customizations | aft-sample-account-provisioning-customizations | aft-account-provisioning-customizations |
โ Set the repositories to private and ensure you have credentials (token or OAuth) for pipeline access.
5๏ธโฃ Developer Tools & CLI Setup
If you are using a local development environment (instead of AWS CloudShell), install:
Terraform CLI
Install Guideterraform --version
jq (for JSON parsing)
Install Guidejq --version
AWS CLI
Install Guideaws --version
Git
git --version
6๏ธโฃ AWS CLI SSO Profile
Configure AWS CLI with your Control Tower Management Account using SSO:
aws configure sso
Follow the prompts to authenticate and store your profile locally.
๐ You must have AdministratorAccess to deploy AFT resources.
7๏ธโฃ Permissions & Access
Ensure the following:
You have Admin access on the Control Tower Management Account.
Your GitHub (or VCS) token or OAuth app has access to the 4 repositories.
IAM Identity Center (SSO) is configured to allow account access and provisioning.
You can assume the necessary IAM roles (used by AFT Lambda and CodePipeline).
8๏ธโฃ Terraform Backend (Recommended for Production)
Use an S3 bucket for remote state storage.
Enable DynamoDB table for state locking.
Define this backend in
backend.tf
.
This improves team collaboration and safeguards Terraform state.
๐ Summary Checklist
Hereโs a quick overview of all prerequisites:
โ Component | Requirement |
Control Tower | Fully deployed landing zone |
AFT Account | Created using Account Factory |
Emails | 2 unique root emails |
Git Repos | 4 private Git repos from AWS samples |
Tools | Terraform, jq, git, AWS CLI |
Permissions | Admin access to Control Tower Management |
Git Auth | Personal token or OAuth app |
SSO | IAM Identity Center enabled |
(Optional) Backend | S3 & DynamoDB for Terraform state |
๐ฏ Next Step
Once these prerequisites are met, youโre ready to deploy the AFT Terraform module and start managing AWS accounts with DevOps efficiency.
Subscribe to my newsletter
Read articles from Chinnayya Chintha directly inside your inbox. Subscribe to the newsletter, and don't miss out.
Written by

Chinnayya Chintha
Chinnayya Chintha
I am ๐๐ต๐ถ๐ป๐ป๐ฎ๐๐๐ฎ ๐๐ต๐ถ๐ป๐๐ต๐ฎ, ๐ฎ ๐ฟ๐ฒ๐๐๐น๐๐-๐ฑ๐ฟ๐ถ๐๐ฒ๐ป ๐ฆ๐ถ๐๐ฒ ๐ฅ๐ฒ๐น๐ถ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ ๐๐ป๐ด๐ถ๐ป๐ฒ๐ฒ๐ฟ (๐ฆ๐ฅ๐) with proven expertise in ๐ฎ๐๐๐ผ๐บ๐ฎ๐๐ถ๐ป๐ด, ๐ฎ๐ป๐ฑ ๐บ๐ฎ๐ป๐ฎ๐ด๐ถ๐ป๐ด ๐๐ฒ๐ฐ๐๐ฟ๐ฒ, ๐๐ฐ๐ฎ๐น๐ฎ๐ฏ๐น๐ฒ, ๐ฎ๐ป๐ฑ ๐ฟ๐ฒ๐น๐ถ๐ฎ๐ฏ๐น๐ฒ ๐ถ๐ป๐ณ๐ฟ๐ฎ๐๐๐ฟ๐๐ฐ๐๐๐ฟ๐ฒ ๐๐ผ๐น๐๐๐ถ๐ผ๐ป๐. My experience spans ๐ฐ๐น๐ผ๐๐ฑ-๐ป๐ฎ๐๐ถ๐๐ฒ ๐๐ฒ๐ฐ๐ต๐ป๐ผ๐น๐ผ๐ด๐ถ๐ฒ๐, ๐๐/๐๐ ๐ฎ๐๐๐ผ๐บ๐ฎ๐๐ถ๐ผ๐ป, ๐ฎ๐ป๐ฑ ๐๐ป๐ณ๐ฟ๐ฎ๐๐๐ฟ๐๐ฐ๐๐๐ฟ๐ฒ ๐ฎ๐ ๐๐ผ๐ฑ๐ฒ (๐๐ฎ๐), enabling me to deliver ๐ต๐ถ๐ด๐ต-๐ฝ๐ฒ๐ฟ๐ณ๐ผ๐ฟ๐บ๐ถ๐ป๐ด ๐๐๐๐๐ฒ๐บ๐ that enhance operational efficiency and drive innovation. As a ๐๐ฟ๐ฒ๐ฒ๐น๐ฎ๐ป๐ฐ๐ฒ ๐ฆ๐ถ๐๐ฒ ๐ฅ๐ฒ๐น๐ถ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ ๐๐ป๐ด๐ถ๐ป๐ฒ๐ฒ๐ฟ, I specialize in: โ ๐๐บ๐ฝ๐น๐ฒ๐บ๐ฒ๐ป๐๐ถ๐ป๐ด ๐๐ฒ๐ฐ๐๐ฟ๐ฒ ๐ฎ๐ป๐ฑ ๐๐ฐ๐ฎ๐น๐ฎ๐ฏ๐น๐ฒ ๐ฝ๐ฎ๐๐บ๐ฒ๐ป๐ ๐ด๐ฎ๐๐ฒ๐๐ฎ๐ ๐๐ผ๐น๐๐๐ถ๐ผ๐ป๐ ๐๐๐ถ๐ป๐ด ๐๐ช๐ฆ ๐๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ๐ ๐น๐ถ๐ธ๐ฒ ๐๐ฃ๐ ๐๐ฎ๐๐ฒ๐๐ฎ๐, ๐๐ฎ๐บ๐ฏ๐ฑ๐ฎ, ๐ฎ๐ป๐ฑ ๐๐๐ป๐ฎ๐บ๐ผ๐๐.. โ ๐๐๐๐ผ๐บ๐ฎ๐๐ถ๐ป๐ด ๐ถ๐ป๐ณ๐ฟ๐ฎ๐๐๐ฟ๐๐ฐ๐๐๐ฟ๐ฒ ๐ฝ๐ฟ๐ผ๐๐ถ๐๐ถ๐ผ๐ป๐ถ๐ป๐ด with ๐ง๐ฒ๐ฟ๐ฟ๐ฎ๐ณ๐ผ๐ฟ๐บ. โ ๐ข๐ฝ๐๐ถ๐บ๐ถ๐๐ถ๐ป๐ด ๐บ๐ผ๐ป๐ถ๐๐ผ๐ฟ๐ถ๐ป๐ด using ๐๐น๐ผ๐๐ฑ๐ช๐ฎ๐๐ฐ๐ต. โ Ensuring compliance with ๐ฃ๐๐-๐๐ฆ๐ฆ ๐๐๐ฎ๐ป๐ฑ๐ฎ๐ฟ๐ฑ๐ through ๐ฒ๐ป๐ฐ๐ฟ๐๐ฝ๐๐ถ๐ผ๐ป ๐บ๐ฒ๐ฐ๐ต๐ฎ๐ป๐ถ๐๐บ๐ โ implemented with ๐๐ช๐ฆ ๐๐ ๐ฆ and ๐ฆ๐ฒ๐ฐ๐ฟ๐ฒ๐๐ ๐ ๐ฎ๐ป๐ฎ๐ด๐ฒ๐ฟ. These efforts have resulted in ๐ฒ๐ป๐ต๐ฎ๐ป๐ฐ๐ฒ๐ฑ ๐๐ฟ๐ฎ๐ป๐๐ฎ๐ฐ๐๐ถ๐ผ๐ป ๐ฟ๐ฒ๐น๐ถ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ and ๐๐๐ฟ๐ฒ๐ฎ๐บ๐น๐ถ๐ป๐ฒ๐ฑ ๐ผ๐ฝ๐ฒ๐ฟ๐ฎ๐๐ถ๐ผ๐ป๐ฎ๐น ๐๐ผ๐ฟ๐ธ๐ณ๐น๐ผ๐๐ for payment processing systems. I am passionate about ๐บ๐ฒ๐ป๐๐ผ๐ฟ๐ถ๐ป๐ด ๐ฎ๐ป๐ฑ ๐ธ๐ป๐ผ๐๐น๐ฒ๐ฑ๐ด๐ฒ ๐๐ต๐ฎ๐ฟ๐ถ๐ป๐ด, having delivered ๐ต๐ฎ๐ป๐ฑ๐-๐ผ๐ป ๐๐ฟ๐ฎ๐ถ๐ป๐ถ๐ป๐ด in ๐ฐ๐น๐ผ๐๐ฑ ๐๐ฒ๐ฐ๐ต๐ป๐ผ๐น๐ผ๐ด๐ถ๐ฒ๐, ๐๐๐ฏ๐ฒ๐ฟ๐ป๐ฒ๐๐ฒ๐, ๐ฎ๐ป๐ฑ ๐ฎ๐๐๐ผ๐บ๐ฎ๐๐ถ๐ผ๐ป. My proactive approach helps me anticipate system challenges and create ๐ฟ๐ผ๐ฏ๐๐๐, ๐๐ฐ๐ฎ๐น๐ฎ๐ฏ๐น๐ฒ ๐๐ผ๐น๐๐๐ถ๐ผ๐ป๐ ๐๐ต๐ฎ๐ ๐ฒ๐ป๐ต๐ฎ๐ป๐ฐ๐ฒ ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐, ๐ฐ๐ผ๐บ๐ฝ๐น๐ถ๐ฎ๐ป๐ฐ๐ฒ, ๐ฎ๐ป๐ฑ ๐ผ๐ฝ๐ฒ๐ฟ๐ฎ๐๐ถ๐ผ๐ป๐ฎ๐น ๐ฒ๐ณ๐ณ๐ถ๐ฐ๐ถ๐ฒ๐ป๐ฐ๐. Dedicated to ๐ฐ๐ผ๐ป๐๐ถ๐ป๐๐ผ๐๐ ๐น๐ฒ๐ฎ๐ฟ๐ป๐ถ๐ป๐ด, I stay updated with ๐ฒ๐บ๐ฒ๐ฟ๐ด๐ถ๐ป๐ด ๐๐ฒ๐ฐ๐ต๐ป๐ผ๐น๐ผ๐ด๐ถ๐ฒ๐ and thrive on contributing to ๐๐ฟ๐ฎ๐ป๐๐ณ๐ผ๐ฟ๐บ๐ฎ๐๐ถ๐๐ฒ ๐ฝ๐ฟ๐ผ๐ท๐ฒ๐ฐ๐๐ that push boundaries in technology.