AWS Control Tower
aws.amazon.com
aws.amazon.com
You want help with a problem in your staging account? pay for support, fair enough. You want help with your production? oh sorry, you have to pay again.
In a sense this is a good thing since support is percentage based and you may want a higher level for support for production than staging.
It's only 10% for the first $10K. 7% for the portion up to $80K, 5% for the portion up to $250K, and 3% beyond that. (Enterprise has the same kind of %age ranges but cutoffs of $150K/$500K/$1M and the bottom range doesn't really matter because the hard minimum is $15K/mo.)
GCP organizations, folders, projects, and IAM system is far better than anything in AWS or Azure.
AWS IAM can still give you more advanced rules but is just hard to manage, especially across lots of accounts.
That's not how it works for us. We have numerous accounts, all under the same support plan. We just let our rep know we have these accounts, and they add our existing support plan to it. After all, we are one client.
Edit: Occurred to me I should point out that we have Enterprise support.
Right now I feel like I would have to poke into every menu option in every region across the entire set of AWS services to find out exactly what I'm using.
The cynic in me wonders if this is not a priority for AWS because they make so much money from forgotten and hard to find resources that are being used and paid for but essentially lost in the interface.
When I saw the new product name I thought "maybe this is it!"
Another way to think of this question is “what is my current exploitable attack surface, against the ‘attack’ of causing AWS to charge me lots of money?”
Don't see any missing functionality but our use case may not be complex enough.
https://docs.aws.amazon.com/awsconsolehelpdocs/latest/gsg/fi...
Regions and tags are optional, which will show you everything.
And several others.
This is one thing that GCP has done so brilliantly right - the projects structure. From an organisation point of view, this is the most seamless way of managing billing+access , instead of mucking about ARN crap.
It's puzzling that AWS has still not been able to roll this out. What's so hard ? roll out projects and put all existing customers in a default project.
It only works regionally, but it's better than nothing.
> You tried to use an account that is a member of an organization in AWS Organizations. To set up your AWS Control Tower landing zone, use an account that is not a member of an organization.
Looks like it’s only feasible if you’re starting from scratch.
Pricing is definitely a hard topic, and we can do more to make it easier. However, with regards to your second comment, are you looking for something more than this page [1]
It provides both pricing and product information, so you can build your own dashboard/tooling if you want to.
What I personally find very frustrating is the lack of being able to migrate any existing organisations into this. I’d love to get rid of some of our account provisioning but this would basically mean starting over with a brand-new AWS Organization which is impossible for us.
It still is quite a hassle to manage many accounts (and resources you need in them) so I hope this service will sooner or later help us with this.
PS: if anyone is over at re:Inforce and wants to talk about anything AWS Orgs & accounts, feel free to mail me (profile)!
This is one area where I think GCP got it right. By using organizations and projects within one account instead of having parent and child accounts, it's quite a bit easier to see what's going on. And a parent account has a very different role from child accounts, so it makes sense to treat them as separate things.
So now if you support something like a "hard-billing-cap", every single service in AWS has to support it. That's a huge stone to move - it could even be in the works today.
I think this is the major problem. It's conceptually easy to say 'Yeah no more spinning up ec2 instances' or whatever, but the only way to deal with hitting that cap for things like network traffic or storage services is just turning off network access or deleting the files. I can't imagine many businesses are going to go for "hey if you set a cap and you exceed it we fix it by deleting your stuff and taking down network availability." - that's going to be a total nonstarter in so many situations! But that's what would be required to actually set a spending cap on an account.
That sort of decision really needs to be made by a human as it's happening - is the spike in usage legitimate? Is it your customers driving the demand? Is it unwanted traffic? Is it an autoscaling group gone wrong? etc. etc. etc.
My suggestion is setting up CW billing alarms at several thresholds, to try and stay ahead of this before it reaches that point, with paging on the highest threshold where it's about at the point where you'd consider turning things off. Then you should hopefully be able to take care of unexpected expenses before they're problematic, but also ready to engage someone to make the tough decisions instead of just automatically taking yourself down.
Nevertheless, that's exactly what people have been asking for several years. See this thread for example (and many others): https://forums.aws.amazon.com/thread.jspa?threadID=58127&sta...
The thread has a limited and reasonable request which is totally separate from account spend limits.
Only if you don't use auto-scaling of any kind and you can already set up budgets which will alert you if your usage is expected to go above some thresholds.