A curated collection of AWS CloudFormation StackSet templates designed for multi-account governance, security baseline enforcement, and compliance automation across AWS Organizations and AWS Control Tower.
.
├── LICENSE # Apache License 2.0
├── README.md # Repository catalog & overview
├── AGENTS.md # Agent guidelines & safety standards
├── CONTRIBUTING.md # Contribution workflow & conventional commits
├── SECURITY.md # Vulnerability disclosure policy
├── Makefile # Validation and linting targets
├── .release-please-config.json # Release Please configuration
├── .release-please-manifest.json # Semantic version tracking
├── .github/
│ ├── dependabot.yml # Automated GitHub Actions updates
│ └── workflows/
│ ├── ci.yml # Template linting & validation CI
│ ├── release-please.yml # Automated versioning and changelog
│ └── semantic-pull-request.yml # PR title validation
└── iam-password-policy/
├── README.md # Architecture, parameters & compliance mapping
└── iam-password-policy.yaml # CloudFormation template
| StackSet | Description | Key Services | Compliance / Controls |
|---|---|---|---|
| IAM Password Policy | Enforces account-level IAM password policy requirements and deploys an AWS Config rule for continuous compliance monitoring. | IAM, Lambda, AWS Config | Control Tower CONFIG.IAM.DT.1, Security Hub SH.IAM.* |
Before deploying these templates as CloudFormation StackSets:
- AWS Organizations:
- AWS Organizations must be configured with All features enabled.
- CloudFormation StackSets Permissions:
- Service-Managed Permissions (Recommended): Enable trusted access with AWS Organizations in CloudFormation to allow deployment to Organizational Units (OUs) without manually configuring IAM roles in target accounts.
- Self-Managed Permissions: If deploying outside of AWS Organizations trusted access, ensure
AWSCloudFormationStackSetAdministrationRolein the admin account andAWSCloudFormationStackSetExecutionRolein target accounts are configured.
- AWS Config:
- For StackSets that deploy AWS Config rules (such as
iam-password-policy), ensure AWS Config configuration recorder and delivery channels are enabled in target accounts and regions.
- For StackSets that deploy AWS Config rules (such as
You can deploy any template in this repository using either the AWS Management Console or the AWS CLI.
- Log into your AWS Management Account or Delegated Administrator Account.
- Navigate to AWS CloudFormation > StackSets.
- Click Create StackSet.
- Choose Template is ready and upload the corresponding
.yamltemplate file. - Specify:
- StackSet name: e.g.,
IAM-Password-Policy-Baseline - Parameters: Adjust parameters according to your organization's security baseline.
- StackSet name: e.g.,
- Configure deployment options:
- Permission model: Choose Service-managed permissions (recommended for AWS Organizations) or Self-managed permissions.
- Deployment targets: Deploy to your entire Organization or specific Organizational Units (OUs).
- Specify regions: Select the target AWS region (e.g.,
us-east-1for global IAM resources). - Deployment options: Set concurrency and failure tolerance preferences.
- Review and select Submit.
Example deployment using Service-Managed Permissions across an Organizational Unit:
# 1. Create the StackSet
aws cloudformation create-stack-set \
--stack-set-name iam-password-policy \
--template-body file://iam-password-policy/iam-password-policy.yaml \
--permission-model SERVICE_MANAGED \
--auto-deployment Enabled=true,RetainStacksOnAccountRemoval=false \
--capabilities CAPABILITY_NAMED_IAM
# 2. Deploy Stack Instances to target Organizational Units (OUs)
aws cloudformation create-stack-instances \
--stack-set-name iam-password-policy \
--deployment-targets OrganizationalUnitIds="ou-xxxx-xxxxxxxx" \
--regions "us-east-1" \
--operation-preferences FailureToleranceCount=0,MaxConcurrentCount=10This project provides standard make targets to lint and validate CloudFormation templates locally:
# Validate template syntax and check CLI availability
make validate
# Lint YAML syntax
make lint
# Run all verification checks
make test
# Clean temporary build/test artifacts
make cleanWe welcome community contributions, additional StackSet templates, and compliance enhancements!
- Contributing Guide: Please review CONTRIBUTING.md for details on our workflow, pull request guidelines, and conventional commits.
- Code of Conduct: This project follows the DIVMORA Technologies Code of Conduct.
- Security: For vulnerability reporting, please review our Security Policy or email security@divmora.com.
This repository is licensed under the Apache License 2.0. See the LICENSE file for details. You are free to use, modify, and deploy these templates in any commercial, enterprise, or personal environment without fees or commercial restrictions.