What do techies feel about Account Factory for Ter...
# terraform
y
What do techies feel about Account Factory for Terraform AFT?? Do ppl use them aggressively??
m
i dont understand why one would use that
r
Control tower is a trap. Don't use it for anything related to infrastructure, just accounts/iam/policies
y
How do you manage multiple accounts then?? GUI??
r
Manage what specifically?
You can use it to bootstrap the accounts but I'm just recommending to manage the infrastructure in a more distributed way
Since when you run the ATF it applies everything across the board and you will have insane conflicts and issues
Basically you want to stack up your TF deployments to import the state of the ATF stuff and run a deployment per account+region. Things like Terragrunt help solve this or just TF enterprise
y
I did noticed conflicts I am not sure how good it is to use for multiple accounts When it comes to apply dozens of policies you can use AFT.
Terragrunt bit confusing to me TBH
r
gonna be honest, creating a workflow to manage multiple aws accounts worth of resources is always gonna be confusing. You can do it though! Just find what you like
j
Hello, membrer of Gruntwork here. We maintain Terragrunt and also build an alternative to AFT which uses plain old OpenTofu/Terragrunt code to manage all your accounts. If you’re looking for help with Terragrunt, we have a Discord server where you can chat directly with our team to get help. There’s also a great course on KodeKloud.com.