Skip to content



You will need to have AWS API credentials from your Management Account configured.


As described here you will need to have AdministratorAccess to allow AFT Account to launch products from AWS Control Tower Account Factory Portfolio.

You can use ~/.aws/credentials file or environment variables. For more information read AWS documentation.


An AWS Control Tower landing zone. For more information, see Plan your AWS Control Tower landing zone.

A home Region for your AWS Control Tower landing zone. For more information, see How AWS Regions work with AWS Control Tower.

A Terraform version and distribution. For more information, see Terraform and AFT versions.

A VCS provider for tracking and managing changes to code and other files.


Create a new organizational unit for AFT (Optional)

Provision the AFT management account