Review StackSet retention on account removal

Retain required stacks and data when accounts leave a StackSet’s automatic deployment targets.

Description

With automatic deployment enabled on a service-managed StackSet, removing or moving an account out of a target organization or OU can delete its associated stack. AutoDeployment.RetainStacksOnAccountRemoval: true selects retention of the stack and its resources in that situation.

Retained resources are no longer managed as part of that StackSet. This option does not prevent every form of stack deletion or replace data backups.

Potential impact

  • Deleting production stacks during account moves or organizational changes can interrupt services and lose data.
  • Recovery may require redeployment and data restoration.

Remediation

  • Set RetainStacksOnAccountRemoval to true when resources must remain after account removal from the deployment target.
  • Before organizational changes, review affected stacks, resource deletion policies, and backups.
  • Assign ownership, access controls, cost management, and cleanup procedures for retained resources.

Examples

These examples compare account-removal behavior for a SERVICE_MANAGED StackSet. Configure the required AWS Organizations integration and supply an accessible S3 template URL through StackTemplateUrl.

Before

yaml
Resources:
  StackSet:
    Type: AWS::CloudFormation::StackSet
    Properties:
      PermissionModel: SERVICE_MANAGED
      StackSetName: some-stack-name
      TemplateURL: !Ref StackTemplateUrl
      AutoDeployment:
        Enabled: true
        RetainStacksOnAccountRemoval: false

Automatic deployment is enabled without retaining stacks on account removal. The template and resource deletion policies also affect which resources are deleted.

After

yaml
Resources:
  StackSet:
    Type: AWS::CloudFormation::StackSet
    Properties:
      PermissionModel: SERVICE_MANAGED
      StackSetName: some-stack-name
      TemplateURL: !Ref StackTemplateUrl
      AutoDeployment:
        Enabled: true
        RetainStacksOnAccountRemoval: true

Stacks and resources remain when the account leaves the deployment target. They must then be managed outside the StackSet and can continue to incur costs.

References