Description
With automatic deployment enabled on a service-managed StackSet, removing or moving an account out of a target organization or OU can delete its associated stack. AutoDeployment.RetainStacksOnAccountRemoval: true selects retention of the stack and its resources in that situation.
Retained resources are no longer managed as part of that StackSet. This option does not prevent every form of stack deletion or replace data backups.
Potential impact
- Deleting production stacks during account moves or organizational changes can interrupt services and lose data.
- Recovery may require redeployment and data restoration.
Remediation
- Set
RetainStacksOnAccountRemovaltotruewhen resources must remain after account removal from the deployment target. - Before organizational changes, review affected stacks, resource deletion policies, and backups.
- Assign ownership, access controls, cost management, and cleanup procedures for retained resources.
Examples
These examples compare account-removal behavior for a SERVICE_MANAGED StackSet. Configure the required AWS Organizations integration and supply an accessible S3 template URL through StackTemplateUrl.
Before
Resources:
StackSet:
Type: AWS::CloudFormation::StackSet
Properties:
PermissionModel: SERVICE_MANAGED
StackSetName: some-stack-name
TemplateURL: !Ref StackTemplateUrl
AutoDeployment:
Enabled: true
RetainStacksOnAccountRemoval: false
Automatic deployment is enabled without retaining stacks on account removal. The template and resource deletion policies also affect which resources are deleted.
After
Resources:
StackSet:
Type: AWS::CloudFormation::StackSet
Properties:
PermissionModel: SERVICE_MANAGED
StackSetName: some-stack-name
TemplateURL: !Ref StackTemplateUrl
AutoDeployment:
Enabled: true
RetainStacksOnAccountRemoval: true
Stacks and resources remain when the account leaves the deployment target. They must then be managed outside the StackSet and can continue to incur costs.