aws-samples / aws-samples/aws-control-tower-config-customization

The configuration of the config recorder for accounts outside the specified ones was reset.

Open
#38 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
52
Forks
51
Avg merge
2m
Merged PRs (30d)
4

Description

Please note that this text is machine-translated from Japanese, so there may be some awkward phrasing.

The issue has already been resolved in collaboration with AWS Support, but I wanted to inform you that this problem occurred when using this template.
I was using EXCLUSION Mode and included accounts other than the ones I wanted to modify in ExcludedAccounts to make changes.
When I increased the CloudFormationVersion of the previously configured CloudFormation stack to suppress the recording of new resources,
the config recorder settings for member accounts included in ExcludedAccounts were reset.
As a result, resource items that had been suppressed and configured in those member accounts started being recorded, leading to unexpected and unnecessary costs.
(It also took several days to notice this.)
Looking at the CloudWatch Logs for the Lambda function: ConsumerLambda, I found the following messages:

> [INFO] 2025-12-10T08:21:00.133Z ef3eebcf-50f9-5d7d-86ba-8a7c7f53c388 Using existing recorder name: aws-controltower-BaselineConfigRecorder
> [WARNING] 2025-12-10T08:21:00.356Z ef3eebcf-50f9-5d7d-86ba-8a7c7f53c388 Configuration Recorder reset to default. Response:

I believe this is where the config recorder settings for accounts other than the target were reset.
But is it really necessary to reset the config recorder for member accounts included in ExcludedAccounts?
Also, if you do perform a config recorder reset, I think there should be a clearer warning (including in blog articles).
Additionally, in the Lambda function: ProducerLambda, at line 139, there is:

```
elif ('LogicalResourceId' in event) and (event['RequestType'] == 'Delete'):
logging.info('DELETE DELETE')
logging.warning(
'Initiating config recorder cleanup for ALL accounts due to CloudFormation stack deletion')
```

Deleting the stack and cleaning up the config recorder settings for ALL accounts is problematic because it also removes config recorder settings that were already configured in other member accounts. I believe this is not a good approach.

Contributor guide

Open the contributing guide

Research direction

Start with the ConsumerLambda logs and ProducerLambda, especially the line 139 deletion branch, and compare their behavior with EXCLUSION mode and ExcludedAccounts. Done means excluded member accounts retain their recorder settings and stack deletion does not clean up recorders in all accounts; the issue names no tests or file paths, so those will need to be located.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, python
Domain
cloud, infrastructure
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
28/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.