Centralised AWS Backup Across an AWS Organisation Using Terraform

7 min read
Share:

Introduction

This blog provides step-by-step instructions to implement centralised AWS Backup across an AWS Organisation using Terraform. Backup policies are managed from a dedicated DevOps Tooling account using Delegated Administration. A CloudFormation StackSet automatically deploys the required IAM role and backup vault to all member accounts. Org-level backup policies are attached to the Production and Non-Production OUs, ensuring all tagged resources are protected without any per-account configuration.

Prerequisites

  • AWS Organization Requirements

Requirement Detail
AWS Organizations Active with all features enabled
Prod OU Organizational Unit containing all production accounts
Non-Prod OU Organizational Unit containing dev / staging / UAT accounts
DevOps Tool Account A dedicated AWS account that acts as the management hub for infrastructure tools
Management Account Used only for delegation
  • AWS CLI Profiles

    • Two CLI profiles are required:
Profile Account
default (or management) Management Account (XXXXXXXXXX)
devops-tooling DevOps Tooling Account (XXXXXXXXXXX)
# Configure DevOps Tooling profile

aws configure –profile devops-tooling

# Enter: Access Key, Secret Key, region: eu-west-1

# Verify both profiles

aws sts get-caller-identity                    # should show management account

aws sts get-caller-identity –profile devops-tooling  # should show devops-tooling account

 

Architecture

The implementation is split across two Terraform folders. The management folder runs once to configure delegation and create org-level backup policies. The devops-tooling folder deploys the CloudFormation StackSet that provisions resources in every member account.

Management Account

  └── Delegates DevOps Tooling as admin for Backup + CloudFormation

  └── Creates Org Backup Policies (prod + non-prod)

  └── Attaches policies to respective OUs

DevOps Tooling Account

  └── CloudFormation StackSet (DELEGATED_ADMIN)

        └── Prod OU accounts   → IAM Role + Backup Vault

        └── Non-Prod OU accounts → IAM Role + Backup Vault

Member Accounts (auto-provisioned, zero manual steps)

  Prod Account

    ├── IAM Role: aws-backup-org-role       ← StackSet

    ├── Backup Vault: org-backup-vault       ← StackSet

    └── Backup Plan: prod-backup-plan        ← Org Policy (3 rules)

  Non-Prod Account

    ├── IAM Role: aws-backup-org-role       ← StackSet

    ├── Backup Vault: org-backup-vault       ← StackSet

    └── Backup Plan: non-prod-backup-plan   ← Org Policy (1 rule)

Repository Structure

The Terraform code is split into two folders. The management/ folder is run once. The devops-tooling/ folder is used for all ongoing operations.

backup/

├── management/              ← Run ONCE from management account credentials

│   ├── providers.tf         ← S3 backend, management account credentials

│   ├── main.tf              ← Delegation + Org Policies + Policy Attachments

│   ├── locals.tf            ← Builds backup policy JSON from ou_configs

│   ├── variables.tf

│   ├── outputs.tf

│   └── terraform.tfvars     ← ALL CONFIG: OU IDs, backup rules, retention

│

└── devops-tooling/          ← All ongoing Terraform runs from here

    ├── providers.tf         ← S3 backend, devops-tooling profile

    ├── main.tf              ← CloudFormation StackSet + Instances

    ├── locals.tf            ← cfn_template (IAM role + vault template)

    ├── variables.tf

    ├── outputs.tf

    └── terraform.tfvars     ← OU IDs (must match management/terraform.tfvars)

AWS BACKUP_POLICY type in Organizations can only be created by the management account. The devops-tooling delegated admin permission covers backup operations only – not Organizations policy management. This is why policies are in management/ and the StackSet is in devops-tooling/

Management Account: One-Time Setup

All commands in this section run once from the management account CLI. After completion, these steps are never repeated.

  • Enable Trusted Access

    • Run from a terminal authenticated to the management account:
# Verify CLI is on management account

aws sts get-caller-identity

# Expected: Account = management account ID

# Enable AWS Backup trusted access with Organizations

aws organizations enable-aws-service-access \

  –service-principal backup.amazonaws.com

# Enable CloudFormation StackSets trusted access

aws organizations enable-aws-service-access \

  –service-principal member.org.stacksets.cloudformation.amazonaws.com

# Verify both are enabled

aws organizations list-aws-service-access-for-organization

  • Enable CloudFormation Organizations Access

    • This is a separate activation step required for SERVICE_MANAGED StackSets to work from a delegated admin account:
aws cloudformation activate-organizations-access

# Verify

aws cloudformation describe-organizations-access

# Expected: Status: ENABLED

  • Enable BACKUP_POLICY Type

    • Get the root ID and enable the BACKUP_POLICY policy type in the organization:
# Get the root ID

aws organizations list-roots

# Note the Id value e.g. r-32ce

# Enable BACKUP_POLICY type

aws organizations enable-policy-type \

  –root-id YOUR_ROOT_ID \

  –policy-type BACKUP_POLICY

# Verify — BACKUP_POLICY should now show Status: ENABLED

aws organizations list-roots

    • Without this step, creating BACKUP_POLICY type resources via Terraform will fail with AccessDeniedException even from the management account.

Management Folder Deployment

  • Update providers.tf

Placeholder Replace with
TERRAFORM_STATE_BUCKET S3 bucket name in management account
  • Update terraform.tfvars

    • Set the DevOps Tooling account ID, region, and OU configurations:
  •  Deploy

cd management

terraform init

terraform plan

terraform apply

  • Expected output — 5 resources created:

Resource Count
aws_organizations_delegated_administrator 2 — backup.amazonaws.com + cloudformation
aws_backup_global_settings 1 — cross-account backup enabled
aws_organizations_policy 2 — prod-backup-policy + non-prod-backup-policy
aws_organizations_policy_attachment 2 — attached to Prod OU + Non-Prod OU

DevOps Tooling Folder Deployment

  • Update providers.tf

Placeholder Replace with
TERRAFORM_STATE_BUCKET S3 bucket name in DevOps Tooling account
  • Update terraform.tfvars

    • The ou_configs map must contain the same OU IDs as management/terraform.tfvars. The backup_rules and selection_tags are not used by the StackSet but must be present as the variable type requires them.
  • Key Configuration in main.tf

    • Two settings are required for the StackSet to work from a delegated admin account:
Setting Value
call_as DELEGATED_ADMIN
capabilities [“CAPABILITY_NAMED_IAM”]
  • Deploy

cd devops-tooling

terraform init

terraform plan

terraform apply

# StackSet instance creation takes 1-2 minutes per OU — this is normal

Expected output — 3 resources created:

Resource Count
aws_cloudformation_stack_set 1 — aws-backup-org-setup
aws_cloudformation_stack_set_instance 2 — one per OU (prod + non-prod)

Tagging Resources for Backup

AWS Backup selects resources based on tags. A resource must carry ALL tags listed in selection_tags for its OU to be included in backup.

  • Production resources

tags = {

  Backup      = “true”

  Environment = “prod”

}

  • Non-Production resources

tags = {

  Backup      = “true”

  Environment = “non-prod”

}

  •  Supported Resource Types

Category Services
Compute EC2 instances, EBS volumes
Database RDS, Aurora, DynamoDB, DocumentDB, Neptune
Storage EFS, FSx, S3
Hybrid AWS Storage Gateway (Volume Gateway)

Backup Plans

  • Production

Rule Schedule Retention
Daily Every day at 02:00 UTC 30 days
Weekly Every Sunday at 03:00 UTC 60 days
Monthly 1st of every month at 04:00 UTC 365 days
  • Non-Production

Rule Schedule Retention
Daily Every day at 02:00 UTC 7 days
  • Backup Storage

All recovery points are stored in the originating account’s own vault. No data crosses account boundaries.

Prod Account     → resources backed up → org-backup-vault (prod account)

Non-Prod Account → resources backed up → org-backup-vault (non-prod account)

 Making Changes

All configuration changes are made in terraform.tfvars files only. After editing, run terraform plan followed by terraform apply in the relevant folder.

  •  Add a New Backup Rule

    • Update management/terraform.tfvars only. Add a new entry to backup_rules of the relevant OU:
  • Add a New Tag to Resource Selection

    • Update selection_tags in management/terraform.tfvars for the relevant OU:
  • Add a New OU

    • Update terraform.tfvars in BOTH folders:

New Account Auto-Provisioning

When a new AWS account is added to a managed OU, the following happens automatically with no manual steps required:

  • Account joins the Prod or Non-Prod OU
  • CloudFormation StackSet detects the new account (auto_deployment = true)
  • IAM role aws-backup-org-role & Backup vault org-backup-vault is created in the new account
  • Org backup policy already attached to the OU applies automatically
  • Any resource tagged Backup=true is backed up on the next scheduled run

 Verification

  • Verify Org Backup Policies

    • Run from management account CLI:
# List all backup policies in the org

aws organizations list-policies –filter BACKUP_POLICY

# Expected: prod-backup-policy + non-prod-backup-policy

# Verify prod policy is attached to Prod OU

aws organizations list-policies-for-target \

  –target-id YOUR_PROD_OU_ID \

  –filter BACKUP_POLICY

# Verify non-prod policy is attached to Non-Prod OU

aws organizations list-policies-for-target \

  –target-id YOUR_NON_PROD_OU_ID \

  –filter BACKUP_POLICY

  • Verify StackSet Instances

    • Note: must include –call-as DELEGATED_ADMIN when querying as the devops-tooling account:
aws cloudformation list-stack-instances \

  –stack-set-name aws-backup-org-setup \

  –call-as DELEGATED_ADMIN \

  –profile devops-tooling

# Expected: both member accounts with Status: CURRENT, DetailedStatus: SUCCEEDED

  •  Verify Member Account Resources

    • Configure a CLI profile for the prod account, then run:
aws iam get-role –role-name aws-backup-org-role –profile prod

aws backup list-backup-vaults –region eu-west-1 –profile prod

# Expected: org-backup-vault

# Verify backup plan exists

aws backup list-backup-plans –region eu-west-1 –profile prod

  • Run an On-Demand Backup (Optional)

    • Tag a resource in the prod account with Backup=true and Environment=prod, then trigger a manual job:

 Conclusion

AWS Backup is fully operational across all member accounts in the organisation. The CloudFormation StackSet has deployed the IAM role and backup vault into each account. Org-level backup policies are attached to the relevant OUs and are enforcing the configured schedules and retention periods automatically.

All recovery points are stored within the originating account – no data moves across account boundaries. Any new account added to a managed OU is provisioned automatically without any manual intervention.

Leave a Reply

Your email address will not be published. Required fields are marked *