Introduction
This blog provides step-by-step instructions to implement centralised AWS Backup across an AWS Organisation using Terraform. Backup policies are managed from a dedicated DevOps Tooling account using Delegated Administration. A CloudFormation StackSet automatically deploys the required IAM role and backup vault to all member accounts. Org-level backup policies are attached to the Production and Non-Production OUs, ensuring all tagged resources are protected without any per-account configuration.
Prerequisites
-
AWS Organization Requirements
| Requirement | Detail |
|---|---|
| AWS Organizations | Active with all features enabled |
| Prod OU | Organizational Unit containing all production accounts |
| Non-Prod OU | Organizational Unit containing dev / staging / UAT accounts |
| DevOps Tool Account | A dedicated AWS account that acts as the management hub for infrastructure tools |
| Management Account | Used only for delegation |
-
AWS CLI Profiles
- Two CLI profiles are required:
| Profile | Account |
|---|---|
| default (or management) | Management Account (XXXXXXXXXX) |
| devops-tooling | DevOps Tooling Account (XXXXXXXXXXX) |
| # Configure DevOps Tooling profile
aws configure –profile devops-tooling # Enter: Access Key, Secret Key, region: eu-west-1 # Verify both profiles aws sts get-caller-identity # should show management account aws sts get-caller-identity –profile devops-tooling # should show devops-tooling account |
Architecture
The implementation is split across two Terraform folders. The management folder runs once to configure delegation and create org-level backup policies. The devops-tooling folder deploys the CloudFormation StackSet that provisions resources in every member account.
| Management Account
└── Delegates DevOps Tooling as admin for Backup + CloudFormation └── Creates Org Backup Policies (prod + non-prod) └── Attaches policies to respective OUs DevOps Tooling Account └── CloudFormation StackSet (DELEGATED_ADMIN) └── Prod OU accounts → IAM Role + Backup Vault └── Non-Prod OU accounts → IAM Role + Backup Vault Member Accounts (auto-provisioned, zero manual steps) Prod Account ├── IAM Role: aws-backup-org-role ← StackSet ├── Backup Vault: org-backup-vault ← StackSet └── Backup Plan: prod-backup-plan ← Org Policy (3 rules) Non-Prod Account ├── IAM Role: aws-backup-org-role ← StackSet ├── Backup Vault: org-backup-vault ← StackSet └── Backup Plan: non-prod-backup-plan ← Org Policy (1 rule) |
Repository Structure
The Terraform code is split into two folders. The management/ folder is run once. The devops-tooling/ folder is used for all ongoing operations.
| backup/
├── management/ ← Run ONCE from management account credentials │ ├── providers.tf ← S3 backend, management account credentials │ ├── main.tf ← Delegation + Org Policies + Policy Attachments │ ├── locals.tf ← Builds backup policy JSON from ou_configs │ ├── variables.tf │ ├── outputs.tf │ └── terraform.tfvars ← ALL CONFIG: OU IDs, backup rules, retention │ └── devops-tooling/ ← All ongoing Terraform runs from here ├── providers.tf ← S3 backend, devops-tooling profile ├── main.tf ← CloudFormation StackSet + Instances ├── locals.tf ← cfn_template (IAM role + vault template) ├── variables.tf ├── outputs.tf └── terraform.tfvars ← OU IDs (must match management/terraform.tfvars) |
AWS BACKUP_POLICY type in Organizations can only be created by the management account. The devops-tooling delegated admin permission covers backup operations only – not Organizations policy management. This is why policies are in management/ and the StackSet is in devops-tooling/
Management Account: One-Time Setup
All commands in this section run once from the management account CLI. After completion, these steps are never repeated.
-
Enable Trusted Access
- Run from a terminal authenticated to the management account:
| # Verify CLI is on management account
aws sts get-caller-identity # Expected: Account = management account ID # Enable AWS Backup trusted access with Organizations aws organizations enable-aws-service-access \ –service-principal backup.amazonaws.com # Enable CloudFormation StackSets trusted access aws organizations enable-aws-service-access \ –service-principal member.org.stacksets.cloudformation.amazonaws.com # Verify both are enabled aws organizations list-aws-service-access-for-organization |
-
Enable CloudFormation Organizations Access
- This is a separate activation step required for SERVICE_MANAGED StackSets to work from a delegated admin account:
| aws cloudformation activate-organizations-access
# Verify aws cloudformation describe-organizations-access # Expected: Status: ENABLED |
-
Enable BACKUP_POLICY Type
- Get the root ID and enable the BACKUP_POLICY policy type in the organization:
| # Get the root ID
aws organizations list-roots # Note the Id value e.g. r-32ce # Enable BACKUP_POLICY type aws organizations enable-policy-type \ –root-id YOUR_ROOT_ID \ –policy-type BACKUP_POLICY # Verify — BACKUP_POLICY should now show Status: ENABLED aws organizations list-roots |
-
- Without this step, creating BACKUP_POLICY type resources via Terraform will fail with AccessDeniedException even from the management account.
Management Folder Deployment
-
Update providers.tf
| Placeholder | Replace with |
|---|---|
| TERRAFORM_STATE_BUCKET | S3 bucket name in management account |
-
Update terraform.tfvars
- Set the DevOps Tooling account ID, region, and OU configurations:
-
Deploy
| cd management
terraform init terraform plan terraform apply |
-
Expected output — 5 resources created:
| Resource | Count |
|---|---|
| aws_organizations_delegated_administrator | 2 — backup.amazonaws.com + cloudformation |
| aws_backup_global_settings | 1 — cross-account backup enabled |
| aws_organizations_policy | 2 — prod-backup-policy + non-prod-backup-policy |
| aws_organizations_policy_attachment | 2 — attached to Prod OU + Non-Prod OU |
DevOps Tooling Folder Deployment
-
Update providers.tf
| Placeholder | Replace with |
|---|---|
| TERRAFORM_STATE_BUCKET | S3 bucket name in DevOps Tooling account |
-
Update terraform.tfvars
- The ou_configs map must contain the same OU IDs as management/terraform.tfvars. The backup_rules and selection_tags are not used by the StackSet but must be present as the variable type requires them.
-
Key Configuration in main.tf
- Two settings are required for the StackSet to work from a delegated admin account:
| Setting | Value |
|---|---|
| call_as | DELEGATED_ADMIN |
| capabilities | [“CAPABILITY_NAMED_IAM”] |
-
Deploy
| cd devops-tooling
terraform init terraform plan terraform apply # StackSet instance creation takes 1-2 minutes per OU — this is normal |
Expected output — 3 resources created:
| Resource | Count |
|---|---|
| aws_cloudformation_stack_set | 1 — aws-backup-org-setup |
| aws_cloudformation_stack_set_instance | 2 — one per OU (prod + non-prod) |
Tagging Resources for Backup
AWS Backup selects resources based on tags. A resource must carry ALL tags listed in selection_tags for its OU to be included in backup.
-
Production resources
| tags = {
Backup = “true” Environment = “prod” } |
-
Non-Production resources
| tags = {
Backup = “true” Environment = “non-prod” } |
-
Supported Resource Types
| Category | Services |
| Compute | EC2 instances, EBS volumes |
| Database | RDS, Aurora, DynamoDB, DocumentDB, Neptune |
| Storage | EFS, FSx, S3 |
| Hybrid | AWS Storage Gateway (Volume Gateway) |
Backup Plans
-
Production
| Rule | Schedule | Retention |
|---|---|---|
| Daily | Every day at 02:00 UTC | 30 days |
| Weekly | Every Sunday at 03:00 UTC | 60 days |
| Monthly | 1st of every month at 04:00 UTC | 365 days |
-
Non-Production
| Rule | Schedule | Retention |
|---|---|---|
| Daily | Every day at 02:00 UTC | 7 days |
-
Backup Storage
All recovery points are stored in the originating account’s own vault. No data crosses account boundaries.
| Prod Account → resources backed up → org-backup-vault (prod account)
Non-Prod Account → resources backed up → org-backup-vault (non-prod account) |
Making Changes
All configuration changes are made in terraform.tfvars files only. After editing, run terraform plan followed by terraform apply in the relevant folder.
-
Add a New Backup Rule
- Update management/terraform.tfvars only. Add a new entry to backup_rules of the relevant OU:
-
Add a New Tag to Resource Selection
- Update selection_tags in management/terraform.tfvars for the relevant OU:
-
Add a New OU
- Update terraform.tfvars in BOTH folders:
New Account Auto-Provisioning
When a new AWS account is added to a managed OU, the following happens automatically with no manual steps required:
- Account joins the Prod or Non-Prod OU
- CloudFormation StackSet detects the new account (auto_deployment = true)
- IAM role aws-backup-org-role & Backup vault org-backup-vault is created in the new account
- Org backup policy already attached to the OU applies automatically
- Any resource tagged Backup=true is backed up on the next scheduled run
Verification
-
Verify Org Backup Policies
- Run from management account CLI:
| # List all backup policies in the org
aws organizations list-policies –filter BACKUP_POLICY # Expected: prod-backup-policy + non-prod-backup-policy # Verify prod policy is attached to Prod OU aws organizations list-policies-for-target \ –target-id YOUR_PROD_OU_ID \ –filter BACKUP_POLICY # Verify non-prod policy is attached to Non-Prod OU aws organizations list-policies-for-target \ –target-id YOUR_NON_PROD_OU_ID \ –filter BACKUP_POLICY |
-
Verify StackSet Instances
- Note: must include –call-as DELEGATED_ADMIN when querying as the devops-tooling account:
| aws cloudformation list-stack-instances \
–stack-set-name aws-backup-org-setup \ –call-as DELEGATED_ADMIN \ –profile devops-tooling # Expected: both member accounts with Status: CURRENT, DetailedStatus: SUCCEEDED |
-
Verify Member Account Resources
- Configure a CLI profile for the prod account, then run:
| aws iam get-role –role-name aws-backup-org-role –profile prod
aws backup list-backup-vaults –region eu-west-1 –profile prod # Expected: org-backup-vault # Verify backup plan exists aws backup list-backup-plans –region eu-west-1 –profile prod |
-
Run an On-Demand Backup (Optional)
- Tag a resource in the prod account with Backup=true and Environment=prod, then trigger a manual job:
Conclusion
AWS Backup is fully operational across all member accounts in the organisation. The CloudFormation StackSet has deployed the IAM role and backup vault into each account. Org-level backup policies are attached to the relevant OUs and are enforcing the configured schedules and retention periods automatically.
All recovery points are stored within the originating account – no data moves across account boundaries. Any new account added to a managed OU is provisioned automatically without any manual intervention.