amazon web services - AWS Consolidated Billing and multiple accounts in AWS -
i hosting infrastructure several different clients. complete, total, 100% separation of client's aws infrastructure necessary (leagal etc). need advice on how best structure accounts.
i have master account mfa. not ever spin-up , infrastructure. merely top-level billing account. each client have own separate aws account. guess separate root login , separate mfa. each client account linked master account consolidated billing. neat because if move business else give them iam details account , strike off master , done.
what not sure of set brand new aws account need unique email account. don't want client ever have first setup account need have whole bunch of email aliases use on our company domain (client@mydomain.com, client2@mydomain.com etc) , use them set new aws accounts? there better way this? pretty clunky have have new email alias every time new client joins.
second, need box full of mfa devices - 1 each account, or same device work accounts?
any pointers gratefully received. thanks
if have gmail address example@gmail.com, can register aws accounts using email addresses like:
example+customer1@gmail.com example+customer2@gmail.com example+customer3@gmail.com
and emails go same gmail account. auto forward gmail address.
this works google apps email addresses, if using host company email.
instead of physical mfa devices, can use google authenticator app on android or iphone 1 entry each customer aws account.
Comments
Post a Comment