Changes to Stax-managed AWS Organizational Units
Changes have been applied to Stax-managed AWS Organizational Units in accordance with Release 1 from the published release plan. This was initially announced on 4 April 2023.
Changed
View All TagsChanges have been applied to Stax-managed AWS Organizational Units in accordance with Release 1 from the published release plan. This was initially announced on 4 April 2023.
Stax manages AWS Organizations in alignment with established best practices. As a result, Stax-managed AWS Organizations will be uplifted to adhere to the organizational structure recommended in the AWS Security Reference Architecture and the Organizing Your AWS Environment Using Multiple Accounts whitepaper. In addition to this, new functionality will be introduced to allow tenancies to better utilize Organizational Units (OUs) and service control policies (SCPs).
These changes will be released over the next 8 weeks. For a detailed outline of these changes, see the release plan here.
The Stax console now features a redesigned navigation interface. This new interface is designed to bring the most used features of Stax to the front, so you're able to access them easily.
For a detailed breakdown of the changes, see the docs.
On 21 March 2023, Stax will be releasing a change to the following rule to align with AWS definitions of public and private. Snapshots shared with specific AWS account IDs will no longer be marked as "public". This only affected the evaluation of public EBS snapshots, and may impact the compliance score of these rules.
| Bundle Name | Rule |
|---|---|
| Public Exposure Bundle v1.0.0 | EBS Snapshots are publicly exposed |
On 28 February 2023 at 0200 UTC (Tuesday, 28 February 1300 AEDT), Stax will update lifecycle configuration to expire non-current S3 object versions on the following S3 buckets in logging foundation account:
In each case above, the <org-uuid> placeholder is replaced by the UUID representing your Stax tenancy/AWS organization within Stax.
These S3 buckets are created and managed by Stax, and the usage of them is defined in the docs.
As announced on 18th of January, the Fetch Account Types API now excludes closed accounts from the response.
For more information, review the API documentation for your region: Stax API Documentation and Endpoints
As announced on 19 January 2023, Stax has introduced resource locking for all account operations. Instead of allowing multiple simultaneous operations on a single account and potentially causing conflict, Stax will return a 409 Conflictresponse. Read more
Stax is required to limit the length of active user sessions to meet security and compliance obligations. It was recently identified that some sessions exceeded the required timeout. These sessions have been invalidated, and improved timeouts introduced.
Affected users will be required to log in to Stax again, but no other functionality is impacted. Stax login URLs are different in different regions, and are available in the docs.
On 5 February 2023 at 0030 UTC (Sunday, 5 February 1130 AEDT), Stax will introduce resource locking for all account operations. Instead of allowing multiple simultaneous operations on a single account and potentially causing conflict, Stax will return a 409 Conflictresponse. Read more
Fetch Account Types API currently returns the account type details including any accounts (with any status) associated with the account type.
The API response will now exclude any closed accounts and will be live in stax-au1, stax-us1 and stax-eu1 on Wednesday 1st February at 0200 UTC (Tuesday 2nd February at 1300 AEST).
If you have any concerns about the change, please raise a support case.