AWS Control Tower customers use the Account Factory to create new AWS accounts with best practices blueprints and guardrails in place during account creation. When customers create new accounts, they want to increase service limits for some AWS services that are required as per their business needs. Service Quotas in AWS help you to manage your quotas for many AWS services from one location.
In this lab, you will learn how to use the Service Quota Template functionality to apply a Service Quota increase for the number of VPCs allowed in each region across all newly created accounts in your AWS Organization. This means that when you create a new account via the AWS Control Tower Account factory, those quotas will be applied automatically, without needing to go and put them in manually.
Note: The Service Quota Template only applies to new accounts and will not affect existing accounts. If you need to modify quotas on those accounts, you can follow the process outlined here: https://docs.aws.amazon.com/servicequotas/latest/userguide/request-quota-increase.html
The lab will assume that you are currently operating in 2 AWS regions, N. Virginia and Oregon. Running this lab will not result in any charges to your AWS Account.
This takes us to the list of Service Quotas for Amazon VPC.
Now that you have identified the desired Service Quota, its default value, and validated that it is adjustable, you can add it to a Quota request template.
A dialog box will pop up confirming that you wish to continue, click Enable.
Now you should see a status of Enabled under Template association. This means whatever you define in this template will be adjusted in all new accounts in your organization.
Now add a quota to the Quota request template. Click the Add quota button to get started.
Next, click the Quota drop down menu and select VPCs per Region.
Next, type in 10 for the Desired quota value and click Add to add it to the template.
Then repeat the process again for Oregon so your quota is applied in both regions.
You can view the quotas that have been added to this template in the Added quotas section.
You have completed a Quota request template! Now whenever an account is vended via Account Factory, these service limit increases will automatically be requested for your new vended account.
If you wish to test this, you can continue with the steps below.
To validate the service quota template functionality, you will need to vend out a new AWS account. You can do this by utilizing the AWS Control Tower Account Factory as described in the Account Factory Lab.
In order to validate the quota increases worked as expected, you will log into your new account and check the Service Quotas dashboard.
Log in to your newly created AWS account, and select a role with access to view service quotas.
You can view your Service Quotas by clicking on your Role in the top navigation and selecting My Service Quotas.
Note: Confirm that you are in one of the regions that you requested a quota increase for.
On the Service Quotas Dashboard, click on AWS Services in the left-hand navigation bar.
Type VPC in the search box, and click on Amazon Virtual Private Cloud (Amazon VPC) in the service list
You should now see that the Service Quota for VPCs per Region now has an Applied quota value of 10 increased from the Default quota value of 5. This means that your template increased the value without needing to go into the account to do so.
Congratulations, now all new accounts you create will be able to utilize this increased quota value. This increases will not be reflected in accounts that were created prior to the template being applied. To make changes in those accounts, you may submit a quota increase request inside of those individual accounts.