A StackSet lives in an administrator account and deploys one template as stack instances into target accounts and regions, for baselines every account needs: logging, alarms, IAM roles. With self-managed permissions you create an AWSCloudFormationStackSetAdministrationRole in the administrator account and an AWSCloudFormationStackSetExecutionRole in each target; with service-managed permissions AWS 24 Organizations creates them, and instances can deploy automatically to accounts that join an organizational unit. Operation preferences control the rollout: concurrent accounts, failure tolerance per region, and sequential or parallel regions. LocalStack 63,725 has one account, so only the single-account, multi-region case runs here:
Resources:
RegionMarker:
Type: AWS::SSM::Parameter
Properties:
Name: /booknest/region-marker
Type: String
Value: !Sub "BookNest baseline in ${AWS::Region}"cd ~/v5-ch7/booknest/infra
aws cloudformation create-stack-set --stack-set-name booknest-baseline \
--template-body file://stackset-baseline.yaml --output text
OP=$(aws cloudformation create-stack-instances --stack-set-name booknest-baseline \
--accounts 000000000000 --regions us-east-1 eu-west-1 \
--operation-preferences RegionConcurrencyType=PARALLEL,FailureToleranceCount=0 \
--query OperationId --output text)
sleep 5
aws cloudformation describe-stack-set-operation --stack-set-name booknest-baseline \
--operation-id "$OP" --output text --query 'StackSetOperation.[Action,Status]'
for r in us-east-1 eu-west-1; do aws ssm get-parameter --region $r \
--name /booknest/region-marker --query Parameter.Value --output text; done
aws cloudformation list-stack-instances --stack-set-name booknest-baseline 2>&1 | fold -s -w 90booknest-baseline:f059c081-e3ab-49ff-8c78-efffaa8afc65 CREATE SUCCEEDED BookNest baseline in us-east-1 BookNest baseline in eu-west-1 aws: [ERROR]: An error occurred (ResourceNotFoundException) when calling the ListStackInstances operation: Stack set named "booknest-baseline" does not exist
Both regional stacks were created and the operation SUCCEEDED, but LocalStack 4.13.1 cannot list the set's instances, and describe-stack-set fails the same way. On AWS, list-stack-instances shows each account and region with a status such as CURRENT or OUTDATED, and a multi-account rollout needs the two roles or AWS Organizations (not run here). Tear down with delete-stack-instances --no-retain-stacks, then delete-stack-set.