All Products
Search
Document Center

Resource Orchestration Service:Automatically deploy stacks

Last Updated:Aug 26, 2026

After you enable a resource directory, you can configure automatic deployment when you use the management account or a delegated administrator account of the resource directory to create a stack group with service-managed permissions. Stacks are then deployed automatically when the member accounts in a target folder change, which helps you manage the stacks in your member accounts in a centralized manner. You can also modify the automatic deployment settings as needed.

Prerequisites

Make sure that you have created a stack group with service-managed permissions. For more information, see Step 3: Create a stack group.

Common scenarios

After you enable automatic deployment, if a member account is added to a target folder, the stack group automatically deploys stacks to the member account. If a member account is removed from a target folder, the stack group automatically deletes the stacks in the member account.

Automatic deployment applies to the following scenarios:

  • Scenario 1: Automatic deployment is performed when a member account is moved between folders.

    Assume that a stack group has automatic deployment configured for Folder 1 and Folder 2 in the resource directory. When a member account is moved from Folder 1 to Folder 2, automatic deployment is triggered. ROS deletes the stacks from the target regions of the member account in Folder 1, and creates identical stacks in the target regions of the member account in Folder 2.

  • Scenario 2: Automatic deployment is performed when a member account is added to a folder.

    Assume that a stack group has automatic deployment configured for a folder. When member account A is added to the folder, automatic deployment is triggered and stacks are created in the target regions of member account A. If another member account B is added to the folder while the stacks are being created, the stack group first creates the stacks in the target regions of member account A. The stack group then creates the stacks in the target regions of member account B.

Note

You can configure automatic deployment only for stack groups. You cannot configure automatic deployment for folders, member accounts, or regions.

Regions

When you create a member account in a target folder or move a member account to a target folder, the regions for automatic deployment depend on the regions that are specified for the stacks in the stack group.

If stacks exist in the stack group, the deployment regions are the regions that are specified for all of the stacks. If no stacks exist, the deployment regions are the regions that you specify when you create the stacks for the first time.

Procedure

  1. Use the management account or a delegated administrator account of the resource directory to log on to the resource orchestration (ROS) console.

    Note

    Use the same account that you used to create the stack group.

  2. In the navigation pane on the left, click Stack Groups.

  3. In the region drop-down list in the top menu bar, select the region in which the stack group resides.

  4. Click the name of the target stack group.

  5. On the Details tab, in the Deployment Configurations section, click Edit Automatic Deployment.

  6. In the Edit Automatic Deployment dialog box, set Automatic Deployment to Enabled, and then configure Account Removal Behavior.

    For more information about automatic deployment and the account removal behavior, see Parameter descriptions.

    Important

    When Account Removal Behavior is set to Retain Stacks, the stacks and their related resources are retained. The resources remain in their current state but are no longer part of the stack group. The stacks cannot be reassociated with an existing stack group or a new stack group.

  7. Click Save.