StackSets extend the functionality of stacks, so you can create, update, or delete stacks across multiple accounts and Regions with a single operation.
Because StackSets perform stack operations across multiple accounts, before you can create your first stack set you need the necessary permissions defined in your AWS accounts.
You can manage StackSets using self-managed or service-managed permissions.
-
For self-managed StackSets, you must create and manage IAM roles in each target account and AWS Region. For more information, see Grant self-managed permissions.
-
For service-managed StackSets, you don't need to manually create and manage IAM roles in each account; AWS handles the role creation and permissions for you. For more information, see Activate trusted access.
Note
Activating trusted access with AWS Organizations for AWS CloudFormation StackSets isn't currently supported in the China Beijing and Ningxia Regions.