diff --git a/cli/cmd/generate_aws_controltower.go b/cli/cmd/generate_aws_controltower.go index c3be3e498..640649ff9 100644 --- a/cli/cmd/generate_aws_controltower.go +++ b/cli/cmd/generate_aws_controltower.go @@ -52,7 +52,7 @@ var ( generateAwsControlTowerTfCommand = &cobra.Command{ Use: "controltower", Short: "Generate and/or execute Terraform code for ControlTower integration", - Long: `Use this command to generate Terraform code for deploying Lacework with Aws Cloudtrail and + Long: `Use this command to generate Terraform code for deploying Lacework with Aws Cloudtrail and ControlTower. By default, this command interactively prompts for the required information to set up the new cloud account. @@ -356,7 +356,9 @@ func initGenerateAwsControlTowerTfCommandFlags() { generateAwsControlTowerTfCommand.PersistentFlags().StringVar( &GenerateAwsControlTowerCommandState.OrgAccountMappingsJson, - "org_account_mapping", "", "Org account mapping json string") + "org_account_mapping", "", "Org account mapping json string. Example: "+ + "'{\"default_lacework_account\":\"main\", \"mapping\": [{ \"aws_accounts\": [\"123456789011\"], "+ + "\"lacework_account\": \"sub-account-1\"}]}'") generateAwsControlTowerTfCommand.PersistentFlags().StringVar( &GenerateAwsControlTowerCommandState.IamRoleExternalID, diff --git a/integration/test_resources/help/generate_cloud-account_aws_controltower b/integration/test_resources/help/generate_cloud-account_aws_controltower index 676475e5a..ea3c5f4e2 100644 --- a/integration/test_resources/help/generate_cloud-account_aws_controltower +++ b/integration/test_resources/help/generate_cloud-account_aws_controltower @@ -30,7 +30,7 @@ Flags: --iam_role_name string specify the name of the existing iam role --lacework_aws_account_id string the Lacework AWS root account id --log_archive_account string The log archive account flag input in the format profile:region - --org_account_mapping string Org account mapping json string + --org_account_mapping string Org account mapping json string. Example: '{"default_lacework_account":"main", "mapping": [{ "aws_accounts": ["123456789011"], "lacework_account": "sub-account-1"}]}' --output string location to write generated content --prefix string specify the prefix that will be used at the beginning of every generated resource --s3_bucket_arn string the S3 Bucket for consolidated CloudTrail