You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Terraform禁用AWS Cognito用户池的自助注册功能?

用Terraform配置AWS Cognito用户池(联合认证)并禁用自助注册

要在联合认证场景下禁用Cognito用户池的自助注册功能,核心是在aws_cognito_user_pool资源中配置admin_create_user_config模块,同时配合联合身份提供商的设置。以下是具体实现方案:

核心配置代码

resource "aws_cognito_user_pool" "your_user_pool" {
  name = "your-federated-user-pool"

  # 关键:开启仅管理员创建用户,禁用自助注册
  admin_create_user_config {
    allow_admin_create_user_only = true
    # 可选:自定义管理员创建用户时的邀请模板
    invite_message_template {
      email_message = "你的临时密码是 {####},请登录后修改密码。"
      email_subject = "Cognito账户邀请"
      sms_message   = "你的临时密码是 {####},请登录后修改密码。"
    }
  }

  # 指定已配置的联合身份提供商(比如Google、Facebook等)
  identity_providers = ["Google"]

  # 配置用户标识字段,这里以邮箱为例
  username_attributes = ["email"]
  auto_verified_attributes = ["email"]

  # 可选:定义用户池字段(根据你的需求调整)
  schema {
    attribute_data_type      = "String"
    name                     = "email"
    mutable                  = true
    required                 = true
    developer_only_attribute = false
  }
}

# 示例:配置联合身份提供商(以Google为例)
resource "aws_cognito_identity_provider" "google" {
  user_pool_id  = aws_cognito_user_pool.your_user_pool.id
  provider_name = "Google"
  provider_type = "Google"

  provider_details = {
    client_id     = "your-google-client-id"
    client_secret = "your-google-client-secret"
    authorize_scopes = "openid email profile"
  }
}

# 用户池客户端配置(确保启用联合身份提供商)
resource "aws_cognito_user_pool_client" "your_client" {
  name                = "your-app-client"
  user_pool_id        = aws_cognito_user_pool.your_user_pool.id
  supported_identity_providers = ["Google"]
  
  # 确保客户端不开启自助注册(默认就是关闭的,但显式设置更稳妥)
  allow_user_registration = false
}

关键参数说明

  • admin_create_user_config.allow_admin_create_user_only = true:这是禁用自助注册的核心开关。设置为true后,普通用户无法通过注册页面自行创建账户,仅允许管理员通过AWS控制台、CLI或API创建用户,同时联合身份提供商的用户首次登录时会自动被导入用户池(这不属于自助注册流程)。
  • identity_providers:在用户池中指定已配置的联合身份提供商,确保用户可以通过第三方身份登录。
  • aws_cognito_user_pool_client.allow_user_registration = false:显式关闭客户端的自助注册权限,和用户池层面的设置形成双重保障。

注意事项

  • 联合身份提供商的配置需要提前在对应平台(如Google Cloud Console)创建OAuth应用,获取client_id和client_secret。
  • 当allow_admin_create_user_only启用时,Cognito的托管UI将不会显示注册入口,仅保留登录选项。

内容的提问来源于stack exchange,提问作者Ryan Pierce Williams

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 14:47:33