能否通过CDK将已创建的CognitoUserPoolsAuthorizer导入至其他项目?
你可以通过导入现有资源的方式在新项目中复用已有的CognitoUserPoolsAuthorizer,具体操作分两种场景:
1. AWS CDK项目间复用
如果新项目同样使用AWS CDK,可通过CognitoUserPoolsAuthorizer.fromAuthorizerAttributes方法导入已存在的授权器,需提供授权器ARN和关联的用户池信息。示例代码如下:
// 先导入关联的Cognito用户池 const importedUserPool = UserPool.fromUserPoolId(this, "ImportedUserPool", "your-user-pool-id"); // 导入已有的Cognito授权器 const importedAuth = CognitoUserPoolsAuthorizer.fromAuthorizerAttributes(this, "ImportedCognitoAuthorizer", { authorizerArn: "arn:aws:apigateway:region::authorizer/your-authorizer-id", cognitoUserPools: [importedUserPool], }); // 将导入的授权器绑定到API方法上 api.root.addMethod("GET", new HttpIntegration("https://example.com"), { authorizer: importedAuth, });
2. 非CDK项目手动配置
如果新项目不使用CDK,可直接在AWS控制台操作:
- 打开API Gateway控制台,找到目标API
- 进入「授权」选项,选择「添加授权器」,再选择「使用现有授权器」
- 输入已创建的Cognito Authorizer的ARN,关联对应的Cognito用户池后完成绑定
关键注意事项
- 若跨账号复用,需确保两个账号间已配置正确的资源访问权限;同账号下需保证区域一致
- 导入前确认原授权器状态可用,且关联的Cognito用户池未被删除
内容的提问来源于stack exchange,提问作者msaavedra91
相关产品推荐
相关产品推荐

