You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Terraform启用AWS Cognito用户名登录功能?

问题描述

使用Terraform创建AWS Cognito用户池时,想要启用用户名登录选项,设置username_attributes = ["username"]后报错:

Error: expected username_attributes.0 to be one of [phone_number email], got username

但AWS控制台中确实存在用户名登录的选项,原代码如下:

resource "aws_cognito_user_pool" "pool" {
  name                = "User_Pool_demo"
  username_attributes = ["username"]

  username_configuration {
    case_sensitive = false
  }

  schema {
    attribute_data_type = "String"
    mutable             = true
    name                = "username"
    required            = true
    string_attribute_constraints {
      min_length = 1
      max_length = 2048
     }
   }
 } 
解决方案

Terraform的aws_cognito_user_pool资源中,username_attributes字段的作用是指定可替代用户名的登录标识(比如用邮箱或手机号登录),它的可选值仅为phone_number和email,因此不能填入username。

而控制台里的“用户名登录”是Cognito用户池的默认行为——当不配置username_attributes时,用户池默认允许使用用户名登录。你已经在schema中定义了必填的username属性,这正好满足用户名登录的需求。

修正后的代码只需移除错误的username_attributes配置:

resource "aws_cognito_user_pool" "pool" {
  name                = "User_Pool_demo"

  username_configuration {
    case_sensitive = false
  }

  schema {
    attribute_data_type = "String"
    mutable             = true
    name                = "username"
    required            = true
    string_attribute_constraints {
      min_length = 1
      max_length = 2048
     }
   }
 } 

配置完成后,用户池将启用用户名登录,同时你可以通过username_configuration控制用户名的大小写敏感性,完全匹配控制台的配置效果。

内容的提问来源于stack exchange,提问作者Misgav Ngaithe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 15:12:05