如何在CloudFormation模板中引用Cognito UserPoolDomain别名目标?
解决Cognito UserPoolDomain自定义域名的Route53别名记录配置问题
不需要自行创建CloudFront分发,Cognito在配置自定义域名时会自动生成对应的CloudFront分发,你可以通过AWS::Cognito::UserPoolDomain的CloudFrontDistribution输出属性获取该分发的DNS名称,直接用于Route53的别名记录配置。
修改后的CloudFormation模板片段如下:
... AuthUserPoolDomain: Type: AWS::Cognito::UserPoolDomain Properties: UserPoolId: !Ref AuthUserPool Domain: auth.example.com CustomDomainConfig: CertificateArn: !Ref CertificateArn AuthRecordSets: Type: AWS::Route53::RecordSetGroup Properties: HostedZoneName: example.com. RecordSets: - Name: auth.example.com Type: A AliasTarget: DNSName: !GetAtt AuthUserPoolDomain.CloudFrontDistribution EvaluateTargetHealth: false HostedZoneId: Z2FDTNDATAQYW2 # CloudFront分发对应的固定托管区ID,无需修改 ...
关键说明:
!GetAtt AuthUserPoolDomain.CloudFrontDistribution会直接返回Cognito自动创建的CloudFront分发域名,填入后即可完成别名指向。- 你使用的
Z2FDTNDATAQYW2是CloudFront分发对应的固定托管区ID,配置完全正确,不需要调整。
部署该模板后,CloudFormation会自动关联UserPoolDomain资源与Route53记录集,确保自定义域名正确指向Cognito托管的认证端点。
内容的提问来源于stack exchange,提问作者bert84
相关产品推荐
相关产品推荐

