如何通过CloudFormation YAML配置AWS Cognito用户池及谷歌身份提供商?
用CloudFormation配置AWS Cognito用户池+谷歌身份提供商的完整方案
当然可以!很多人一开始没找到对应的CloudFormation资源类型,其实AWS早就支持通过AWS::Cognito::UserPoolIdentityProvider资源来配置第三方身份提供商(包括谷歌)。我之前帮不少开发者实现过这个自动化部署,下面给你完整的YAML模板和关键说明:
完整CloudFormation YAML示例
AWSTemplateFormatVersion: '2010-09-09' Parameters: GoogleClientId: Type: String Description: 谷歌OAuth客户端ID GoogleClientSecret: Type: String Description: 谷歌OAuth客户端密钥 NoEcho: true UserPoolName: Type: String Default: MyAppUserPool UserPoolDomainPrefix: Type: String Default: my-app-auth Resources: # 创建Cognito用户池 MyUserPool: Type: AWS::Cognito::UserPool Properties: UserPoolName: !Ref UserPoolName UsernameAttributes: - email AutoVerifiedAttributes: - email Schema: - Name: email AttributeDataType: String Mutable: true Required: true - Name: given_name AttributeDataType: String Mutable: true - Name: family_name AttributeDataType: String Mutable: true # 配置谷歌身份提供商 GoogleIdentityProvider: Type: AWS::Cognito::UserPoolIdentityProvider Properties: UserPoolId: !Ref MyUserPool ProviderName: Google ProviderType: Google ProviderDetails: client_id: !Ref GoogleClientId client_secret: !Ref GoogleClientSecret authorize_scopes: "openid email profile" AttributeMapping: email: email given_name: given_name family_name: family_name username: email # 创建用户池域名(用于OAuth回调) MyUserPoolDomain: Type: AWS::Cognito::UserPoolDomain Properties: Domain: !Ref UserPoolDomainPrefix UserPoolId: !Ref MyUserPool Outputs: UserPoolId: Value: !Ref MyUserPool UserPoolDomain: Value: !Sub "https://${UserPoolDomainPrefix}.auth.${AWS::Region}.amazoncognito.com"
关键配置说明
- 核心资源:
AWS::Cognito::UserPoolIdentityProvider是实现第三方身份提供商集成的关键,ProviderType指定为Google即可。 - 谷歌OAuth配置:
- 你需要先在谷歌云控制台创建OAuth 2.0客户端ID,回调URL必须设置为:
https://<你的用户池域名>.auth.<区域>.amazoncognito.com/oauth2/idpresponse ProviderDetails里的authorize_scopes要包含谷歌返回用户信息所需的权限,openid email profile是最常用的组合。
- 你需要先在谷歌云控制台创建OAuth 2.0客户端ID,回调URL必须设置为:
- 属性映射:
AttributeMapping用来把谷歌返回的用户属性映射到Cognito用户池的属性,比如把谷歌的email对应到Cognito的email,确保用户信息能正确同步。
部署注意事项
- 部署前替换模板中的占位符(比如
GoogleClientId、GoogleClientSecret)为你自己的谷歌OAuth凭证。 - 确保你的谷歌OAuth客户端已将Cognito的回调URL添加到授权的重定向URI列表中。
- 如果需要自定义用户池的其他配置(比如密码策略、MFA),可以在
MyUserPool的Properties里添加对应参数。
内容的提问来源于stack exchange,提问作者sigmaxf
相关产品推荐
相关产品推荐

