You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过CloudFormation YAML配置AWS Cognito用户池及谷歌身份提供商?

用CloudFormation配置AWS Cognito用户池+谷歌身份提供商的完整方案

当然可以!很多人一开始没找到对应的CloudFormation资源类型,其实AWS早就支持通过AWS::Cognito::UserPoolIdentityProvider资源来配置第三方身份提供商(包括谷歌)。我之前帮不少开发者实现过这个自动化部署,下面给你完整的YAML模板和关键说明:

完整CloudFormation YAML示例

AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  GoogleClientId:
    Type: String
    Description: 谷歌OAuth客户端ID
  GoogleClientSecret:
    Type: String
    Description: 谷歌OAuth客户端密钥
    NoEcho: true
  UserPoolName:
    Type: String
    Default: MyAppUserPool
  UserPoolDomainPrefix:
    Type: String
    Default: my-app-auth

Resources:
  # 创建Cognito用户池
  MyUserPool:
    Type: AWS::Cognito::UserPool
    Properties:
      UserPoolName: !Ref UserPoolName
      UsernameAttributes:
        - email
      AutoVerifiedAttributes:
        - email
      Schema:
        - Name: email
          AttributeDataType: String
          Mutable: true
          Required: true
        - Name: given_name
          AttributeDataType: String
          Mutable: true
        - Name: family_name
          AttributeDataType: String
          Mutable: true

  # 配置谷歌身份提供商
  GoogleIdentityProvider:
    Type: AWS::Cognito::UserPoolIdentityProvider
    Properties:
      UserPoolId: !Ref MyUserPool
      ProviderName: Google
      ProviderType: Google
      ProviderDetails:
        client_id: !Ref GoogleClientId
        client_secret: !Ref GoogleClientSecret
        authorize_scopes: "openid email profile"
      AttributeMapping:
        email: email
        given_name: given_name
        family_name: family_name
        username: email

  # 创建用户池域名(用于OAuth回调)
  MyUserPoolDomain:
    Type: AWS::Cognito::UserPoolDomain
    Properties:
      Domain: !Ref UserPoolDomainPrefix
      UserPoolId: !Ref MyUserPool

Outputs:
  UserPoolId:
    Value: !Ref MyUserPool
  UserPoolDomain:
    Value: !Sub "https://${UserPoolDomainPrefix}.auth.${AWS::Region}.amazoncognito.com"

关键配置说明

  • 核心资源:AWS::Cognito::UserPoolIdentityProvider是实现第三方身份提供商集成的关键,ProviderType指定为Google即可。
  • 谷歌OAuth配置:
    • 你需要先在谷歌云控制台创建OAuth 2.0客户端ID,回调URL必须设置为:https://<你的用户池域名>.auth.<区域>.amazoncognito.com/oauth2/idpresponse
    • ProviderDetails里的authorize_scopes要包含谷歌返回用户信息所需的权限,openid email profile是最常用的组合。
  • 属性映射:AttributeMapping用来把谷歌返回的用户属性映射到Cognito用户池的属性,比如把谷歌的email对应到Cognito的email,确保用户信息能正确同步。

部署注意事项

  1. 部署前替换模板中的占位符(比如GoogleClientId、GoogleClientSecret)为你自己的谷歌OAuth凭证。
  2. 确保你的谷歌OAuth客户端已将Cognito的回调URL添加到授权的重定向URI列表中。
  3. 如果需要自定义用户池的其他配置(比如密码策略、MFA),可以在MyUserPool的Properties里添加对应参数。

内容的提问来源于stack exchange,提问作者sigmaxf

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 12:13:14