ããã«ã¡ã¯ãã¯ã©ã¦ãã¤ã³ãã°ã¬ã¼ã·ã§ã³2é¨ æè¡1課 宮形 ã§ãã
Amazon Cognito (ä»¥ä¸ Cognito)ã®å°å ¥ã§ãCognito Hosted UI ã«ã¦ç¬èªãã¡ã¤ã³ãå©ç¨ããå ´åã®ããããã¤ã³ãã«ééããã®ã§ãæ¬BLOGã«ã¦ç´¹ä»ããã¦ããã ãã¾ãã
åæç°å¢ã¨ããããäº
ä½ãããç°å¢ã®æ¦ç¥å³ã¯ä¸è¨ã«ãªãã¾ããAWS ã® ALB 㨠Cognito ã§ä½ãããæè»½ãªå¤è¦ç´ èªè¨¼æ©è½ã§ãã
ãã®ç°å¢ã«ã¤ãã¦ã¯å¥BLOGã¨ãã¦ç´¹ä»ãã¦ããã¾ãã®ã§ã詳細ã¯ãã¡ãããåç §ãã ããã
ãã®æ§æã§ã¯ãALB ã® FQDN ã¸ã¢ã¯ã»ã¹ãã㨠Cognito ã® ãµã¤ã³ã¤ã³ç»é¢ (Hosted UI) ã¸ãªãã¤ã¬ã¯ããããã®ã§ããããã®ãªãã¤ã¬ã¯ãå
ã®URL㯠https://(ä»»æã®åå).auth.(ãªã¼ã¸ã§ã³å).amazoncognito.com/xxx...
ã¨ãAWSãç¨æãããµããã¡ã¤ã³ã¨ãªãã¾ãã
ãã®URLãç¬èªãã¡ã¤ã³ã¸å¤æ´ãããã¨ãåºæ¥ã¾ãããã¨ãã° https://auth.miyagata.abc
ã¨ããå
·åã§ããç¬èªãã¡ã¤ã³ã®DNSãµã¼ãã¼ã¯ãä¸è¨ã©ã¡ããå©ç¨ã§ãã¾ããç§ã¯å¾è
ã® 2. ã§è¡ãã¾ããã
- Amazon Route 53 ãããªãã¯ãã¹ãã¾ã¼ã³ ã® DNSãµã¼ãã¼
- ä»ãã³ãã¼ãèªåã® DNSãµã¼ãã¼
ããã£ã¦ãã¾ã£ããã¨
ä¸è¨ã®ãã㪠FQDN ã®æ§æã«ãããã¨ããã®ã§ãããCognito ã®ç»é²ã§ã¨ã©ã¼ã¨ãªãã¾ããã
AWSãªã½ã¼ã¹ | FQDN |
---|---|
ALB | www.miyagata.abc |
Cognito | auth.miyagata.abc |
ã¨ã©ã¼ã¡ãã»ã¼ã¸ã¯ä¸è¨ã¨ãªãã¾ãã
Custom domain is not a valid subdomain: Was not able to resolve the root domain, please ensure an A record exists for the root domain.
坾妿¹æ³
AWSå ¬å¼ããã¥ã¡ã³ãã«ä¸è¨ã®ãããªè¨è¼ãããã¾ãããã¡ããåå ã§ããã ãã¹ãããã UI ã¸ã®ç¬èªã®ãã¡ã¤ã³ã®ä½¿ç¨ - Amazon Cognito
ææããã¦ã§ããã¡ã¤ã³ããã®ã«ã¼ãã«ã¯ã DNS ã«æå¹ãª A ã¬ã³ã¼ã ãå¿ è¦ã§ããä¾ãã°ãã«ã¹ã¿ã ãã¡ã¤ã³ããauth.example.com ã®å ´åãexample.com ã IP ã¢ãã¬ã¹ã«è§£æ±ºã§ããå¿ è¦ãããã¾ãã詳細ã«ã¤ãã¦ã¯ãããã¡ã¤ã³åããåç §ãã¦ãã ããã
auth.miyagata.abc
ã®ã«ã¼ã㯠miyagata.abc
ã«ãªãã¾ãããç§ã®ç°å¢ã§ã¯ä½ã DNSã¬ã³ã¼ããããã¾ããã§ããã
ç¹ã«è¦ããã Webãµã¤ããç¡ãã®ã§ãã¨ããããä¸è¨ã®ããã«è¨å®ãã¾ãããAWSã®ããã¥ã¡ã³ãã«ã¯ãexample.com ã IP ã¢ãã¬ã¹ã«è§£æ±ºã§ããå¿ è¦ãããã¾ããã¨ããã®ã§ãåå解決ã®ã¿è¡ããã°ããã ããã¨èãã¾ããã
DNSã¬ã³ã¼ã | ã¿ã¤ã | å¤ |
---|---|---|
miyagata.abc | A | 127.0.0.1 |
127.0.0.1
ã¨ã¯ãã«ã¼ãããã¯ã¢ãã¬ã¹ã«ãªãã®ã§èªåèªèº«ã¨ããæå³ã«ãªãã¾ãã仮㫠miyagata.abc å®ã¦ã«ã¢ã¯ã»ã¹ããã£ã¦ããã¯ã©ã¤ã¢ã³ãã¯ã©ãã«ãéä¿¡ãããã¨ã¯ããã¾ãããå°æ¥çã« miyagata.abc ã® FQDN ã使ã£ã Webãµã¤ãã追å ããå ´åã¯ãé©å® Aã¬ã³ã¼ãã夿´ããã°ããã§ãã
çµæãç¡äºã¨ã©ã¼ã解決ã§ã㦠Cognito ã«ç¬èªãã¡ã¤ã³ãè¨å®ã§ãã¾ããã
ãã ããã®ç¶æ ã§ã¯ããã¡ã¤ã³ã®ã¹ãã¼ã¿ã¹ï¼CREATINGãã§ãããã¾ã å©ç¨ã§ãã¾ããã ç»é¢ã«è¡¨ç¤ºããããã¨ã¤ãªã¢ã¹ã¿ã¼ã²ããããå¤ã¨ãã¦ãCNAMEã¬ã³ã¼ãã追å ç»é²ãã¾ãã
DNSã¬ã³ã¼ã | ã¿ã¤ã | å¤ |
---|---|---|
auth.miyagata.abc | CNAME | 表示ãããå¤.cloudfront.net |
ãã°ããå¾ ã¤ã¨ãç¡äºããã¡ã¤ã³ã®ã¹ãã¼ã¿ã¹ï¼ACTIVEãã¨ãªããCognito Hosted UI ã® URL ãç¬èªãã¡ã¤ã³ã«ãããã¨ãã§ãã¾ããã
ããã§ã®çå
AWSå ¬å¼ããã¥ã¡ã³ãã§ã¯ ã«ã¼ãã¯ãAã¬ã³ã¼ããã¨ããã¾ãããããã¨ãã°ä¸è¨ã®ããã«ãµããã¡ã¤ã³åãã¦æ¢ã« CNAMEã¬ã³ã¼ããè¨å®ããã¦ããã±ã¼ã¹ãããã¨æããã¾ããã«ã¼ãã CNAME ã§ã Cognito ã¯åé¡ãªãã®ã§ããããï¼
DNSã¬ã³ã¼ã | ã¿ã¤ã | å¤ |
---|---|---|
sub.miyagata.abc | CNAME | ALBã®DNSã¨ã³ããã¤ã³ãå etc |
ããã§ãä¸è¨ã®ãããªæ§æãå¯è½ããæ¤è¨¼ãã¾ããã
AWSãªã½ã¼ã¹ | FQDN |
---|---|
ALB | sub.miyagata.abc |
Cognito | auth.sub.miyagata.abc |
çµæãç¡äºè¨å®ãã¦å©ç¨ãããã¨ãã§ãã¾ããã
ã¾ã¨ã
æ°è¦ãã¡ã¤ã³ç°å¢ã§æ§ç¯ããå ´åã¯ãã©ã¤ï¼ã¨ã©ã¼ã§ãè¨å®ã§ãã¾ããããã§ã«åå¨ãã¦ããéç¨ä¸ã®ãã¡ã¤ã³ã«ããã¦ã® DNSã¬ã³ã¼ãè¨å®ã¯æ¢åç°å¢ã«å½±é¿ãåºãªãããæ éã«è¡ãå¿ è¦ãããã¾ãã
ä»åã®ãã©ãã«ã·ã¥ã¼ãã«ãã£ã¦ Cognito Hosted UI ã§ç¬èªãã¡ã¤ã³ãå©ç¨ããéã®æ³¨æç¹ãæãããã¨ãã§ãã¦ããã£ãã§ãã
æ¬BLOGã®å 容ããçæ§ã®èª²é¡è§£æ±ºã«ã¤ãªããã°å¹¸ãã§ãã
宮形ç´å¹³(å·çè¨äºã®ä¸è¦§)
ã¨ã³ã¿ã¼ãã©ã¤ãºã¯ã©ã¦ãé¨ ã½ãªã¥ã¼ã·ã§ã³ã¢ã¼ããã¯ã1課
好ããªãé ã¯ç¼¶ãã¥ã¼ãã¤ã¨æ¬æ ¼ç¼é