æ¬è¨äºã¯
AWSã¢ã¯ã¼ãè¨å¿µï¼å¤ã®ã¢ããã³ãã«ã¬ã³ãã¼
3æ¥ç®ã®è¨äºã§ãã
ðð
2æ¥ç®
â¶â¶ æ¬è¨äº â¶â¶
4æ¥ç®
ðð
å°è¥¿ç§åã§ãã
ä»å¹´ãç§ã¯2024 Japan AWS Top Engineerã2024 Japan AWS All Certifications Engineerã«é¸åºãããå¼ç¤¾ã®è¡¨å½°è
ãåå ããããã°ã¤ãã³ããAWSã¢ã¯ã¼ãè¨å¿µï¼å¤ã®ã¢ããã³ãã«ã¬ã³ãã¼ãã«è¨äºãæç¨¿ãããã¨ãã§ãã¾ããã
ç§ã¯æã ãAWSãµã¼ãã¹ã®ã¢ãããã¼ãã®æ´å²ã辿ã£ã¦ããã®æ©è½ãã¾ã¨ããè¨äºãæ¸ãã¦ãã¾ãããä»åã¯ã¡ããã©è¯ãã¿ã¤ãã³ã°ã®AWSãµã¼ãã¹ãããã¾ããã®ã§ãããã«ã¤ãã¦æ¸ãã¦ã¿ã¾ãã
ã¨ãããã¨ã§ãæ´å²ã»å¹´è¡¨ã§ã¿ãAWSå ¨ãµã¼ãã¹ä¸è¦§ ï¼ã¢ãã¦ã³ã¹æ¥ãGeneral Availability(GA)ãAWSãµã¼ãã¹æ¦è¦ã®ã¾ã¨ãï¼ãããå§ã¾ã£ããAWSãµã¼ãã¹ãæ´å²ã»å¹´è¡¨ããæ©è½ãæ´ãåºãã¦ã¾ã¨ããã·ãªã¼ãºã®ç¬¬9å¼¾ã§ã(éå»ãAmazon S3ãAWS Systems ManagerãAmazon Route 53ãAmazon EventBridgeãAWS KMSãAmazon SQSãAWS Lambdaã«ã¤ãã¦æ¸ãã¾ãã)ã
ä»åã¯2014å¹´7æ10æ¥ã«ã¢ãã¦ã³ã¹ããã³GAã«ãªã£ããµã¼ãã¼ã¬ã¹ã§ãã«ããã¼ã¸ããªèªè¨¼ã»èªå¯ãµã¼ãã¹ãæä¾ããAmazon Cognitoã«ã¤ãã¦æ´å²å¹´è¡¨ã使ãã¦ã¿ã¾ããã
æ¬æ¥ã2024å¹´7æ10æ¥ã¯Amazon Cognitoãã¢ãã¦ã³ã¹ããã³GAã¨ãªã£ãæ¥ãããã¡ããã©10å¨å¹´ãè¿ããè¨å¿µãã¹ãæ¥ã§ãã
ãã®è¨äºã§ãAmazon Cognitoã®èªçããæ©è½è¿½å ãã¢ãããã¼ãã追ããªããä¸»è¦æ©è½ãç¾å¨ã®Amazon Cognitoã®æ©è½ä¸è¦§ã¨æ¦è¦ã¨ãã¦ã¾ã¨ãã¦ãã¾ãã
ãããããåAWSãµã¼ãã¹ã®æ©è½æ¦è¦ã«å ãã¦ã³ã³ã»ãããå¤ãããªããã®ãå¤ãã£ã¦ãããã®ãç¥ãæãããã¨ãªãã°ã¨èãã¦ãã¾ãã
ä»åã®è¨äºã®å
å®¹ã¯æ¬¡ã®ãããªæ§æã«ãªã£ã¦ãã¾ãã
- Amazon Cognitoæ´å²å¹´è¡¨ã®ä½æçµç·¯ã¨æ¹æ³
- Amazon Cognitoæ´å²å¹´è¡¨(2014å¹´07æ10æ¥ï½2024å¹´07æ10æ¥ã¾ã§ã®ã¢ãããã¼ã)
- ç¾å¨ã®Amazon Cognitoã®æ©è½ä¸è¦§ã¨æ¦è¦
- Amazon Cognitoã®ã¦ã¼ã¹ã±ã¼ã¹
- Amazon Cognitoã®æ¦å¿µå³
- Amazon Cognito User Pools
- Amazon Cognito Identity Pools
- Amazon Cognito Identity Poolsã®æ©è½æ¦è¦
- ãã¼ã«ãã¼ã¹ã®ã¢ã¯ã»ã¹å¶å¾¡(Role-Based Access Control, RBAC)
- 屿§ãã¼ã¹ã®ã¢ã¯ã»ã¹å¶å¾¡(Attribute-Based Access Control, ABAC)
- AWSãªã½ã¼ã¹ã«ã¢ã¯ã»ã¹ã§ããèªè¨¼æ å ±ã®åå¾
- éçºè èªè¨¼ID(Developer-Authenticated Identities)
- å¤é¨ã¢ã¤ãã³ãã£ãã£ãããã¤ãã¼
- ã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹
- User Poolsã¨Identity Poolsã®éãã¨æ¯è¼
- AWS AppSyncã¨Amazon Cognito Sync
- AWSãµã¼ãã¹ã¨ã®çµ±å
- AWS Amplifyã¨ã®çµ±å
- AWS SDKã¨ã®çµ±å
- Amazon Verified Permissionsã¨ã®çµ±å
- Amazon Cognito User Poolsã«ããèªè¨¼ããã»ã¹
- Amazon Verified Permissionsã«ããèªå¯ããã»ã¹
- Amazon Cognito User Poolsã¨Amazon Verified Permissionsãçµ±åãããå©ç¹
- Amazon API Gatewayã®èªè¨¼ã»èªå¯ã§Amazon Cognito User Poolsã¨Amazon Verified Permissionsã使ç¨ããå ´åã®ããã»ã¹ã¨å©ç¹
- Amazon Cognito Identity Poolsã¨Amazon Verified Permissionsã®å½¹å²ã¨ç¨éã®éã
- ã¾ã¨ã
Amazon Cognitoæ´å²å¹´è¡¨ã®ä½æçµç·¯ã¨æ¹æ³
ä»åãAmazon Cognitoã®æ´å²å¹´è¡¨ã使ããã®ã¯ãä»å¹´2024å¹´ã«Amazon Cognitoãã¢ãã¦ã³ã¹ãã10å¨å¹´ãè¿ãããã¨ã«ä»ãªãã¾ããã
ã¾ããAmazon Cognitoã2014å¹´7æã«ã¢ãã¦ã³ã¹ããã³GAã«ãªã£ã¦ä»¥éãæ§ã
ãªAWSãµã¼ãã¹ã¨ã®çµ±åãæ©è½ã®æ¡å¼µãããã¦ãããããæ¬¡ã®ã¢ããã¼ãã§Amazon Cognitoã®æ
å ±ãæ´çãããã¨èãããã¨ãçç±ã®ä¸ã¤ã§ãã
- Amazon Cognitoã®æ´å²ã追ããªãããã¢ãããã¼ãã®å¤é·ãæ´çãã
- Amazon Cognitoã®æ©è½ä¸è¦§ã¨ç¹å¾´ãã¾ã¨ãã
ãã®å¹´è¡¨ã¯ä¸»ã«æ¬¡ã®ããã°ãããã¥ã¡ã³ãå±¥æ´ã®Amazon Cognitoã«é¢ããå 容ãåèã«ãã¦ãã¾ãã
åèã«ããè³æã«ãã£ã¦ã¢ãã¦ã³ã¹ãè¨äºæç¨¿ã®ã¿ã¤ãã³ã°ãéãå ´åããã£ããããå¹´è¡¨ã®æ¥ä»ã«ã¯è¥å¹²ã®ãã¬ãããã¾ãã
æ²è¼ãã¦ããå
容ã¯ç¾å¨ã®Amazon Cognitoã¨é¢ä¿ãã¦ãã主è¦ãªæ©è½ã¨æ¦è¦èª¬æã«å¿
è¦ãªãã®ã«éå®ãã¦ãã¾ãã
ã¤ã¾ããããã®å¹´è¡¨ã«ãããã®ãAmazon Cognitoã®æ©è½ã®ã¢ãããã¼ãã®å
¨ã¦ã§ã¯ãªããããã¾ã§ç§ãããã¯ã¢ãããã代表çãªã¢ãããã¼ãã§ãããã¨ã«ã注æãã ããã
Amazon Cognitoæ´å²å¹´è¡¨(2014å¹´07æ10æ¥ï½2024å¹´07æ10æ¥ã¾ã§ã®ã¢ãããã¼ã)
ãã¦ããããããAmazon Cognitoã®æ©è½ã«é¢ãã年表ã§ãã
â»ãã¼ãã«ã¯é
ç®åã¯ãªãã¯ã§ã½ã¼ãã§ãã¾ãã
å¹´ææ¥ | æ¦è¦ |
---|---|
2014/07/10 | Amazon Cognitoãã¢ãã¦ã³ã¹ããã³General Availability(GA)ã¨ãªãã åæã®Amazon Cognitoã¯AmazonãFacebookãGoogleã¨ãã£ãæ¢åã®IDãããã¤ãã¼ã¨é£æºããèªè¨¼ããã¦ããªãã²ã¹ãã¦ã¼ã¶ã¼ããµãã¼ããã¦ã¦ã¼ã¶ã¼åºæã®ãã¼ã¿ãå®å ¨ã«ç®¡çããIdentity Poolsã¨ããã¼ã¿ã®åæãæ ããã¦ã¼ã¶ã¼ã®ã¢ããªè¨å®ãã²ã¼ã ç¶æ ãªã©ãããã¤ã¹éã§åæããCognito Syncã«ç¸å½ããæ©è½ãæä¾ãã¦ãã¾ããã |
2014/09/29 | ç¬èªã®ã¦ã¼ã¶ã¼IDã·ã¹ãã ãå©ç¨ã§ããDeveloper authenticated identities(éçºè èªè¨¼ID)ã追å ããããã¦ã¼ã¶ã¼ãææããèªè¨¼ããã³ID管çã·ã¹ãã ãAmazon Cognitoã®ã¢ã¤ãã³ãã£ãã£ãããã¤ãã¼ã¨ãã¦æ±ããããã«ãªãã |
2014/10/23 | OpenID Connectãããã¤ãã¼ã®ãµãã¼ãã追å ãããã |
2014/11/06 | Amazon Cognito Syncã«ããããã·ã¥åæã®ãµãã¼ãã追å ãããã |
2015/03/04 | ã¦ã¼ã¶ã¼IDãã¼ã¿ãAmazon Kinesisã«èªåçã«ã¹ããªã¼ãã³ã°ããAmazon Cognito Streamsã追å ããããã¼ã¿ã¹ããªã¼ã ã®å¶å¾¡ã¨æ´å¯ãå¯è½ã«ãªãã |
2015/04/09 | AWS Lambdaã¨ã®çµ±åã追å ãããAmazon Cognitoã®éè¦ãªã¤ãã³ãã«å¿ãã¦AWS Lambda颿°ãå®è¡ã§ããããã«ãªãã |
2015/04/30 | ãããªãã¯ãã°ã¤ã³ãããã¤ãã¼ã¨ãã¦Twitterã¨Digitsã追å ãããã |
2016/02/18 | AWS CloudTrailã§Amazon Cognito Identity Poolsã¨Amazon Cognito Syncã®ä½æã»å¤æ´ã»åé¤ã追跡ã§ããããã«ãªãã |
2016/04/19 | Amazon Cognito Identity Poolsã§ã¦ã¼ã¶ã¼ã®ãµã¤ã³ã¢ããã¨ãµã¤ã³ã¤ã³ã追å ã§ããããã«ãªãã |
2016/06/23 | SAML2.0ã使ç¨ããã¢ã¤ãã³ãã£ãã£ãããã¤ãã¼ã«ããèªè¨¼ã®ãµãã¼ãã追å ãããã |
2016/07/28 | Amazon Cognito User Poolsãä¸è¬æä¾éå§ãã¦ã¼ã¶ã¼ãã£ã¬ã¯ããªã使ã»ç¶æããã¦ã¼ã¶ã¼ãã¼ã«ã使ç¨ãã¦ã¢ãã¤ã«ã¢ããªãã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã«ãµã¤ã³ã¢ããã¨ãµã¤ã³ã¤ã³æ©è½ã追å ã§ããããã«ãªãã |
2016/09/01 | Amazon Cognito User Poolsã«ä¸æ¬ã¤ã³ãã¼ãæ©è½ã追å ããããæ¢åã®ã¢ã¤ãã³ãã£ãã£ãããã¤ãã¼ããAmazon Cognito User Poolsã¸ã®ã¦ã¼ã¶ã¼ç§»è¡ãå¯è½ã«ãªãã AWS CloudTrailã§Amazon Cognito User Poolsã®ä½æã»å¤æ´ã»åé¤ã追跡ã§ããããã«ãªãã |
2016/10/06 | Amazon Cognitoã³ã³ã½ã¼ã«ã¨APIã§ã管çè ãã¦ã¼ã¶ã¼ã¢ã«ã¦ã³ãã使ããæ©è½ã追å ãããã |
2016/11/09 | AWS Mobile Hubã§ã¡ã¼ã«ã¨ãã¹ã¯ã¼ãã®ãªãã·ã§ã³ã使ç¨ããã¨ãAmazon Cognitoã§ã¢ããªã®ãã«ããã¼ã¸ãã¦ã¼ã¶ã¼ãã£ã¬ã¯ããªããããã¸ã§ãã³ã°ã§ããããã«ãªãã |
2016/12/15 | Amazon Cognito User Poolsã§ã°ã«ã¼ãæ©è½ã追å ããããAmazon Cognito Identity Poolsã§Role-Based Access Control(RBAC)ã追å ãããã |
2017/04/28 | Amazon CognitoãAWS CloudFormationã§ãµãã¼ããããã |
2017/07/06 | Amazon CognitoãHIPAA驿 ¼æ§ã¨PCIã³ã³ãã©ã¤ã¢ã³ã¹ãéæãã¦ã¼ã¶ã¼ãé»è©±çªå·ã¾ãã¯ã¡ã¼ã«ã¢ãã¬ã¹ãã¦ã¼ã¶ã¼åã¨ãã¦ä½¿ç¨ã§ããããã«ãªãã |
2017/08/10 | Amazon Cognito User Poolsã«ãã§ãã¬ã¼ã·ã§ã³ã¨çµã¿è¾¼ã¿ã¢ããªUIæ©è½ã追å ããããã¦ã¼ã¶ã¼ãOAuth 2.0ã使ç¨ãã¦Facebookã»Googleã»Login with Amazonã»SAMLã¢ã¤ãã³ãã£ãã£ãããã¤ãã¼ã使ç¨ãã¦ã¦ã¼ã¶ã¼ãã¼ã«ã«ãµã¤ã³ã¤ã³ã§ããããã«ãªãã |
2017/09/26 | Amazon Pinpointã¨ã®çµ±åã追å ããããAmazon Cognito User Poolsã¢ããªã®åæã«Amazon Pinpointã使ç¨ããAmazon Pinpointãã£ã³ãã¼ã³ã®ã¦ã¼ã¶ã¼ãã¼ã¿ãå¼·åã§ããããã«ãªãã |
2017/11/28 | Amazon Cognito Advanced Security(ãã¼ã¿ç)ã追å ããããæªæã®ãããããããã¢ããªã¨ã¦ã¼ã¶ã¼ãä¿è·ããã¤ã³ã¿ã¼ãããä¸ã®ä»ã®å ´æã§æ¼æ´©ããèªè¨¼æ å ±ããã¦ã¼ã¶ã¼ã¢ã«ã¦ã³ããä¿è·ãããµã¤ã³ã¤ã³è©¦è¡ã®è¨ç®ããããªã¹ã¯ã«åºã¥ãã¦ãµã¤ã³ã¤ã³ã«å¿ è¦ãªãã£ã¬ã³ã¸ãèªåçã«èª¿æ´ããæ°ããã»ãã¥ãªãã£æ©è½ã追å ãããã |
2018/02/08 | Amazon Cognito Lambda Migration Triggerããµãã¼ããã¦ã¼ã¶ã¼ãã¼ã«ã«ãããã¦ã¼ã¶ã¼åå¨ç¢ºèªãããæ¢åã®ã¢ããªã±ã¼ã·ã§ã³ãã£ã¬ã¯ããªããã¦ã¼ã¶ã¼ãã¼ã«ã«ã¦ã¼ã¶ã¼ã®ãããã¡ã¤ã«ãã¼ã¿ãã³ãã¼ã§ããããã«ãªãã |
2018/05/17 | Amazon Cognito User Poolsã«OpenID Connect(OIDC)ã¢ã¤ãã³ãã£ãã£ãããã¤ãã¼(SalesforceãPing Identityãªã©)ã使ç¨ãããµã¤ã³ã¤ã³ã追å ãããã |
2018/06/04 | Amazon Cognito User Poolsã§ãã¹ãããããã°ã¤ã³UIã«ç¬èªã®ã«ã¹ã¿ã ãã¡ã¤ã³ã使ç¨ã§ããããã«ãªãã |
2018/06/14 | Amazon Cognito Advanced Securityãä¸è¬æä¾ããããæªæã®ãããããããã¢ããªã¨ã¦ã¼ã¶ã¼ãä¿è·ããã¤ã³ã¿ã¼ãããä¸ã®ä»ã®å ´æã§æ¼æ´©ããèªè¨¼æ å ±ããã¦ã¼ã¶ã¼ã¢ã«ã¦ã³ããä¿è·ãããµã¤ã³ã¤ã³è©¦è¡ã®è¨ç®ããããªã¹ã¯ã«åºã¥ãã¦ãµã¤ã³ã¤ã³ã«å¿ è¦ãªãã£ã¬ã³ã¸ãèªåçã«èª¿æ´ããæ°ããã»ãã¥ãªãã£æ©è½ã追å ãããã |
2019/01/22 | Amazon Cognitoã99.9%ã®ãµã¼ãã¹ã¬ãã«ã¢ã°ãªã¼ã¡ã³ã(SLA)ãã¢ãã¦ã³ã¹ã |
2019/03/26 | ã¿ã°ä»ããµãã¼ãã追å ããããAmazon Cognito ãªã½ã¼ã¹ã®ã¿ã°ä»ãã«é¢ããæ å ±ã追å ãããã |
2019/04/08 | Amazon Cognito User Poolsã®Amazon SESã¡ã¼ã«è¨å®æ©è½ã追å ããããAmazon Cognitoã Amazon SESè¨å®ã使ç¨ãã¦ã¦ã¼ã¶ã¼ã«ã¡ã¼ã«ãéä¿¡ããããã«ã¦ã¼ã¶ã¼ãã¼ã«ãè¨å®ã§ããããã«ãªãã |
2019/05/06 | 管çè ãã¨ã³ãã¦ã¼ã¶ã¼ã®ä¸æãã¹ã¯ã¼ãã¾ãã¯æ°¸ç¶ãã¹ã¯ã¼ããè¨å®ã§ããããã«ããã¦ã¼ã¶ã¼ãã¹ã¯ã¼ããªã»ããAPIã追å ãç¢ºèªæ¸ã¿ã®é»è©±ãã¡ã¼ã«ãå©ç¨ã§ããªãå ´åã§ãã¨ã³ãã¦ã¼ã¶ã¼ãå©ç¨ã§ããããã«ãªãã |
2019/10/07 | AWS CloudFormationã§Amazon Cognitoã®ãã¹ããããUIãã¡ã¤ã³ãå®å ¨ãã¤èªåçã«æ§æããæ©è½ããã¹ããããUIã®ã«ã¹ã¿ãã¤ãºãæ§æããæ©è½ãIdentityProviderãæ§æããæ©è½ãAmazon Cognito Advanced Securityã®åä½ãæ§æããæ©è½ããªã½ã¼ã¹ãµã¼ãã¼ãæ§æããæ©è½ã追å ã§ãµãã¼ãã |
2019/11/20 | Amazon Cognito User PoolsãAppleã§ã®ãµã¤ã³ã¤ã³ããµãã¼ãã |
2019/11/26 | Amazon Cognito User Poolsã§ãã¹ã¯ã¼ããå¿ããå ´åã®å¾©æ§æ¹æ³ã®åªå é ä½ä»ãããµãã¼ãã |
2020/01/10 | Amazon CognitoãAmazon CloudWatch Usage Metrics(使ç¨ç¶æ³ã¡ããªã¯ã¹)ããµãã¼ãã |
2020/02/05 | AWS CloudTrailã§Amazon Cognito User Poolsã®ãã¹ã¦ã®APIå¼ã³åºãã®ãã°è¨é²ããµãã¼ãã |
2020/02/12 | Amazon Cognito User Poolsãã¦ã¼ã¶ã¼ã¨ã¤ãªã¢ã¹ã®å¤§æåã¨å°æåãåºå¥ããªãæ©è½ããµãã¼ããã¦ã¼ã¶ã¼ãã¼ã«ã使ããåã«ã¦ã¼ã¶ã¼åã®å¤§æåå°æåã®åºå¥ãç¡å¹ã«ãããã¨ãæ¨å¥¨ãããããã«ãªãã |
2020/04/07 | Amazon Cognito Identity PoolsãApple(Sign in with Apple)ã§ã®ãµã¤ã³ã¤ã³ããµãã¼ãã |
2020/08/12 | Amazon Cognito ã¦ã¼ã¶ã¼ãã¼ã«ãã¢ã¯ã»ã¹ãã¼ã¯ã³ã¨ãªãã¬ãã·ã¥ãã¼ã¯ã³ã®æå¹æéã®ã«ã¹ã¿ãã¤ãºããµãã¼ãã |
2020/10/30 | Amazon Cognito User Poolsã®ã¯ã©ã¼ã¿ç®¡çã¨ä½¿ç¨ç¶æ³ã®è¿½è·¡ãAWS Service Quotasã¨Amazon CloudWatchã¡ããªã¯ã¹ã使ç¨ãã¦ã§ããããã«ãªãã |
2021/01/14 | Amazon Cognito Identity Poolsã§ã¢ã¤ãã³ãã£ãã£ãããã¤ãã¼ã®ã¦ã¼ã¶ã¼å±æ§ã使ç¨ããã¢ã¯ã»ã¹å¶å¾¡ã«ãã£ã¦ãAWSãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹è¨±å¯ç®¡çãç°¡ç´ åã§ããããã«ãªãã |
2021/06/02 | Amazon CognitoãAmazon SNSã®SMS Sandboxããµãã¼ãã |
2021/06/10 | Amazon Cognitoããªãã¬ãã·ã¥ãã¼ã¯ã³ããªã¢ã«ã¿ã¤ã ã§åãæ¶ããã¨ã«ããã¿ã¼ã²ãããµã¤ã³ã¢ã¦ãããµãã¼ããRevokeToken APIã¨å¤±å¹ã¨ã³ããã¤ã³ãã追å ãããRevokeTokenæä½ã使ç¨ããã¦ã¼ã¶ã¼ã®æ´æ°ãã¼ã¯ã³ã失å¹ããããã¨ãã§ããããã«ãªãã |
2021/11/18 | Amazon Cognito User Poolsã§æ°ããã³ã³ã½ã¼ã«ã¨ã¯ã¹ããªã¨ã³ã¹ã追å ãããã |
2022/03/14 | Amazon Cognito User Poolsã§Amazon SNSã¨Amazon SESã¨ã®åä¸ãªã¼ã¸ã§ã³å çµ±åããµãã¼ããAmazon SNSãSMSã¡ãã»ã¼ã¸ã«ãAmazon SESãã¡ã¼ã«ã¡ãã»ã¼ã¸ã«ä½¿ç¨ã§ããããã«ãªãã |
2022/05/31 | Amazon Cognito Advanced Securityã®ãªã¹ã¯è©ä¾¡ãæ¹åãããAmazon Cognitoã¸ã®èªè¨¼ããã¦ããªãå¼ã³åºãã§ãå¼ã³åºãå ã®ã³ã³ããã¹ããã¼ã¿ã®ä¸é¨ã¨ãã¦IPã¢ãã¬ã¹ã伿ã§ããããã«ãªãã |
2022/08/11 | Amazon Cognito User Poolsã«AWS WAF Web ACLãé¢é£ä»ããããããã«ãªãã |
2022/09/09 | Amazon Cognitoã®ãã¹ããããUIã§Time-Based-One-Time-Password(TOTP) MFAããã¤ã¹ãç»é²ã§ããããã«ãªãã |
2022/10/24 | Amazon Cognito User Poolsã®åé¤ä¿è·ãæä¾éå§ã |
2023/02/15 | AWS CloudTrailã§Amazon Cognito Identity Poolsã®ãã¼ã¿ã¤ãã³ããè¨é²ã§ããããã«ãªãã |
2023/05/16 | Amazon Cognito Identity Poolsã®ã³ã³ã½ã¼ã«ã¨ã¯ã¹ããªã¨ã³ã¹ãæ¹åãããã |
2023/08/01 | Amazon Verified PermissionsãGeneral Availability(GA)ã«ãªããAmazon Cognitoã®å±æ§ã«åºã¥ãã¦ããªã·ã¼ãæ¤è¨¼ããAmazon Cognitoãã¼ã¯ã³ã使ç¨ãã¦ãªã¯ã¨ã¹ããèªå¯ã§ããã¢ããªã±ã¼ã·ã§ã³ç¨ã®çµ±åèªè¨¼ããã³èªå¯ã½ãªã¥ã¼ã·ã§ã³ãå¯è½ã«ãªãã |
2023/12/12 | Amazon Cognito Identity Poolsãã¢ã¯ã»ã¹ãã¼ã¯ã³ã®å 容ãã«ã¹ã¿ãã¤ãºæ©è½ããµãã¼ããã¦ã¼ã¶ã¼ãã¼ã«ã¢ã¯ã»ã¹ãã¼ã¯ã³ã®ã¯ã¬ã¼ã ã¨ã¹ã³ã¼ãã追å ã夿´ãããã³åé¤ã§ããããã«ãªãã |
2023/12/19 | Amazon Cognito User PoolsãAWS Service Quotasã§ã¢ã¤ãã³ãã£ãã£ã®ä½æã¨åå¾ãããã³ã¢ã¤ãã³ãã£ãã£ãã¼ã«ã®ã¿ã°ã®ç®¡çã«ãã使ç¨ãããæä½ã®ã¯ã©ã¼ã¿ã管çã§ããããã«ãªãã |
2024/02/01 | Amazon Cognitoã§ç½²åãããSAMLèªè¨¼ãªã¯ã¨ã¹ããéä¿¡ããSAML IDãããã¤ãã¼ããã®æå·åãããå¿çãè¦æ±ããSAMLãã§ãã¬ã¼ã·ã§ã³ã«IDãããã¤ãã¼ãéå§ããã·ã³ã°ã«ãµã¤ã³ãªã³(SSO)ã使ç¨ã§ããããã«ãªãã |
2024/04/05 | Amazon Verified Permissionsã使ç¨ãã¦æ¿èªãããAmazon Cognitoã°ã«ã¼ãã®ã¦ã¼ã¶ã¼ã®ã¿ãã¢ããªã±ã¼ã·ã§ã³ã®APIã«ã¢ã¯ã»ã¹ã§ããããã«ãªãã |
2024/05/21 | Amazon Verified Permissionsã使ç¨ãã¦Cognitoãã¼ã¯ã³ã使ç¨ãã¦èªè¨¼ããå ´åã«Cognitoã°ã«ã¼ãã®ã¡ã³ãã¼ã·ããã«åºã¥ãã¦Cedarããªã·ã¼ã使ã§ããããã«ãªãã |
2024/05/30 | Amazon Cognito User Poolsãã¢ã¯ã»ã¹ãã¼ã¯ã³ã®ã«ã¹ã¿ãã¤ãºæ©è½ãæ¡å¼µãã¦ãIDãã¼ã¯ã³ã¨ã¢ã¯ã»ã¹ãã¼ã¯ã³ã®ä¸¡æ¹ã§ãé åã»ãããã»JSONãªãã¸ã§ã¯ããªã©ã®è¤éãªã«ã¹ã¿ã 屿§ããµãã¼ãããããã«ãªãã |
ç¾å¨ã®Amazon Cognitoã®æ©è½ä¸è¦§ã¨æ¦è¦
ããããã¯ãç¾å¨ã®Amazon Cognitoã®ä¸»è¦ãªæ©è½ã«ã¤ãã¦è©³ãã解説ãã¦ããã¾ãã
Amazon Cognitoã¯ãã¢ãã¤ã«ããã³Webã¢ããªã±ã¼ã·ã§ã³ã®éçºè
ãã¦ã¼ã¶ã¼èªè¨¼ã¨ãã¼ã¿åæãç°¡åã«å®ç¾ã§ããããã«ããã¼ã¸ããªèªè¨¼ãµã¼ãã¹ã§ãã
Amazon Cognitoã¯ä¸»ã«äºã¤ã®æ©è½ãæä¾ãã¾ãã
ä¸ã¤ç®ã®ãUser Poolsãã¯ãã¦ã¼ã¶ã¼ãã£ã¬ã¯ããªã管çãããµã¤ã³ã¢ããããµã¤ã³ã¤ã³ãªã©ã®ã¦ã¼ã¶ã¼èªè¨¼ãè¡ããã¢ããªã±ã¼ã·ã§ã³ã«å¿
è¦ãªèªè¨¼ãã¬ã¼ã ã¯ã¼ã¯ãç°¡åã«çµ±åã§ãã¾ããã¾ããèªè¨¼å¾ã«JWTãã¼ã¯ã³ãçºè¡ããã¢ããªã±ã¼ã·ã§ã³å
ã§ã®èªå¯ã«ã使ç¨ã§ãã¾ãã
äºã¤ç®ã®ãIdentity Poolsãã¯ãèªè¨¼æ¸ã¿ããã³æªèªè¨¼ã®ã¦ã¼ã¶ã¼ã«å¯¾ãã¦ä¸æçãªAWSã¯ã¬ãã³ã·ã£ã«ãä»ä¸ããAWSãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ã許å¯ãããã¨ã§ãAWSç°å¢ã§ã®èªå¯ãå®ç¾ãã¾ãã
èªè¨¼ã¯ä¸»ã«ãUser Poolsãã使ç¨ãã¦ã¦ã¼ã¶ã¼ã®èº«å
ã確èªãã¾ããèªå¯ã«ã¤ãã¦ã¯ãã¢ããªã±ã¼ã·ã§ã³å
ã§ã¯ãUser Poolsããçºè¡ãããã¼ã¯ã³ã使ç¨ããAWSãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ã¯ãIdentity Poolsããçµç±ãã¦å¶å¾¡ãã¾ãã
ãã®åæ¹ã使ç¨ãããã¨ã§ãã¢ããªã±ã¼ã·ã§ã³éçºè
ã¯ã¦ã¼ã¶ã¼ã®èªè¨¼æ
å ±ã¨ã¢ã¯ã»ã¹æ¨©éã广çã«ç®¡çãããã¨ãã§ãã¾ãã
ããã«ãAmazon Cognitoã¯ä»ã®AWSãµã¼ãã¹ã¨ã®ç°¡åãªçµ±åãå¯è½ã§ãããããã¤ã¹éã§ã®ã¦ã¼ã¶ã¼ãã¼ã¿ã®åæããµãã¼ããã¦ãããããã¦ã¼ã¶ã¼ã¨ã¯ã¹ããªã¨ã³ã¹ã®åä¸ã«å¯ä¸ãã¾ãã
ã¾ããAWS IAMã«ããã¢ã¯ã»ã¹å¶å¾¡ã¨çµã¿åããããã¨ã§ãã»ãã¥ãªãã£ãå¼·åãã¤ã¤ãéçºã®æè»æ§ãä¿ã¡ãªããã¢ããªã±ã¼ã·ã§ã³ãå®å
¨ã«éç¨ã§ãã¾ãã
Amazon Cognitoã®ã¦ã¼ã¹ã±ã¼ã¹
Amazon Cognitoã¯ãèªè¨¼ã¨èªå¯ãã»ãã¥ã¢ã«ç®¡çãããã¨ã§ãã¢ããªã±ã¼ã·ã§ã³éçºè
ãã¦ã¼ã¶ã¼æ
å ±ã®åãæ±ããç°¡ç´ åã§ããããã«ãã¶ã¤ã³ããã¦ãã¾ãã
Amazon Cognitoã®ä¸»è¦ãªã³ã³ãã¼ãã³ãã§ããUser Poolsã¨Identity Poolsãæ´»ç¨ãã主ãªã¦ã¼ã¹ã±ã¼ã¹ã«ã¯ä»¥ä¸ã®ãããªãã®ãæãããã¾ãã
ã¦ã¼ã¶ã¼èªè¨¼
User Poolsã使ç¨ãã¦ã¢ãã¤ã«ãã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã§å®å ¨ã«ã¦ã¼ã¶ã¼ç»é²ã¨ãã°ã¤ã³æ©è½ãæä¾ãã¾ãã
ã½ã¼ã·ã£ã«IDãããã¤ãã¼(Facebookã»Googleã»Amazonã»Apple)ãOIDCãSAMLãéãããã§ãã¬ã¼ã·ã§ã³èªè¨¼ããµãã¼ããã¾ããã¦ã¼ã¶ã¼èªå¯ã¨ãªã½ã¼ã¹ã¢ã¯ã»ã¹ç®¡ç
Identity Poolsã使ç¨ãã¦ãèªè¨¼æ¸ã¿ããã³æªèªè¨¼ã®ã¦ã¼ã¶ã¼ã«AWSãªã½ã¼ã¹ã¸ã®ä¸æçãªã¢ã¯ã»ã¹ã許å¯ãã¾ãã
User Poolsã®ã°ã«ã¼ãæ©è½ã使ç¨ãã¦ãã¢ããªã±ã¼ã·ã§ã³å ã®æ¨©é管çãè¡ãã¾ãããµã¼ãã¼ãµã¤ããªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹å¶å¾¡
User Poolsããçºè¡ããããã¼ã¯ã³ã使ç¨ãã¦ããµã¼ãã¼ãµã¤ããªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ãå¶å¾¡ãã¾ããAPI Gatewayã¨Lambdaãä»ãããªã½ã¼ã¹ã¢ã¯ã»ã¹
API Gatewayã§User Poolsã®ãã¼ã¯ã³ãæ¤è¨¼ããLambdaãã¡ã³ã¯ã·ã§ã³ãèªä½APIã¸ã®ã¢ã¯ã»ã¹ãå¶å¾¡ãã¾ããAWSãµã¼ãã¹ã¸ã®ã¢ã¯ã»ã¹
User Poolsã¨Identity Poolsãçµã¿åããã¦ãèªè¨¼ãããã¦ã¼ã¶ã¼ã«å¯¾ãã¦AWSãµã¼ãã¹ã¸ã®ä¸æçãªã¢ã¯ã»ã¹æ¨©ãä»ä¸ãã¾ãããµã¼ããã¼ãã£èªè¨¼ã¨AWSãµã¼ãã¹ã¢ã¯ã»ã¹
Identity Poolsã使ç¨ãã¦ããµã¼ããã¼ãã£IDãããã¤ãã¼ã§èªè¨¼ãããã¦ã¼ã¶ã¼ã«AWSãµã¼ãã¹ã¸ã®ã¢ã¯ã»ã¹ã許å¯ãã¾ããAWS AppSyncãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹
User Poolsã®ãã¼ã¯ã³ã使ç¨ãã¦ãAWS AppSyncãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ãå¶å¾¡ãã¾ãã
Identity Poolsããåå¾ããIAMèªè¨¼æ å ±ã使ç¨ãã¦ãAWS AppSync GraphQL APIã«ãªã¯ã¨ã¹ããéä¿¡ãã¾ããã¢ããªã±ã¼ã·ã§ã³éã§ã®ã¦ã¼ã¶ã¼ãã¼ã¿ã®åæ
User Poolsã®æ©è½ãæ´»ç¨ãã¦ãã¦ã¼ã¶ã¼ã®ããã¤ã¹éã§è¨å®æ å ±ãã¢ããªã±ã¼ã·ã§ã³ã®ç¶æ ãåæããã¾ãã
ã¦ã¼ã¹ã±ã¼ã¹ã®å ·ä½ä¾
ã½ã¼ã·ã£ã«ã¡ãã£ã¢çµ±åãã°ã¤ã³
ã¦ã§ããã¢ãã¤ã«ã¢ããªã±ã¼ã·ã§ã³ã§ãã¦ã¼ã¶ã¼ãFacebookãGoogleãªã©ã®ã½ã¼ã·ã£ã«ã¢ã«ã¦ã³ãã使ç¨ãã¦ãã°ã¤ã³ããæ©è½ãæä¾ãã¾ããUser Poolsããã®èªè¨¼ãå¦çãã¾ããã¢ãã¤ã«ã¢ããªã®ã«ã¹ã¿ã èªè¨¼ããã¼
ã¢ãã¤ã«ã¢ããªã±ã¼ã·ã§ã³ã§ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ã(OTP)ããã¤ãªã¡ããªãã¯ã¹ã使ã£ãã»ãã¥ãªãã£å¼·åããããã°ã¤ã³ããã»ã¹ãå®è£ ãã¾ããUser Poolsã§ãããã®èªè¨¼æ¹æ³ããµãã¼ããã¾ãããµã¼ãã¼ã¬ã¹ããã¯ã¨ã³ãã¸ã®ã¢ã¯ã»ã¹èªå¯
ã¢ããªã±ã¼ã·ã§ã³ãAmazon S3ãDynamoDBãªã©ã®AWSãµã¼ãã¹ã«ã¢ã¯ã»ã¹ããéãIdentity Poolsã使ç¨ãã¦ä¸æçãªAWSã¯ã¬ãã³ã·ã£ã«ãçºè¡ããèªè¨¼ãããã¦ã¼ã¶ã¼ã®ã¿ããªã½ã¼ã¹ã«ã¢ã¯ã»ã¹ã§ããããã«ãã¾ãããã¤ã¯ããµã¼ãã¹ã¢ã¼ããã¯ãã£ã§ã®èªè¨¼
API Gatewayã¨Lambdaã使ç¨ãããã¤ã¯ããµã¼ãã¹ã¢ã¼ããã¯ãã£ã§ãUser Poolsã®ãã¼ã¯ã³ãå©ç¨ãã¦åãµã¼ãã¹ã¸ã®ã¢ã¯ã»ã¹ãå¶å¾¡ãã¾ããã¦ã¼ã¶ã¼ã°ã«ã¼ããã¼ã¹ã®ã¢ã¯ã»ã¹å¶å¾¡
User Poolsã®ã°ã«ã¼ãæ©è½ã使ç¨ãã¦ãã¢ããªã±ã¼ã·ã§ã³å ã§ç°ãªã権éã¬ãã«ãæã¤ã¦ã¼ã¶ã¼ã°ã«ã¼ã(ä¾ï¼ç®¡çè ã»ä¸è¬ã¦ã¼ã¶ã¼)ã使ããããããã«é©åãªã¢ã¯ã»ã¹æ¨©ãä»ä¸ãã¾ããã¯ãã¹ãã©ãããã©ã¼ã ã¢ããªã±ã¼ã·ã§ã³ã§ã®ã¦ã¼ã¶ã¼ä½é¨ã®ä¸è²«æ§
User Poolsã使ç¨ãã¦ãã¦ã§ãã»iOSã»Androidãªã©ç°ãªããã©ãããã©ã¼ã éã§ã¦ã¼ã¶ã¼ãããã¡ã¤ã«ã¨èªè¨¼ç¶æ ãåæããä¸è²«ããã¦ã¼ã¶ã¼ä½é¨ãæä¾ãã¾ããGraphQLãã¼ã¹ã®ã¢ããªã±ã¼ã·ã§ã³éçº
AWS AppSyncã使ç¨ããGraphQLãã¼ã¹ã®ã¢ããªã±ã¼ã·ã§ã³ã§ãUser Poolsã¨Identity Poolsãçµã¿åããã¦ãã¼ã¿ã¢ã¯ã»ã¹ãå¶å¾¡ãã¾ãã
ãããã®ã¦ã¼ã¹ã±ã¼ã¹ã¯ãAmazon Cognitoã使ã£ã¦ã¦ã¼ã¶ã¼èªè¨¼ã¨èªå¯ãå¹ççãã¤å®å ¨ã«è¡ããæ§ã ãªã·ããªãªã§ã¢ããªã±ã¼ã·ã§ã³ã®éçºãå éãããå ·ä½çãªä¾ã§ãã
Amazon Cognitoã®æ¦å¿µå³
ãããããAmazon Cognitoã®ä¸»ãªæ©è½ãç¹å¾´ã«ã¤ãã¦èª¬æãã¦ããã¾ããããã®åã«Amazon Cognitoã®å
¨ä½åãæ³åããããããããã«Amazon Cognitoã®æ¦å¿µå³ã次ã«ç¤ºãã¾ãã

ãã®æ¦å¿µå³ã¯ãAmazon Cognitoã®ä¸»è¦ãªæ©è½ã§ããUser Poolsã¨Identity Poolsã使ç¨ããå ¸åçãªèªè¨¼ããã¼ã示ãã¦ãã¾ãã
èªè¨¼ããã»ã¹ã¯æ¬¡ã®3ã¤ã®ä¸»è¦ãªã¹ãããã§æ§æããã¦ãã¾ãã
- ã¦ã¼ã¶ã¼ã¯ã¾ãAmazon Cognito User Poolsã§èªè¨¼ãè¡ãããã¼ã¯ã³ãåå¾ãã¾ãã
- 次ã«ããã®ãã¼ã¯ã³ãAmazon Cognito Identity Poolsã¨äº¤æãã¦ã䏿çãªAWSèªè¨¼æ å ±ãåå¾ãã¾ãã
- æå¾ã«ããããã®èªè¨¼æ å ±ã使ç¨ãã¦ãã¢ããªã±ã¼ã·ã§ã³ã¯AWSã®å種ãµã¼ãã¹ããªã½ã¼ã¹ã«ã¢ã¯ã»ã¹ã§ããããã«ãªãã¾ãã
ãã®æ¦å¿µå³ã®ããã«ãAmazon Cognito User Poolsã¨Amazon Cognito Identity Poolsã¯åãAmazon Cognitoã®ãµã¼ãã¹ã§ãããªãããç°ãªãå½¹å²ã¨ç¨éã¨æä¾ãã¾ãã
以éã§ã¯ä¸»ã«Amazon Cognito User Poolsã¨Amazon Cognito Identity Poolsã®ããããã®æ©è½ã®æ¦è¦ã«ã¤ãã¦ã説æãã¦ãã¾ãã
Amazon Cognito User Pools
Amazon Cognito User Poolsã®æ©è½æ¦è¦
Amazon Cognito User Poolsã¯ãã¦ã§ããã¢ãã¤ã«ã¢ããªã±ã¼ã·ã§ã³ã®ã¦ã¼ã¶ã¼èªè¨¼ã管çããããã®å
æ¬çãªãµã¼ãã¹ã§ãã
ç¬èªã®ã¦ã¼ã¶ã¼ãã£ã¬ã¯ããªã¨ãã¦æ©è½ããèªå·±ç»é²ãã¢ãããã¹ãã¬ã¼ã¿ã¼ä¸»å°ã®ã¦ã¼ã¶ã¼ä½æã»ç®¡çã»èªè¨¼ããµãã¼ããã¾ãã
OpenID Connect(OIDC)æ¨æºã«åºã¥ãã¦åä½ããå®å
¨ãªæ
å ±ã®ä¼éã«ä½¿ç¨ãããã³ã³ãã¯ãã§èªå·±å®çµåã®ç½²åä»ãJSONãªãã¸ã§ã¯ãã§ããJSON Web Token(JWT)ãçºè¡ãã¦ãã¢ããªã±ã¼ã·ã§ã³ãAPIã«ç´æ¥èªè¨¼ãæä¾ãã¾ãã
User Poolsã®ç¹çãã¹ãæ©è½ã®ä¸ã¤ã¯ããµã¼ããã¼ãã£ã®IDãããã¤ãã¼(IdP)ã¨ã®é«åº¦ãªé£æºã§ãã
SAML 2.0ã»OIDCã»OAuth 2.0ãããã³ã«ãä»ãã¦ã伿¥ã®ã¯ã¼ã¯ãã©ã¼ã¹èå¥åãã«ã¹ã¿ãã¼èå¥åãããã«ã¯Facebookã»Googleã»Amazonã»Appleãªã©ã®ä¸è¬çãªã½ã¼ã·ã£ã«IDãããã¤ãã¼ã¨ã®çµ±åããµãã¼ããã¾ãã
ãã®é£æºã«ããã¦ã屿§ãããã³ã°æ©è½ãéè¦ãªå½¹å²ãæããã¾ãã
ã¦ã¼ã¶ã¼ã¯ãå¤é¨IdPããã®ã¦ã¼ã¶ã¼å±æ§ãUser Poolå
ã®å±æ§ã«æè»ã«ãããã³ã°ã§ãããã¼ã¿ã®ä¸è²«æ§ã¨äºææ§ã確ä¿ã§ãã¾ãã
ããã«ãUser Poolsã¯ãã§ãã¬ã¼ã·ã§ã³ã¦ã¼ã¶ã¼ãæ¢åã®ã¦ã¼ã¶ã¼ãããã¡ã¤ã«ã«ãªã³ã¯ããæ©è½ãæä¾ãã¾ãã
ãã®æ©è½ã«ãã£ã¦ãã¦ã¼ã¶ã¼ã¯è¤æ°ã®èªè¨¼æ¹æ³(ä¾ï¼ãã¼ã«ã«ã¢ã«ã¦ã³ãã¨Facebookã¢ã«ã¦ã³ã)ãåä¸ã®ã¦ã¼ã¶ã¼ãããã¡ã¤ã«ã«é¢é£ä»ãããã¨ãã§ããã·ã¼ã ã¬ã¹ãªã¦ã¼ã¶ã¼ã¨ã¯ã¹ããªã¨ã³ã¹ãå®ç¾ãã¾ãã
ã»ãã¥ãªãã£é¢ã§ã¯ãå¤è¦ç´ èªè¨¼(MFA)ã»ã«ã¹ã¿ã èªè¨¼ããã¼ã»æªæã®ããã¢ã¯ãã£ããã£ããã®ä¿è·ãªã©ãé«åº¦ãªæ©è½ãæä¾ãã¾ãã
ã¦ã¼ã¶ã¼ã¨ã¯ã¹ããªã¨ã³ã¹ã®ã«ã¹ã¿ãã¤ãºãå¯è½ã§ãLambda颿°ã使ç¨ãã¦èªè¨¼ããã»ã¹ãã«ã¹ã¿ãã¤ãºãããããã¹ããããUIã®ãã¶ã¤ã³ãã«ã¹ã¿ãã¤ãºãããã§ãã¾ãã
ç£è¦ã¨åææ©è½ãå
å®ãã¦ãããAWS CloudTrailã»Amazon CloudWatchã»Amazon Pinpointã¨ã®çµ±åã«ãã£ã¦ãã¦ã¼ã¶ã¼ã¢ã¯ãã£ããã£ã®è©³ç´°ãªåæã¨ç£è¦ãå¯è½ã§ãã
ã¾ããAmazon Cognito Identity Poolsã¨ã®é£æºã§ãAWSãµã¼ãã¹ã¸ã®ã¢ã¯ã»ã¹æ¨©éã®ç®¡çã容æã«ãªãã¾ãã
ãããã®æ©è½ãç·åããã¨ãAmazon Cognito User Poolsã¯ãè¤éãªèªè¨¼ã·ããªãªã«å¯¾å¿ã§ããæè»æ§ã¨ãå¼·åãªã»ãã¥ãªãã£æ©è½ãå
¼ãåãããç¾ä»£ã®ã¢ããªã±ã¼ã·ã§ã³éçºã«ä¸å¯æ¬ ãªãã¼ã«ã¨ãªã£ã¦ãã¾ãã
屿§ãããã³ã°ã¨ã¦ã¼ã¶ã¼ãããã¡ã¤ã«ã®ãªã³ã¯æ©è½ã«ãã£ã¦ãç°ãªãIDãããã¤ãã¼éã§ã®ã¦ã¼ã¶ã¼æ
å ±ã®çµ±åã¨ç®¡çã容æã«ãªããã·ã¼ã ã¬ã¹ãªã¦ã¼ã¶ã¼ä½é¨ãæä¾ãããã¨ãã§ãã¾ãã
Amazon Cognito User Poolsã¸ã®ãµã¤ã³ã¤ã³æ¹æ³
Amazon Cognito User Poolsã¯ãã¦ã§ãããã³ã¢ãã¤ã«ã¢ããªã±ã¼ã·ã§ã³ã®èªè¨¼ã¨èªå¯ã®ããã®æè»ã§å¼·åãªã½ãªã¥ã¼ã·ã§ã³ãæä¾ãã¾ãã
ã¦ã¼ã¶ã¼ãèªåã®ã¢ããªã±ã¼ã·ã§ã³ã«ã¢ã¯ã»ã¹ããæ¹æ³ã¯è¤æ°ãããããããã®ãã¼ãºãæ¢åã®ã¤ã³ãã©ã¹ãã©ã¯ãã£ã«åããã¦é¸æã§ãã¾ãã
以ä¸ã§ã¯ãAmazon Cognito User Poolsã§å©ç¨å¯è½ãªä¸»è¦ãªãµã¤ã³ã¤ã³æ¹æ³ã«ã¤ãã¦èª¬æãã¾ãã
ã¦ã¼ã¶ã¼ãã¼ã«ãä»ããç´æ¥ãµã¤ã³ã¤ã³
Amazon Cognito User Poolsã§ã¯ãã¹ã¿ã³ãã¢ãã³ã®ã¦ã¼ã¶ã¼ãã£ã¬ã¯ããªããã³IDãããã¤ãã¼(IdP)ã¨ãã¦æ©è½ããå ´åã«ãç´æ¥ãµã¤ã³ã¤ã³ããµãã¼ããã¦ãã¾ãã
ã¦ã¼ã¶ã¼ã¯ãAmazon Cognitoããã¹ãããUI(Hosted UI)ã使ç¨ããããAmazon Cognito User Pools APIãä»ãã¦ã«ã¹ã¿ã UIãããµã¤ã³ã¤ã³ã§ãã¾ãã
Social IdPãä»ãããã§ãã¬ã¼ã·ã§ã³
Amazon Cognito User Poolsã§ã¯ãOAuth 2.0ã½ã¼ã·ã£ã«ãµã¤ã³ã¤ã³ããµãã¼ããã¦ãã¾ãã
ã¦ã¼ã¶ã¼ã¯ãGoogleã»Facebookã»Amazonã»Appleãªã©ã®ã½ã¼ã·ã£ã«ã¢ã¤ãã³ãã£ãã£ãããã¤ãã¼ãä»ãã¦ãµã¤ã³ã¤ã³ã§ãã¾ãã
Social IdPãä»ãããã§ãã¬ã¼ã·ã§ã³ã«ãã£ã¦ãã³ã³ã·ã¥ã¼ãã¼ã¦ã¼ã¶ã¼ã®ãµã¤ã³ã¤ã³ãå¯è½ã«ãªããåæã«ãã®ã¦ã¼ã¶ã¼ã®ãããã¡ã¤ã«æ
å ±ãAmazon Cognito User Poolsã«ã¤ã³ãã¼ããããã¨ãã§ãã¾ãã
ã¤ã³ãã¼ããããæ
å ±ã«ã¯ãã¦ã¼ã¶ã¼ã®åºæ¬çãªãããã¡ã¤ã«å±æ§((ä¾: ååã»ã¡ã¼ã«ã¢ãã¬ã¹ã»ãããã£ã¼ã«ç»åã®URL)ãå«ã¾ãã¾ãã
ãããã®å±æ§ã¯ãè¨å®ãããããã³ã°ã«ã¼ã«ã«åºã¥ãã¦User Poolså
ã®ã¦ã¼ã¶ã¼ãããã¡ã¤ã«ã«ä¿åããã¾ãã
SAML IdPãä»ãããã§ãã¬ã¼ã·ã§ã³
Amazon Cognito User Poolsã§ã¯ãSAML(Security Assertion Markup Language)ãã§ãã¬ã¼ã·ã§ã³ã使ç¨ã§ãã¾ãã
Amazon Cognito User Poolsã¯ãä»»æã®SAML IdPããã®è¦æ±ãåãå
¥ããããã«è¨å®ãããã¨ãã§ãã¾ãã
SAML IdPãä»ãããã§ãã¬ã¼ã·ã§ã³ã«ãã£ã¦ãçµç¹ã®ã¦ã¼ã¶ã¼ãã¼ã¿ã使ç¨ãããµã¤ã³ã¤ã³ã¨ã¤ã³ãã¼ãã«ãé©ãã¦ãããæ¢åã®çµç¹ã®IDã·ã¹ãã ã¨ã®çµ±åã容æã«ãªãã¾ãã
SAMLèªè¨¼ãçµç±ãã¦ãã¦ã¼ã¶ã¼ã®å±æ§ããã¼ã«ãªã©ã®æ
å ±ãAmazon Cognito User Poolsã«å®å
¨ã«è»¢éããã¢ããªã±ã¼ã·ã§ã³ã§ã®èªè¨¼ã«æ´»ç¨ãããã¨ãã§ãã¾ãã
OIDC IdPãä»ãããã§ãã¬ã¼ã·ã§ã³
Amazon Cognito User Poolsã§ã¯ãOpenID Connect(OIDC)ãããã³ã«ã使ç¨ããIdPãéãããã§ãã¬ã¼ã·ã§ã³ãå¯è½ã§ãã
Amazon Cognitoã¯ãOIDCã«æºæ ããä»»æã®IdPããã®è¦æ±ãå¦çã§ãã¾ãã
OIDC IdPãä»ãããã§ãã¬ã¼ã·ã§ã³ã«ãã£ã¦ããã¾ãã¾ãªæ¨æºæºæ ã®IDãããã¤ãã¼ã¨ã®é£æºãå¯è½ã«ãªãã¾ãã
ãããã®æ¹æ³ãçµã¿åããããã¨ã§ãã¦ã¼ã¶ã¼ã«æè»ãªèªè¨¼ãªãã·ã§ã³ãæä¾ããæ¢åã®IDã¤ã³ãã©ã¹ãã©ã¯ãã£ã¨ã·ã¼ã ã¬ã¹ã«çµ±åãããã¨ãã§ãã¾ãã
Hosted UI
Amazon Cognito User Poolsã®Hosted UIã¯ãããã«å©ç¨å¯è½ãªã¦ã¼ã¶ã¼èªè¨¼ã¦ã§ãã¤ã³ã¿ã¼ãã§ã¼ã¹ã§ãã
ããã¯ãOAuth 2.0æºæ ã®èªå¯ãµã¼ãã¼ã¨ãã¦æ©è½ãã以ä¸ã®ç¹å¾´ãæã£ã¦ãã¾ãã
- åºæ¬çãªãµã¤ã³ã¢ããããµã¤ã³ã¤ã³ãå¤è¦ç´ èªè¨¼(MFA)ããã¹ã¯ã¼ããªã»ãããªã©ã®æ©è½ãæä¾ãã¾ãã
- ãµã¼ããã¼ãã£ã®ã¢ã¤ãã³ãã£ãã£ãããã¤ãã¼(IdP)ã¨ã®èªè¨¼ãçµ±åããããã¨ãã¦ãæ©è½ãã¾ãã
- ã«ã¹ã¿ãã¤ãºå¯è½ã§ããã´ãCSSã使ç¨ãã¦ãã©ã³ãã«åãããå¤è¦³ã使ã§ãã¾ãã
- èªè¨¼ãªã¯ã¨ã¹ãã®ã«ã¼ãã£ã³ã°ãJSON Webãã¼ã¯ã³(JWT)ã®çºè¡ã¨ç®¡çãã¦ã¼ã¶ã¼å±æ§æ å ±ã®æä¾ãè¡ãã¾ãã
Hosted UIã®ä¸»ãªå©ç¹ã¯ãã¢ããªã±ã¼ã·ã§ã³ã«ç°¡åã«çµ±åã§ããç¹ã§ãã¦ã¼ã¶ã¼ãã¼ã«ã®ãã¡ã¤ã³ã»ã¢ããªã¯ã©ã¤ã¢ã³ãIDã»ãªãã¤ã¬ã¯ãURIãªã©ã®ãã©ã¡ã¼ã¿ã使ç¨ãã¦ãèªè¨¼ã¨ã³ããã¤ã³ãã«ã¢ã¯ã»ã¹ã§ãã¾ãã
ä¾ãã°ã以ä¸ã®ãããªURLã§ Hosted UI ã«ã¢ã¯ã»ã¹ã§ãã¾ãã
https://<your user pool domain>/authorize?client_id=<your app client ID>&response_type=<code/token>&scope=<scopes to request>&redirect_uri=<your callback URL>
Hosted UIã®æ©è½ã«ãã£ã¦ãéçºè
ã¯èªè¨¼ããã»ã¹ãç°¡åã«å®è£
ã§ããã¦ã¼ã¶ã¼ã«ã¨ã£ã¦ã使ããããèªè¨¼ã¨ã¯ã¹ããªã¨ã³ã¹ãæä¾ã§ãã¾ãã
Amazon Cognito User Poolsã®Hosted UIã使ç¨ãããã¨ã§ãéçºè
ã¯è¤éãªèªè¨¼ã·ã¹ãã ãèªåã§æ§ç¯ããå¿
è¦ããªããå®å
¨ã§æ¨æºåãããèªè¨¼ããã»ã¹ãç°¡åã«å®è£
ã§ãã¾ãã
Lambdaããªã¬ã¼ã®ç¨®é¡
Amazon Cognito User Poolsã§ã¯ãLambdaããªã¬ã¼ã使ç¨ãã¦ãã¦ã¼ã¶ã¼èªè¨¼ããã»ã¹ã®æ§ã
ãªæ®µéã§ã«ã¹ã¿ã ãã¸ãã¯ãå®è¡ããèªè¨¼ããã¼ãã«ã¹ã¿ãã¤ãºã§ãã¾ãã
Lambdaããªã¬ã¼ã§å®è¡ã§ããå¦çã«ã¯ä¸»ã«æ¬¡ã®ãããªãã®ãæãããã¾ãã
ãµã¤ã³ã¢ããé¢é£
Pre sign-up: ãµã¤ã³ã¢ããåã«ã«ã¹ã¿ã ããªãã¼ã·ã§ã³ãä»ã®åå¦çãè¡ãããªã¬ã¼ã§ããã¦ã¼ã¶ã¼ç»é²ã®æ¿èªã¾ãã¯æå¦ãå¯è½ã§ãã
Post confirmation: ãµã¤ã³ã¢ããã®ç¢ºèª(ã¡ã¼ã«ãSMSã§ã®èªè¨¼å¾)ãå®äºããå¾ã«è¡ãããå¦çã§ãã«ã¹ã¿ã ã¡ãã»ã¼ã¸ã®éä¿¡ããã°ã®è¨é²ãªã©ãå¯è½ã§ããèªè¨¼é¢é£
Pre authentication: èªè¨¼åã«ã«ã¹ã¿ã ããªãã¼ã·ã§ã³ãè¡ãããªã¬ã¼ã§ããä¾ãã°ãç¹å®ã®æ¡ä»¶ãæºããã¦ã¼ã¶ã¼ã®ãã°ã¤ã³ãæå¦ãããã¨ãã§ãã¾ãã
Post authentication: ã¦ã¼ã¶ã¼ã®èªè¨¼ãæåããå¾ã«ãã°è¨é²ãåæãã¼ã¿ã®åéãªã©ã®å¦çãè¡ãããªã¬ã¼ã§ããã«ã¹ã¿ã èªè¨¼ãã£ã¬ã³ã¸é¢é£
Define auth challenge: èªè¨¼ããã»ã¹ä¸ã®æ¬¡ã®ãã£ã¬ã³ã¸(èªè¨¼ã¹ããã)ãæ±ºå®ãã¾ãã
Create auth challenge: æ°ããèªè¨¼ãã£ã¬ã³ã¸ã使ãã¾ãã
Verify auth challenge response: ã¦ã¼ã¶ã¼ããã®ã¬ã¹ãã³ã¹ãæ¤è¨¼ããèªè¨¼ã®æåã¾ãã¯å¤±æã決å®ãã¾ãããã¼ã¯ã³çæé¢é£
Pre token generation: IDãã¼ã¯ã³ãã¢ã¯ã»ã¹ãã¼ã¯ã³ãçæãããåã«ããã¼ã¯ã³ã®ã¯ã¬ã¼ã ã夿´ããããæ°ããã¯ã¬ã¼ã ã追å ãããããããªã¬ã¼ã§ããã¦ã¼ã¶ã¼ç§»è¡é¢é£
Migrate user: æ¢åã®ã¦ã¼ã¶ã¼ãã£ã¬ã¯ããªããAmazon Cognito User Poolã¸ã®ã¦ã¼ã¶ã¼æ å ±ã®ç§»è¡ãæ¯æ´ããããªã¬ã¼ã§ããã¦ã¼ã¶ã¼ãåãã¦ãµã¤ã³ã¤ã³ããéã«å¤ãã·ã¹ãã ããæ å ±ãç§»è¡ãã¾ããã¡ãã»ã¼ã¸ã«ã¹ã¿ãã¤ãºé¢é£
Custom message: ã¡ã¼ã«ãSMSã§éä¿¡ãããã¡ãã»ã¼ã¸ã®å 容ãã«ã¹ã¿ãã¤ãºããããªã¬ã¼ã§ããè¨èªã®ãã¼ã«ã©ã¤ãºãå¯è½ã§ããã«ã¹ã¿ã éä¿¡è é¢é£
Custom email sender: 第ä¸è ã®ãããã¤ãã¼ã使ç¨ãã¦ãEã¡ã¼ã«ãã«ã¹ã¿ãã¤ãºãã¦éä¿¡ããããªã¬ã¼ã§ãã
Custom SMS sender: 第ä¸è ã®ãããã¤ãã¼ã使ç¨ãã¦ãSMSã¡ãã»ã¼ã¸ãã«ã¹ã¿ãã¤ãºãã¦éä¿¡ããããªã¬ã¼ã§ãã
Amazon Pinpointåæ
Amazon Pinpointã¯ããã«ããã£ãã«ãã¼ã±ãã£ã³ã°ãã©ãããã©ã¼ã ã§ãã¦ã¼ã¶ã¼ã¨ã³ã²ã¼ã¸ã¡ã³ãã®åä¸ã¨ã¿ã¼ã²ãããçµã£ããã£ã³ãã¼ã³ã®å®æ½ãæ¯æ´ãã¾ãã
Amazon Pinpointãã£ã³ãã¼ã³ã¯ãã¦ã¼ã¶ã¼ã»ã°ã¡ã³ãã«å¯¾ãã¦ç¹å®ã®ã¡ãã»ã¼ã¸ãããã¢ã¼ã·ã§ã³ãé
ä¿¡ããæ©è½ãæä¾ãã¾ãã
Amazon Cognito User Poolsã¯Amazon Pinpointã¨çµ±åããã¦ãããã¦ã¼ã¶ã¼ãã¼ã«ã®åææ©è½ãæä¾ããã¨ã¨ãã«Amazon Pinpointãã£ã³ãã¼ã³ã®ã¦ã¼ã¶ã¼ãã¼ã¿ãå¼·åãã¾ãã
ãã®çµ±åã«ãã£ã¦ã次ã®ãããªãã¨ãå¯è½ã«ãªãã¾ãã
- ã¦ã¼ã¶ã¼ãã¼ã«ã®ãµã¤ã³ã¢ããããµã¤ã³ã¤ã³ã»èªè¨¼å¤±æã»æ¥æ¬¡ã¢ã¯ãã£ãã¦ã¼ã¶ã¼(DAU)ã»ææ¬¡ã¢ã¯ãã£ãã¦ã¼ã¶ã¼(MAU)ãªã©ã®è¿½è·¡
- ããã¤ã¹ãã©ãããã©ã¼ã ã»ããã¤ã¹ãã±ã¼ã«ã»ã¢ããªãã¼ã¸ã§ã³ãªã©ã®å±æ§ã«åºã¥ããã¼ã¿åæ
- ã«ã¹ã¿ã 屿§ã®è¨å®ã¨ãããç¨ããã¦ã¼ã¶ã¼ã»ã°ã¡ã³ãã¼ã·ã§ã³
- ã¿ã¼ã²ãããçµã£ãããã·ã¥éç¥ã®éä¿¡
Amazon Cognitoã³ã³ã½ã¼ã«ã§åæãæå¹ã«ããã¨ããµã¼ãã¹ã«ãªã³ã¯ããããã¼ã«ã使ãããAmazon CognitoãAmazon Pinpointã¸ã®APIãªã¯ã¨ã¹ããè¡ãéã«ä½¿ç¨ããã¾ãã
Amazon Cognitoã¨Amazon Pinpointã®å°åå¯ç¨æ§ã«ã¯å¶éããããä¸é¨ã®å°åã§ã¯Amazon Pinpointããã¸ã§ã¯ããåãå°åã¾ãã¯us-east-1(N. Virginia)ã«ä½æããå¿
è¦ãããã¾ãã
åæè¨å®ãæå®ããã«ã¯ãAmazon Cognitoã³ã³ã½ã¼ã«ãAWS CLIãã¾ãã¯AWS APIã使ç¨ã§ãã¾ãã
è¨å®å¾ãã¢ããªã±ã¼ã·ã§ã³ã§AnalyticsMetadataãã©ã¡ã¼ã¿ãå«ãããã¨ã§ãAmazon Pinpointã«ã¡ã¿ãã¼ã¿ã渡ããã¨ãã§ãã¾ãã
ãã®ããã«Amazon Cognito User Poolsã¨Amazon Pinpointã®çµ±åã«ãã£ã¦ãã¢ãã¤ã«ã¢ããªã®ã¦ã¼ã¶ã¼ã¨ã³ã²ã¼ã¸ã¡ã³ããåä¸ããããã广çãªã¿ã¼ã²ãã£ã³ã°ã¨ã¢ããªãã£ã¯ã¹ãå¯è½ã«ãªãã¾ãã
ã¦ã¼ã¶ã¼ã®ç®¡ç
Amazon Cognito User Poolsã使ç¨ããã¨ãã¦ã¼ã¶ã¼ãã¼ã«ã使ããå¾ã«ã¦ã¼ã¶ã¼ã¢ã«ã¦ã³ãã使ã確èªãããã³ç®¡çãããã¨ãã§ãã¾ãã
ã¦ã¼ã¶ã¼ãã¼ã«ã®ã°ã«ã¼ããå©ç¨ãããã¨ã§ãIAMãã¼ã«ãã°ã«ã¼ãã«ãããã³ã°ããã¦ã¼ã¶ã¼ã¨ãã®ãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ã管çã§ãã¾ãã
ã¾ããMigrate user Lambdaããªã¬ã¼ãç¨ãã¦ã¦ã¼ã¶ã¼ãã¦ã¼ã¶ã¼ãã¼ã«ã«ã¤ã³ãã¼ããããã¨ãå¯è½ã§ãã
ãã®æ¹æ³ãç¨ããã¨ãã¦ã¼ã¶ã¼ãåãã¦ã¦ã¼ã¶ã¼ãã¼ã«ã«ãµã¤ã³ã¤ã³ããéã«ãæ¢åã®ã¦ã¼ã¶ã¼ãã£ã¬ã¯ããªããã¦ã¼ã¶ã¼ãã¼ã«ã¸ã®ã¦ã¼ã¶ã¼ã®ã·ã¼ã ã¬ã¹ãªç§»è¡ãå®ç¾ãã¾ãã
ã¦ã¼ã¶ã¼ãã¼ã«ã使ããå¾ã以ä¸ã®ãããªæ©è½ãæ´»ç¨ãã¦ã¦ã¼ã¶ã¼ãå¹ççã«ç®¡çã§ãã¾ãã
- ã°ã«ã¼ã管ç
ã¦ã¼ã¶ã¼ãã¼ã«å ã«ã°ã«ã¼ãã使ããIAMãã¼ã«ããããã³ã°ãããã¨ã§ãã¦ã¼ã¶ã¼ã®ã¢ã¯ã»ã¹æ¨©éã管çã§ãã¾ãã - ã¦ã¼ã¶ã¼ç§»è¡
Migrate user Lambdaããªã¬ã¼ã使ç¨ãã¦ãæ¢åã®ã¦ã¼ã¶ã¼ãã£ã¬ã¯ããªããã¦ã¼ã¶ã¼ãã¼ã«ã¸ã®ã·ã¼ã ã¬ã¹ãªç§»è¡ãå¯è½ã§ããã¦ã¼ã¶ã¼ãåãã¦ãµã¤ã³ã¤ã³ããéã«èªåçã«ç§»è¡ããã¾ãã - ããªã·ã¼è¨å®
ã¦ã¼ã¶ã¼ä½æã«é¢ããããªã·ã¼ãè¨å®ããã»ãã¥ãªãã£ãå¼·åã§ãã¾ãã - ã¢ã«ã¦ã³ã管ç
管çè ã¨ãã¦ã¦ã¼ã¶ã¼ã¢ã«ã¦ã³ãã使ããããæ¢åã®ã¢ã«ã¦ã³ããæ¤ç´¢ã»ç®¡çããããããã¨ãã§ãã¾ãã - ã¢ã«ã¦ã³ãå復
ã¦ã¼ã¶ã¼ããã¹ã¯ã¼ããå¿ããå ´åãªã©ã«åãã¦ãã¢ã«ã¦ã³ãå復æ©è½ãæä¾ãã¦ãã¾ãã - 屿§ç®¡ç
ã¦ã¼ã¶ã¼ãã¼ã«ã®å±æ§ãæè»ã«è¨å®ããå¿ è¦ãªæ å ±ã管çã§ãã¾ãã - ãã¹ã¯ã¼ãè¦ä»¶
ã¦ã¼ã¶ã¼ãã¼ã«ã®ãã¹ã¯ã¼ãè¦ä»¶ã追å ããã»ãã¥ãªãã£ãå¼·åãããã¨ãã§ãã¾ãã
ãããã®æ©è½ãæ´»ç¨ãããã¨ã§ãAmazon Cognito User Poolsã使ç¨ããã¢ããªã±ã¼ã·ã§ã³ã«ããã¦ã广çãªã¦ã¼ã¶ã¼ç®¡çãå®ç¾ã§ãã¾ãã
èªè¨¼æåå¾ã®AWSãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹
åè¿°ããããã«ãAmazon Cognito User Poolsã使ç¨ããã¨ãã¦ã¼ã¶ã¼ã¯ç´æ¥ã¦ã¼ã¶ã¼ãã¼ã«ã使ç¨ãã¦ãã¾ãã¯ç¬¬ä¸è
ã®ã¢ã¤ãã³ãã£ãã£ãããã¤ãã¼(IdP)ãçµç±ãã¦èªè¨¼ã§ãã¾ãã
èªè¨¼ãæåããã¨ãã¢ããªã±ã¼ã·ã§ã³ã¯Amazon Cognitoããã¦ã¼ã¶ã¼ãã¼ã«ãã¼ã¯ã³ãåãåãã¾ãã
ãããã®ãã¼ã¯ã³ã使ç¨ãã¦ã以ä¸ã®ãããªãã¾ãã¾ãªæä½ãå¯è½ã«ãªãã¾ã
- AWSãµã¼ãã¹(DynamoDBãS3ãªã©)ã®ãªã½ã¼ã¹ã«ã¢ã¯ã»ã¹ããããã®AWSèªè¨¼æ å ±ã®åå¾
- 䏿çã§åãæ¶ãå¯è½ãªèªè¨¼ã®è¨¼æã®æä¾
- ã¢ããªã±ã¼ã·ã§ã³å ã®ã¦ã¼ã¶ã¼ãããã¡ã¤ã«ã¸ã®èº«å ãã¼ã¿ã®æå ¥
- ã¦ã¼ã¶ã¼ãã¼ã«ãã£ã¬ã¯ããªå ã®ãµã¤ã³ã¤ã³ããã¦ã¼ã¶ã¼ã®ãããã¡ã¤ã«å¤æ´ã®æ¿èª
- ã¢ã¯ã»ã¹ãã¼ã¯ã³ã使ç¨ããã¦ã¼ã¶ã¼æ å ±ã¸ã®ãªã¯ã¨ã¹ãã®æ¿èª
- ã¢ã¯ã»ã¹ãã¼ã¯ã³ã使ç¨ããå¤é¨APIã¸ã®ãªã¯ã¨ã¹ãã®æ¿èª
- Amazon Verified Permissionsã使ç¨ããã¯ã©ã¤ã¢ã³ãã¾ãã¯ãµã¼ãã¼ä¸ã®ã¢ããªã±ã¼ã·ã§ã³è³ç£ã¸ã®ã¢ã¯ã»ã¹ã®æ¿èª
ãããã®æ©è½ã«ãã£ã¦ãã»ãã¥ã¢ãã¤æè»ãªã¦ã¼ã¶ã¼èªè¨¼ã¨ãªã½ã¼ã¹ã¢ã¯ã»ã¹ç®¡çãå¯è½ã«ãªãã¾ãã
使ç¨å¯è½ãªã»ãã¥ãªãã£æ©è½
Amazon Cognito User Poolsã§ã¯ãã¦ã¼ã¶ã¼IDãä¿è·ããããã«å¤æ§ãªã»ãã¥ãªãã£æ©è½ãæä¾ãã¦ãã¾ãã
Amazon Cognito User Poolsã§æä¾ããã主ãªã»ãã¥ãªãã£æ©è½ã«ã¯ä»¥ä¸ã®ãããªãã®ãæãããã¾ãã
å¤è¦ç´ èªè¨¼(MFA)
ã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ã以å¤ã®ç¬¬2ã®èªè¨¼è¦ç´ ã追å ã§ãã¾ãã
SMSããã¹ãã¡ãã»ã¼ã¸ã¾ãã¯æéãã¼ã¹ã®ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ã(TOTP)ãå©ç¨å¯è½ã§ããé©å¿åèªè¨¼(Adaptive Authentication)
é©å¿åèªè¨¼(Adaptive Authentication)ã¯ãã¦ã¼ã¶ã¼ã®è¡åãã¿ã¼ã³ããªã¹ã¯è¦å ãåæããç¶æ³ã«å¿ãã¦é©åãªèªè¨¼ã¬ãã«ãåçã«èª¿æ´ããã»ãã¥ãªãã£æ©è½ã§ãã
ãªã¹ã¯ãã¼ã¹ã¢ãã«ã使ç¨ãã¦è¿½å ã®èªè¨¼è¦ç´ ãå¿ è¦ãã©ãããäºæ¸¬ãã¾ãã
è¿½å æéãå¿ è¦ãªãAmazon Cognito Advanced Securityãã®ä¸é¨ã¨ãã¦æä¾ããã¾ãã侵害ãããèªè¨¼æ å ±ã«å¯¾ããä¿è·
æ¢ç¥ã®æ¼æ´©ãã¹ã¯ã¼ããã¼ã¿ãã¼ã¹ã¨ç §åããã¦ã¼ã¶ã¼ãèå¼±ãªãã¹ã¯ã¼ãã使ç¨ãããã¨ãé²ãã¾ãã
è¿½å æéãå¿ è¦ãªãAmazon Cognito Advanced Securityãã®ä¸é¨ã¨ãã¦æä¾ããã¾ããAWS WAF Web ACLã¨ã®é£æº
ã¦ã¼ã¶ã¼ãã¼ã«ã«AWS WAF Web ACLãé¢é£ä»ãã§ãã¾ããã¦ã¼ã¶ã¼ãã¼ã«ã®å¤§æåå°æåã®åºå¥
ã¦ã¼ã¶ã¼åããã®ä»ã®å±æ§ã®å¤§æåå°æåã®æ±ãã管çã§ãã¾ããã¦ã¼ã¶ã¼ãã¼ã«åé¤ä¿è·
æå³ããªãã¦ã¼ã¶ã¼ãã¼ã«ã®åé¤ã鲿¢ãã¾ããã¦ã¼ã¶ã¼åå¨ã¨ã©ã¼ã¬ã¹ãã³ã¹ã®ç®¡ç
ã¦ã¼ã¶ã¼ã®åå¨ã«é¢ããã¨ã©ã¼ã¬ã¹ãã³ã¹ãã«ã¹ã¿ãã¤ãºã§ãã¾ãã
ãããã®æ©è½ãé©åã«çµã¿åããããã¨ã§ãã¦ã¼ã¶ã¼ãã¼ã«ã®ã»ãã¥ãªãã£ãå¼·åããããã»ãã¥ã¢ãªèªè¨¼ã·ã¹ãã ãæ§ç¯ãããã¨ãã§ãã¾ãã
Amazon Cognito Identity Pools
Amazon Cognito Identity Poolsã®æ©è½æ¦è¦
Amazon Cognito Identity Poolsã¯ãèªè¨¼ãããã¦ã¼ã¶ã¼ãæªèªè¨¼ã¦ã¼ã¶ã¼ã«AWSãªã½ã¼ã¹ã¸ã®ä¸æçãªã¢ã¯ã»ã¹æ¨©ãä»ä¸ããããã®ãµã¼ãã¹ã§ãã
Identity Poolsã¯ãèªè¨¼æ¸ã¿ã¦ã¼ã¶ã¼ã ãã§ãªããå¿åã¦ã¼ã¶ã¼ã«å¯¾ãã¦ãAWSèªè¨¼æ
å ±ãçºè¡ããã¢ããªã±ã¼ã·ã§ã³ãé©åãªã¬ãã«ã®ãªã½ã¼ã¹ã¢ã¯ã»ã¹ãæä¾ã§ããããã«ãã¾ãã
Identity Poolsã®ç¹çãã¹ãæ©è½ã®ä¸ã¤ã¯ãèªè¨¼ããã¦ããªãã¦ã¼ã¶ã¼ãèªè¨¼æ¸ã¿ã¦ã¼ã¶ã¼ã«åæ»ã«åãæ¿ããæ©è½ã§ãã¦ã¼ã¶ã¼ã¯æåã¯å¶éä»ãã®ã²ã¹ãã¢ã¯ã»ã¹ã§å§ãããã®å¾èªè¨¼ããã»ã¹ãçµã¦ããåºç¯ãªã¢ã¯ã»ã¹æ¨©ãå¾ããã¨ãã§ãã¾ãã
ãã®ãããªæè»æ§ã«ãã£ã¦ãã¢ããªã±ã¼ã·ã§ã³ã¯æ°è¦ã¦ã¼ã¶ã¼ã®ç²å¾ã¨ã¨ã³ã²ã¼ã¸ã¡ã³ãã®åä¸ãåæã«å®ç¾ã§ãã¾ãã
ããã«ãIdentity Poolsã¯å¤æ§ãªèªè¨¼ãããã¤ãã¼ã¨é£æºãã¾ãã
ã¦ã¼ã¶ã¼ãã¼ã«ã»SAML 2.0ãµã¼ãã¹ã»OIDCãããã¤ãã¼ãã½ã¼ã·ã£ã«IDãããã¤ãã¼(Amazonã»Facebookã»GoogleãAppleã»Twitterãªã©)ããµãã¼ãããã«ã¹ã¿ã èªè¨¼ã¹ãã¼ã ã許å¯ãããããéçºè
ã¯èªç¤¾ã®ãã¼ãºã«æé©ãªèªè¨¼æ¹æ³ã鏿ã§ãã¾ãã
Identity Poolsã®éè¦ãªç¹å¾´ã¯ããã¼ã«ãã¼ã¹ã¨å±æ§ãã¼ã¹ã®ã¢ã¯ã»ã¹å¶å¾¡ãçµã¿åããã¦ä½¿ç¨ã§ãããã¨ã§ãã
ãã¼ã«ãã¼ã¹ã®ã¢ã¯ã»ã¹å¶å¾¡ã§ã¯ãã¦ã¼ã¶ã¼ã®è¦æ±ã屿§ã«åºã¥ãã¦é©åãªIAMãã¼ã«ã鏿ããåãã¼ã«ã«ç´°ãã調æ´ãããIAMããªã·ã¼ãé©ç¨ãã¾ãã屿§ãã¼ã¹ã®ã¢ã¯ã»ã¹å¶å¾¡ã§ã¯ãã¦ã¼ã¶ã¼ã®è¦æ±ãã屿§ãæ½åºãããããã䏿çãªã»ãã·ã§ã³ã®ããªã³ã·ãã«ã¿ã°ã«ãããã³ã°ãã¦ããªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ãããç²¾å¯ã«å¶å¾¡ãã¾ãã
Amazon Cognitoèªè¨¼æ
å ±ãããã¤ãã¼ãè¨å®ããAWSèªè¨¼æ
å ±ãåå¾ããã¨ãéçºè
ã¯ãããã®èªè¨¼æ
å ±ã使ç¨ãã¦AWSãµã¼ãã¹ã¯ã©ã¤ã¢ã³ãã使ã§ããã¢ããªã±ã¼ã·ã§ã³ã¯Amazon S3ã»Amazon DynamoDBã»Amazon Pinpointã»Amazon CloudWatchãªã©ã®æ§ã
ãªAWSãµã¼ãã¹ã¨å®å
¨ã«ããåãã§ããããã«ãªãã¾ãã
ãã®æ©è½ã«ãã£ã¦ãéçºè
ã¯AWSã®ãªãããªãµã¼ãã¹ã¨ã³ã·ã¹ãã ãæå¤§éã«æ´»ç¨ããã¹ã±ã¼ã©ãã«ã§å
ç¢ãªã¢ããªã±ã¼ã·ã§ã³ãæ§ç¯ã§ãã¾ãã
ç·ãã¦ãAmazon Cognito Identity Poolsã¯ãã¦ã¼ã¶ã¼èªè¨¼ããAWSãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ç®¡çã¾ã§ãå
æ¬çãã¤æè»ãªèªè¨¼ã»èªå¯ã½ãªã¥ã¼ã·ã§ã³ãæä¾ããéçºè
ã¯ã»ãã¥ãªãã£ãæãªããã¨ãªããã·ã¼ã ã¬ã¹ãªã¦ã¼ã¶ã¼ã¨ã¯ã¹ããªã¨ã³ã¹ãå®ç¾ã§ãã¾ãã
ãã¼ã«ãã¼ã¹ã®ã¢ã¯ã»ã¹å¶å¾¡(Role-Based Access Control, RBAC)
Amazon Cognito Identity Poolsã¯ãèªè¨¼ãããã¦ã¼ã¶ã¼ã«å¯¾ãã¦ãAWSãªã½ã¼ã¹ã«ã¢ã¯ã»ã¹ããããã®ä¸æçã§éå®çãªæ¨©éãæã¤èªè¨¼æ
å ±ãå²ãå½ã¦ã¾ãã
åã¦ã¼ã¶ã¼ã®æ¨©éã¯ã使ããIAMãã¼ã«ã«ãã£ã¦å¶å¾¡ããã¾ãã
ã¦ã¼ã¶ã¼ã®IDãã¼ã¯ã³å
ã®ã¯ã¬ã¼ã ã«åºã¥ãã¦ãåã¦ã¼ã¶ã¼ã«é©ç¨ãããã¼ã«ã鏿ããã«ã¼ã«ãå®ç¾©ã§ãã¾ãã
èªè¨¼ãããã¦ã¼ã¶ã¼ã«å¯¾ããããã©ã«ãã®ãã¼ã«ãå®ç¾©ãããã¨ãå¯è½ã§ããã¾ããèªè¨¼ããã¦ããªãã²ã¹ãã¦ã¼ã¶ã¼ã«å¯¾ãã¦ã¯ãéå®çãªæ¨©éãæã¤å¥ã®IAMãã¼ã«ãå®ç¾©ãããã¨ãã§ãã¾ãã
ãã¼ã«ãããã³ã°ã®ããã®ãã¼ã«ä½ææã«ã¯ããã®ãã¼ã«ãIdentity Poolå
ã®èªè¨¼ãããã¦ã¼ã¶ã¼ã«å¯¾ãã¦ã®ã¿Amazon Cognitoã«ãã£ã¦å¼ãåããããããã«ãé©åãªä¿¡é ¼ããªã·ã¼ãåãã¼ã«ã«è¿½å ãããã¨ãéè¦ã§ãã
ã¦ã¼ã¶ã¼ã«ãã¼ã«ãå²ãå½ã¦ãæ¹æ³ã«ã¯ã主ã«ä»¥ä¸ã®2ã¤ãããã¾ãã
- ãã¼ã¯ã³ã使ç¨ãããã¼ã«ã®å²ãå½ã¦
ã¦ã¼ã¶ã¼ãã¼ã«ãçµç±ãã¦ãã°ã¤ã³ããã¦ã¼ã¶ã¼ã®å ´åãIDãã¼ã¯ã³å ã®ç¹å®ã®ã¯ã¬ã¼ã (cognito:preferred_role
,cognito:roles
)ã使ç¨ãã¦ãã¼ã«ãå²ãå½ã¦ããã¨ãã§ãã¾ãã - ã«ã¼ã«ãã¼ã¹ã®ãããã³ã°ã«ãããã¼ã«ã®å²ãå½ã¦
IDãããã¤ãã¼ãã¼ã¯ã³ã®ã¯ã¬ã¼ã ãIAMãã¼ã«ã«ãããã³ã°ããã«ã¼ã«ãè¨å®ã§ãã¾ããåã«ã¼ã«ã§ã¯ããã¼ã¯ã³ã¯ã¬ã¼ã ããããã¿ã¤ããå¤ãããã³IAMãã¼ã«ãæå®ãã¾ãã
ã«ã¼ã«ãã¼ã¹ã®ãããã³ã°ã§ã¯ãæå¤§25åã®ã«ã¼ã«ã使ã§ãããããã¯é çªã«è©ä¾¡ããã¾ããæåã«ãããããã«ã¼ã«ã®IAMãã¼ã«ã使ç¨ããã¾ãã
ã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ã¨ãã¦ãã¨ã³ãã¦ã¼ã¶ã¼ãç´æ¥è¨å®ã§ããªãã¯ã¬ã¼ã ã®ã¿ããæ¨©éã®é«ããã¼ã«ã«ãããã³ã°ãããã¨ãéè¦ã§ãã
ã¾ããé©åãªãã¼ã«ã決å®ã§ããªãå ´åã®ããã©ã«ãã®åä½ãæå®ãããã¨ãã§ãã¾ãã
屿§ãã¼ã¹ã®ã¢ã¯ã»ã¹å¶å¾¡(Attribute-Based Access Control, ABAC)
Amazon Cognito Identity Poolsã«ããã屿§ãã¼ã¹ã®ã¢ã¯ã»ã¹å¶å¾¡(ABAC)ã¯ãã¦ã¼ã¶ã¼å±æ§ã«åºã¥ãã¦AWSãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ãå¶å¾¡ããæ©è½ã§ãã
ãã®æ©è½ã使ç¨ãããã¨ã§ãã½ã¼ã·ã£ã«ã伿¥ã®èªè¨¼ãããã¤ãã¼ããåå¾ããã¦ã¼ã¶ã¼å±æ§ããIAMããªã·ã¼ã§åç
§å¯è½ãªã¿ã°ã«ãããã³ã°ã§ãã¾ãã
ABACã®ä¸»ãªç¹å¾´ã¨å©ç¹ã¯ä»¥ä¸ã®éãã§ãã
- å¹ççãªæ¨©é管ç
ã¦ã¼ã¶ã¼å±æ§ã使ç¨ãããã¨ã§ãè¤æ°ã®ããªã·ã¼ã使ãã代ããã«ãåºæ¬çãªæ¨©éããªã·ã¼ã1ã¤ä½æããã ãã§æ¸ã¿ã¾ãã - ããªã·ã¼ã®æè»æ§
ãªã½ã¼ã¹ãã¦ã¼ã¶ã¼ã追å ã»åé¤ããéã«ãããªã·ã¼ãæ´æ°ããå¿ è¦ãããã¾ãããããªã·ã¼ã¯ããããããã¦ã¼ã¶ã¼å±æ§ãæã¤ã¦ã¼ã¶ã¼ã«ã®ã¿ã¢ã¯ã»ã¹ã許å¯ãã¾ãã - 屿§ã®ãããã³ã°
ããã©ã«ãã®ãããã³ã°ã鏿ããããã«ã¹ã¿ã ãããã³ã°ã使ãã¦ãIAM権éããªã·ã¼ã§åç §ããã屿§ãè¨å®ã§ãã¾ãã - æ¡ä»¶ä»ãã¢ã¯ã»ã¹
ã¦ã¼ã¶ã¼ã®å±æ§å¤ã«åºã¥ãã¦ãç¹å®ã®ãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ãæ¡ä»¶ä»ãã§è¨±å¯ã¾ãã¯æå¦ã§ãã¾ãã
ã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ã¨ãã¦ãä¿¡é ¼ã§ããã½ã¼ã¹ããåå¾ãã屿§ã®ã¿ã使ç¨ããã¦ã¼ã¶ã¼ãèªç±ã«å¤æ´ã§ããªã屿§ãéè¦ãªæ¨©éã®å¤æã«å©ç¨ãããã¨ãéè¦ã§ãã
ã¾ãã屿§ã®å¤ã䏿ã¾ãã¯åå¨ããªãå ´åã®ããã©ã«ãã®åä½ãå®ç¾©ããæå°æ¨©éã®ååã«å¾ã£ã¦ã¢ã¯ã»ã¹ãå¶å¾¡ãããã¨ãæ¨å¥¨ããã¾ãã
ã¦ã¼ã¶ã¼ã»ãã·ã§ã³ã«ããªã³ã·ãã«ã¿ã°ãé©ç¨ããããã«ãIAMãã¼ã«ã®ä¿¡é ¼ããªã·ã¼ãé©åã«è¨å®ããå¿
è¦ãããã¾ãã
ããã«ã屿§ã®çµã¿åããã使ç¨ãã¦ããç´°ããªã¢ã¯ã»ã¹å¶å¾¡ãå®ç¾ãã宿çã«å±æ§ã¨ããªã·ã¼ã®é¢ä¿ãè¦ç´ãã¦ãä¸è¦ãªæ¨©éãä»ä¸ããã¦ããªãã確èªãããã¨ã大åã§ãã
ãããã®å®è·µã«ããã屿§ãã¼ã¹ã®ã¢ã¯ã»ã¹å¶å¾¡ãããå®å
¨ãã¤å¹æçã«å®è£
ãããã¨ãã§ãã¾ãã
AWSãªã½ã¼ã¹ã«ã¢ã¯ã»ã¹ã§ããèªè¨¼æ å ±ã®åå¾
Amazon Cognito Identity Poolsã使ç¨ããã¨ãAWSãªã½ã¼ã¹ã«ã¢ã¯ã»ã¹ã§ãã䏿çãªéå®ç権éãæã¤èªè¨¼æ
å ±ãã¢ããªã±ã¼ã·ã§ã³ã¸æä¾ã§ãã¾ãã
èªè¨¼æ
å ±ã®åå¾ããã»ã¹ã«ã¯ã以ä¸ã®éè¦ãªãã¤ã³ããããã¾ãã
- èªè¨¼æ¸ã¿ã¨æªèªè¨¼ã®ã¢ã¤ãã³ãã£ãã£
æªèªè¨¼ã¦ã¼ã¶ã¼ï¼ 身å 確èªãªãã§ã¢ããªã«ã¢ã¯ã»ã¹ã§ããã²ã¹ãã¦ã¼ã¶ã¼ã«é©ãã¦ãã¾ãã
èªè¨¼æ¸ã¿ã¦ã¼ã¶ã¼ï¼ ãµã¼ããã¼ãã£ã®IDãããã¤ãã¼ã¾ãã¯ã¦ã¼ã¶ã¼ãã¼ã«ãçµç±ãã¦ãã°ã¤ã³ãã身å ã確èªããã¾ãã - Amazon Cognitoã¢ã¤ãã³ãã£ãã£
ã¢ã¤ãã³ãã£ãã£ãã®ãã®ã¯èªè¨¼æ å ±ã§ã¯ããã¾ããã
AWS Security Token Service(STS)ã®Web IDãã§ãã¬ã¼ã·ã§ã³ãµãã¼ãã«ãã£ã¦èªè¨¼æ å ±ã¨äº¤æããã¾ãã - æ¨å¥¨ãããèªè¨¼æ
å ±å徿¹æ³
Amazon Cognito Identity Poolsèªè¨¼æ å ±ãªãã¸ã§ã¯ãã§ããAWS.CognitoIdentityCredentialsãããAWSèªè¨¼æ å ±ãå ¥æãããã¨ãæ¨å¥¨ããã¦ãã¾ãã
èªè¨¼æ å ±ãªãã¸ã§ã¯ãå ã®ã¢ã¤ãã³ãã£ãã£ãAWS STSãçµç±ãã¦èªè¨¼æ å ±ã«äº¤æããã¾ãã - SDKãAWS Amplifyã¨ã®çµ±åã®å©ç¨
AWS SDKã«ã¯ãèªè¨¼æ å ±ãèªåçã«æ¢ç´¢ãã使ç¨ããããã®ä»çµã¿(èªè¨¼æ å ±ãããã¤ãã¼ãã§ã¼ã³)ãçµã¿è¾¼ã¾ãã¦ãã¾ããã¦ã§ãIDã¯ã¬ãã³ã·ã£ã«ãããã¤ãã¼(Identity Poolsãå«ã)ã¯ãã®ãã§ã¼ã³ã®ä¸é¨ã§ããã¤ã¾ããSDKã使ç¨ããéã«ã追å ã®è¨å®ãªãã§Identity Poolsããã®èªè¨¼æ å ±ãç°¡åã«å©ç¨ã§ãã¾ãã
ã¾ããAWS Amplifyã«ã¯Identity Poolçµ±åæ©è½ãçµã¿è¾¼ã¾ãã¦ãããèªè¨¼ãã¦ã¼ã¶ã¼ç®¡çã®å®è£ ãå¤§å¹ ã«ç°¡ç´ åã§ããéçºæéã®ç縮ã¨ãããå ç¢ãªã»ãã¥ãªãã£å®è£ ãå¯è½ã«ãªãã¾ãã - å種SDKåãã®ãªã½ã¼ã¹
Androidã»iOSã»JavaScriptã».NETã»Goã»Javaã»PHPã»Pythonã»Rustãªã©ãåããã°ã©ãã³ã°è¨èªããã©ãããã©ã¼ã åãã®SDKã§ãIdentity Poolsã使ç¨ããèªè¨¼æ å ±ã®åå¾ã¨è¨å®æ¹æ³ãæä¾ããã¦ãã¾ãã
ãããã®ãã¤ã³ããæãã¦èªè¨¼æ å ±ãæ´»ç¨ãããã¨ã§ãã¢ããªã±ã¼ã·ã§ã³ã«å®å ¨ãã¤å¹ççãªèªè¨¼ã·ã¹ãã ãå®è£ ãããã¨ãã§ãã¾ãã
éçºè èªè¨¼ID(Developer-Authenticated Identities)
éçºè
èªè¨¼IDã¯ãAmazon Cognito Identity Poolsãæä¾ããèªè¨¼æ¹å¼ã®1ã¤ã§ãã
ãã®æ©è½ã使ç¨ããã¨ãéçºè
ã¯æ¢åã®èªè¨¼ããã»ã¹ã使ç¨ãã¦ã¦ã¼ã¶ã¼ãç»é²ã»èªè¨¼ããªãããAmazon Cognito Identity Poolsãå©ç¨ãã¦ã¦ã¼ã¶ã¼ãã¼ã¿ã®åæãAWSãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ãè¡ããã¨ãã§ãã¾ãã
ãã ãããã®æ©è½ã¯Amazon Cognito Identity Poolsã¨é£æºãã¦ä½¿ç¨ãããã®ã§ãAmazon Cognito Identity Poolsã«ã¯å¯¾å¿ãã¦ããªããã¨ã«æ³¨æãå¿
è¦ã§ãã
éçºè
èªè¨¼IDã®ä¸»ãªç¹å¾´ã«ã¯æ¬¡ã®ãã®ãããã¾ãã
- ã«ã¹ã¿ã èªè¨¼
éçºè ã¯ç¬èªã®èªè¨¼ã·ã¹ãã ã使ç¨ã§ãã¾ãã - ããã¯ã¨ã³ãã¨ã®é£æº
ã¦ã¼ã¶ã¼ããã¤ã¹ã»éçºè ã®ããã¯ã¨ã³ãã»Amazon Cognito Identity Poolsã®3è éã§é£æºãã¾ãã - æè»æ§
ã¦ã§ãIDãã§ãã¬ã¼ã·ã§ã³(Facebookã»Googleã»Amazonã»Appleãªã©)ã¨ä½µç¨å¯è½ã§ãããå®è£ ã®è¤éããå¢ãå¯è½æ§ãããã¾ãã - ã»ãã¥ãªãã£
GetOpenIdTokenForDeveloperIdentity APIãããã¯ã¨ã³ããµã¼ãã¼ã§ä½¿ç¨ãã¦ã管çè èªè¨¼æ å ±ã§èªè¨¼ãè¡ãã¾ããã¯ã©ã¤ã¢ã³ããµã¤ãã§ã®ç´æ¥å¼ã³åºãã¯æ¨å¥¨ããã¾ããã - å®è£
æ¬è¨äºå·çæç¹ã§ãAndroidã»iOSã»JavaScriptã»Unityã»Xamarinåãã®SDKã§å®è£ æ¹æ³ãæä¾ããã¦ãã¾ãã - IDãã¼ã«ã¨ã®é¢é£ä»ã
éçºè ãããã¤ãã¼åãIDãã¼ã«ã«é¢é£ä»ãã¦ä½¿ç¨ãã¾ãã - ãã¼ã¯ã³ç®¡ç
ããã¯ã¨ã³ãã§ãã¼ã¯ã³ãåå¾ããã¯ã©ã¤ã¢ã³ãã«è¿ãä»çµã¿ãå¿ è¦ã§ããã¾ãããã¼ã¯ã³ã®æå¹æé管çãæ´æ°ã¡ã«ããºã ãèæ ®ããå¿ è¦ãããã¾ãã - ä»ã®èªè¨¼æ¹å¼ã¨ã®çµ±å
æªèªè¨¼IDãã½ã¼ã·ã£ã«IDãããã¤ãã¼ã¨ä½µç¨ããå ´åã®å®è£ æ¹æ³ãæä¾ããã¦ãã¾ãã
éçºè
èªè¨¼IDã®èªè¨¼ããã¼ã¯ä»¥ä¸ã®ããã«ãªãã¾ãã
- ã¢ããªã±ã¼ã·ã§ã³ãç¬èªã®ããã¯ã¨ã³ãã§èªè¨¼ãè¡ãã¾ãã
- ããã¯ã¨ã³ããAmazon Cognito Identity Poolsã®
GetOpenIdTokenForDeveloperIdentity
APIãå¼ã³åºããIDãã¼ã¯ã³ãåå¾ãã¾ãã - ããã¯ã¨ã³ããã¢ããªã±ã¼ã·ã§ã³ã«IDãã¼ã¯ã³ãè¿ãã¾ãã
- ã¢ããªã±ã¼ã·ã§ã³ããã®ãã¼ã¯ã³ã使ç¨ãã¦AWSèªè¨¼æ å ±ãåå¾ãã¾ãã
ã¾ããã¨ã©ã¼ãã³ããªã³ã°ããã¼ã¯ã³ã®æ´æ°ããã»ã¹ãèæ
®ã«å
¥ããå¿
è¦ãããã¾ãã
éçºè
èªè¨¼IDã使ç¨ããã«ã¯ã以ä¸ã®æé ãå¿
è¦ã§ãã
- Amazon Cognito Identity Pools consoleã§ã¢ã¤ãã³ãã£ãã£ãã¼ã«ã«éçºè ãããã¤ãã¼åãé¢é£ä»ãã¾ãã
- ã¢ã¤ãã³ãã£ãã£ãã¼ã«ã«é©åãªIAMãã¼ã«ã¨ããªã·ã¼ãè¨å®ãã¾ãã
- ã¢ããªã±ã¼ã·ã§ã³å´ã§ç¬èªã®IDãããã¤ãã¼ã¯ã©ã¹ãå®è£ ãã¾ãã
- ããã¯ã¨ã³ãå´ã§
GetOpenIdTokenForDeveloperIdentity
APIãå¼ã³åºããIDãã¼ã¯ã³ãåå¾ã»ç®¡çãã¾ãã
éçºè
èªè¨¼IDã使ç¨ãããã¨ã§ãæ¢åã®èªè¨¼ã·ã¹ãã ãæ´»ç¨ããªãããAmazon Cognito Identity Poolsã®æ©è½ãå©ç¨ã§ãããããæè»ãªã¦ã¼ã¶ã¼ç®¡çã¨AWSãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹å¶å¾¡ãå¯è½ã«ãªãã¾ãã
å¤é¨ã¢ã¤ãã³ãã£ãã£ãããã¤ãã¼
Amazon Cognito Identity Poolsã¯ãè¤æ°ã®å¤é¨ã¢ã¤ãã³ãã£ãã£ãããã¤ãã¼(IdP)ã¨ã®é£æºããµãã¼ããã¦ãããã¦ã¼ã¶ã¼ã¯æ§ã
ãªæ¹æ³ã§èªè¨¼ãè¡ããã¨ãã§ãã¾ãã
Amazon Cognito Identity Poolsã«ããã¦ãå¤é¨IdPããã®èªè¨¼æ
å ±ãè¨å®ããããã«ä½¿ç¨ãããè¦ç´ ã§ããloginsããããã£ã使ç¨ãããã¨ã§ãIdPããåãåã£ãèªè¨¼æ
å ±ãè¨å®ã§ãã¾ãã
ããã«ã1ã¤ã®ã¢ã¤ãã³ãã£ãã£ãã¼ã«ãè¤æ°ã®IdPã¨é¢é£ä»ãããã¨ãå¯è½ã§ãã
ä¾ãã°ãFacebookã¨Googleã®ä¸¡æ¹ã®ãã¼ã¯ã³ãloginsããããã£ã«è¨å®ãããã¨ã§ã1ã¤ã®Amazon Cognitoã¢ã¤ãã³ãã£ãã£ãè¤æ°ã®IdPãã°ã¤ã³ã¨é¢é£ä»ãããã¨ãã§ãã¾ãã
ãã®çµæãã¦ã¼ã¶ã¼ã¯ã©ã¡ãã®ã¢ã«ã¦ã³ãã§ãèªè¨¼ã§ããAmazon Cognitoã¯åãã¦ã¼ã¶ã¼èå¥åãè¿ãã¾ãã
Amazon Cognito Identity Poolsããµãã¼ããã主ãªå¤é¨IdPã«ã¯ä»¥ä¸ã®ãã®ãããã¾ã
- Login with Amazon
- Sign in with Apple
- OpenID Connect(OIDC)ãããã¤ãã¼
- SAML ãããã¤ãã¼
ãããã®å¤é¨IdPãå©ç¨ãããã¨ã§ãã¢ããªã±ã¼ã·ã§ã³ã«æè»ã§å ç¢ãªèªè¨¼æ©è½ãå®è£ ãããã¨ãã§ãã¾ãã
ã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹
Amazon Cognito Identity Poolsã®ã»ãã¥ãªãã£ãå¼·åããããã®ãã¹ããã©ã¯ãã£ã¹ã«ã¯ã以ä¸ã®ãããªéè¦ãªç¹ãããã¾ãã
- æå°æ¨©éã®åå
IAMãã¼ã«ã¨ããªã·ã¼ã使ç¨ãã¦ãã¦ã¼ã¶ã¼ã«å¿ è¦æå°éã®æ¨©éã®ã¿ãä»ä¸ãã¾ãã - ãªã½ã¼ã¹ãã¼ã¹ã®ããªã·ã¼ã®æ´»ç¨ ã¦ã¼ã¶ã¼ã®ãªã½ã¼ã¹ã¢ã¯ã»ã¹ã«å¯¾ãã¦ãããç´°ããªå¶å¾¡ãè¡ãããã«ãªã½ã¼ã¹ãã¼ã¹ã®ããªã·ã¼ã使ç¨ãã¾ãã
- ã»ãã·ã§ã³ã¿ã°ã®å©ç¨
ã¦ã¼ã¶ã¼ã¯ã¬ã¼ã ãIAMã»ãã·ã§ã³ã¿ã°ã«å¤æããã¦ã¼ã¶ã¼ã®ç¹æ§ã«åºã¥ããã¢ã¯ã»ã¹å¶å¾¡ãå®è£ ãã¾ãã - ã²ã¹ãã¢ã¯ã»ã¹ã®å¶é
æªèªè¨¼ã¦ã¼ã¶ã¼ã«å¯¾ãã¦ã¯ãéå®çãªã¹ã³ã¼ãã®AWSèªè¨¼æ å ±ã®ã¿ãçæããããè¨å®ãã¾ãã - ã¦ã¼ã¶ã¼ç¹æ§ã«åºã¥ãIAMãã¼ã«ã®å²ãå½ã¦
èªè¨¼æ¸ã¿ã¦ã¼ã¶ã¼ã«å¯¾ãã¦ãåã ã®ã¦ã¼ã¶ã¼ã¯ã¬ã¼ã ã«åºã¥ãã¦é©åãªIAMãã¼ã«ãå²ãå½ã¦ã¾ãã - é©åãªèªè¨¼ãããã¤ãã¼ã®é¸æ
ã¦ã¼ã¹ã±ã¼ã¹ã«é©ããä¿¡é ¼ã§ããèªè¨¼ãããã¤ãã¼ã鏿ããé©åã«è¨å®ãã¾ãã - ã«ã¹ã¿ã èªè¨¼ã®é©åãªå®è£
éçºè èªè¨¼identitiesã使ç¨ããå ´åã¯ãå ç¢ãªèªè¨¼ã¡ã«ããºã ãå®è£ ããé©åã«æ¤è¨¼ãã¾ãã - 宿çãªç£æ»ã¨ã¢ãã¿ãªã³ã°
Amazon CloudWatchãªã©ã®ãµã¼ãã¹ãæ´»ç¨ãã¦ãã¦ã¼ã¶ã¼ã¢ã¯ãã£ããã£ã宿çã«ç£æ»ããã³ã¢ãã¿ãªã³ã°ãã¾ãã
ãããã®ãã©ã¯ãã£ã¹ãé©ç¨ãããã¨ã§ãAmazon Cognito Identity Poolsã®ã»ãã¥ãªãã£ãå¤§å¹ ã«åä¸ãããã¢ããªã±ã¼ã·ã§ã³ã¨ã¦ã¼ã¶ã¼ãã¼ã¿ãä¿è·ãããã¨ãã§ãã¾ãã
User Poolsã¨Identity Poolsã®éãã¨æ¯è¼
Amazon Cognitoã®User Poolsã¨Identity Poolsã¯ãç°ãªãç®çã¨æ©è½ãæã¤2ã¤ã®éè¦ãªã³ã³ãã¼ãã³ãã§ãã
User Poolsã¯ä¸»ã«ã¦ã¼ã¶ã¼èªè¨¼ã¨ç®¡çã«ç¹åãã¦ãããã¦ã§ããã¢ãã¤ã«ã¢ããªã±ã¼ã·ã§ã³ã®ã¦ã¼ã¶ã¼ãã£ã¬ã¯ããªã¨ãã¦æ©è½ãã¾ãã
ãã¼ã«ã«ã¦ã¼ã¶ã¼ã®ä½æã»ãµã¼ããã¼ãã£IdPãéãããã§ãã¬ã¼ã·ã§ã³ã»å¤è¦ç´ èªè¨¼(MFA)ã»ã«ã¹ã¿ã èªè¨¼ããã¼ãªã©ã®æ©è½ãæä¾ãã¾ãã
䏿¹ãIdentity Poolsã¯ä¸»ã«AWSãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹å¶å¾¡ã«ç¦ç¹ãå½ã¦ã¦ãããèªè¨¼ãããã¦ã¼ã¶ã¼ãæªèªè¨¼ã¦ã¼ã¶ã¼ã«å¯¾ãã¦ä¸æçãªAWSèªè¨¼æ
å ±ãçºè¡ãã¾ãã
Identity Poolsã¯ããã¼ã«ãã¼ã¹ã®ã¢ã¯ã»ã¹å¶å¾¡ã屿§ãã¼ã¹ã®ã¢ã¯ã»ã¹å¶å¾¡ãçµç±ãã¦ãããç´°ããªAWSãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ç®¡çãå¯è½ã«ãã¾ãã
ãã®ä¸¡è
ãçµã¿åããããã¨ã§ãã»ãã¥ã¢ã§æè»ãªã¦ã¼ã¶ã¼èªè¨¼ã¨AWSãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹å¶å¾¡ãå®ç¾ã§ãã¾ãã
ä¾ãã°ãUser Poolsã§èªè¨¼ãããã¦ã¼ã¶ã¼ã®ãã¼ã¯ã³ãIdentity Poolsã§ä½¿ç¨ããé©åãªAWSèªè¨¼æ
å ±ãåå¾ããã¨ãã£ã飿ºãå¯è½ã§ãã
次ã®AWSããã¥ã¡ã³ãã®ãã¼ã¸ã«ã¯Amazon Cognitoã¨User Poolsã¨Identity Poolsã®æ©è½ã®æ¯è¼è¡¨ãããã¾ãã
Amazon Cognito user pools and identity pools comparison
ãã®å
容ãã¾ã¨ããã¨User Poolsã¨Identity Poolsã®ä¸»ãªéãã®ç¹å¾´ã«ã¯æ¬¡ã®ãã®ãæãããã¾ãã
é ç® | Amazon Cognito User Pools | Amazon Cognito Identity Pools |
---|---|---|
èªè¨¼ã¨èªå¯ | 主ã«ã¦ã¼ã¶ã¼èªè¨¼(OIDC IdPãSAML 2.0ãOAuth 2.0ãªã©)ã¨APIèªå¯ã«ç¹åãã¦ãã¾ãã | 䏿çãªAWSèªè¨¼æ å ±ã®çºè¡ã«ç¦ç¹ãå½ã¦ã¦ãã¾ãã |
ãã¼ã¯ã³ç®¡ç | IDãã¼ã¯ã³ãã¢ã¯ã»ã¹ãã¼ã¯ã³ã®çºè¡ã¨ã«ã¹ã¿ãã¤ãºãè¡ãã¾ãã | AWS STSã¨é£æºãã¦ä¸æçãªèªè¨¼æ å ±ã管çãã¾ãã |
ã¦ã¼ã¶ã¼ç®¡ç | ã¦ã¼ã¶ã¼ã®ç»é²ã»èªè¨¼ã»å±æ§ç®¡çã»MFAã»ã»ãã¥ãªãã£ç£è¦ãªã©ã®æ©è½ãæä¾ãã¾ãã | ãããã®æ©è½ãç´æ¥æä¾ãã¾ããã |
ã¢ã¯ã»ã¹å¶å¾¡ | ã°ã«ã¼ãæ©è½ãçµç±ãã¦IAMãã¼ã«è¦æ±ã®é層ã使ã§ãã¾ãã | ãã¼ã«ãã¼ã¹ããã³å±æ§ãã¼ã¹ã®ã¢ã¯ã»ã¹å¶å¾¡ãæä¾ããAWSãªã½ã¼ã¹ã¸ã®ããç´°ããªã¢ã¯ã»ã¹ç®¡çãå¯è½ã«ãã¾ãã |
æªèªè¨¼ã¢ã¯ã»ã¹ | ãã®æ©è½ãæã¡ã¾ããã | æªèªè¨¼ã¦ã¼ã¶ã¼ã«å¯¾ãã¦ãå¶éä»ãã®ã¢ã¯ã»ã¹ãæä¾ã§ãã¾ãã |
ã«ã¹ã¿ãã¤ãº | ã«ã¹ã¿ãã¤ãºæ©è½ãæä¾ãã¾ããèªè¨¼ããã¼ã»ã¦ã¼ã¶ã¼å±æ§ã»IDãã¼ã¯ã³ã対象ã«ãªãã¾ãã | ã«ã¹ã¿ãã¤ãºæ©è½ãæä¾ãã¾ããã¢ã¯ã»ã¹å¶å¾¡ã«éç¹ãç½®ãã¦ãã¾ãã |
AWS AppSyncã¨Amazon Cognito Sync
ã¯ã©ã¦ããã¼ã¹ã®ã¢ãã¤ã«ããã³ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³éçºã«ããããã¼ã¿ã®åæã¨ç®¡çãæ
ã主è¦ãªAWSãµã¼ãã¹ã¨ãã¦AWS AppSyncã¨Amazon Cognito Syncãæãããã¾ãã
çµè«ããè¨ãã¨ç¾å¨ã§ã¯Amazon Cognito Syncã¯éæ¨å¥¨(deprecated)ã«ãªããAWS AppSyncã®ä½¿ç¨ãæ¨å¥¨ããã¦ãã¾ãã
ããã§ã¯ããããã®ãµã¼ãã¹ã®ç¹å¾´ãéããç¾å¨ã®æ¨å¥¨ãããçç±ã«ã¤ãã¦èª¬æãã¾ãã
主ãªéã
AWS AppSyncã¯ãGraphQLã使ç¨ãã¦ã¢ããªã±ã¼ã·ã§ã³ãã¼ã¿ã管çããããã®ãã«ããã¼ã¸ããµã¼ãã¹ã§ããè¤éãªãã¼ã¿æ§é ãæ±ãããªã¢ã«ã¿ã¤ã ã§ã®ãã¼ã¿åæãå¯è½ã«ãã¾ãã
Amazon Cognito Syncã¯ãããã¤ã¹éã§ã¦ã¼ã¶ã¼ãã¼ã¿ãåæããããã®ã·ã³ãã«ãªãµã¼ãã¹ã§ããããã¼ã»ããªã¥ã¼ãã¢ã®å½¢å¼ã§ãã¼ã¿ãä¿åããåæããæ©è½ãæä¾ãã¦ãã¾ããã
観ç¹å¥ã«è¦ãã¨æ¬¡ã®ãããªéããããã¾ãã
é ç® | AWS AppSync | Amazon Cognito Sync |
---|---|---|
ãã¼ã¿ã¢ãã« | GraphQLã使ç¨ããè¤éãªãã¼ã¿æ§é ã¨ãªã¬ã¼ã·ã§ã³ã·ãããæ±ãã¾ãã | ã·ã³ãã«ãªãã¼ã»ããªã¥ã¼ãã¢ã®ãã¼ã¿ã¢ãã«ã«éå®ããã¾ãã |
ã¹ã±ã¼ã©ããªã㣠| å¤§è¦æ¨¡ãªã¢ããªã±ã¼ã·ã§ã³ã«å¯¾å¿å¯è½ã§ãé«ãã¹ã±ã¼ã©ããªãã£ãæä¾ãã¾ãã | å°è¦æ¨¡ããä¸è¦æ¨¡ã®ã¢ããªã±ã¼ã·ã§ã³ã«é©ãã¦ãã¾ããã |
ãªã¢ã«ã¿ã¤ã æ©è½ | WebSocketsã使ç¨ãããªã¢ã«ã¿ã¤ã ãã¼ã¿æ´æ°ããµãã¼ããã¦ãã¾ãã | ãªã¢ã«ã¿ã¤ã æ´æ°æ©è½ã¯éå®çã§ããã |
çµ±åæ§ | 夿§ãªAWSãµã¼ãã¹(DynamoDB, Aurora, Elasticsearchãªã©)ã¨çµ±åå¯è½ã§ãã | 主ã«Cognito Identity Poolsã¨å¯æ¥ã«çµ±åããã¦ãã¾ããã |
éçºè ã¨ã¯ã¹ããªã¨ã³ã¹ | ããè±å¯ãªéçºãã¼ã«ã¨AWS Amplifyã¨ã®çµ±åãæä¾ãã¾ãã | ã·ã³ãã«ãªAPIã§åºæ¬çãªãã¼ã¿åæã¿ã¹ã¯ã«é©ãã¦ãã¾ããã |
ç¾å¨ã®æ¨å¥¨äºé ã¨ãã®çç±
AWSã¯ç¾å¨ãæ°è¦ã®ã¢ããªã±ã¼ã·ã§ã³éçºã«ããã¦AWS AppSyncã®ä½¿ç¨ãå¼·ãæ¨å¥¨ãã¦ãã¾ãã
䏿¹ã§ãAmazon Cognito Syncã¯éæ¨å¥¨(deprecated)ã¨ãªã£ã¦ãããæ°è¦ã§ã®ä½¿ç¨ã¯æ¨å¥¨ããã¦ãã¾ããã
ãã®æ¨å¥¨ã®èæ¯ã«ã¯ä»¥ä¸ã®çç±ãããã¾ãã
- AWS AppSyncã®åªããæè»æ§ã¨ã¹ã±ã¼ã©ããªãã£
- ã¢ãã³ãªã¢ããªã±ã¼ã·ã§ã³éçºãã¼ãºã¸ã®é©åæ§
- ããå¼·åãªã»ãã¥ãªãã£æ©è½ã¨ç´°ããã¢ã¯ã»ã¹å¶å¾¡
- GraphQLã®æ®åã¨ãå¹ççãªãã¼ã¿åå¾ã®éè¦å¢å
AWS AppSyncã¨Amazon DynamoDBãçµã¿åããããã¨ã§ãããçµ±åãããã¯ã©ã¦ããã¤ãã£ããªã¢ããã¼ããå®ç¾ããã¹ã±ã¼ã©ããªãã£ã¨ããã©ã¼ãã³ã¹ã®åä¸ãå³ããã¨ãã§ãã¾ãã
ãã®ãããæ¢åã®Cognito Syncã使ç¨ãã¦ããããã¸ã§ã¯ãã«ã¤ãã¦ã¯ãå°æ¥çã«AppSyncã¸ã®ç§»è¡ãæ¤è¨ãããã¨ãæã¾ããã¨ãããã§ãããã
AWSãµã¼ãã¹ã¨ã®çµ±å
Amazon Cognitoã¯ãæ§ã
ãªAWSãµã¼ãã¹ã¨çµ±åãããã¨ã§ãããå¼·åã§æè»ãªèªè¨¼ã»èªå¯ã½ãªã¥ã¼ã·ã§ã³ãæä¾ãã¾ãã
ããã§ã¯ã主è¦ãª3ã¤ã®çµ±åæ¹æ³ã«ã¤ãã¦è©³ãã説æãã¾ãã
ãããã®çµ±åã«ãããéçºè
ã¯èªèº«ã®ã¢ããªã±ã¼ã·ã§ã³ãã¼ãºã«æé©ãªèªè¨¼ã»èªå¯ã·ã¹ãã ãæ§ç¯ãããã¨ãã§ãã¾ãã
AWS Amplifyã¨ã®çµ±å
Amazon Cognito User Poolsã¯ãAWS Amplifyãçµç±ãã¦ç°¡åã«ã¦ã§ãã¢ããªãã¢ãã¤ã«ã¢ããªã«çµ±åã§ãã¾ãã
Amplify Authã¯ä¸»ã«Amazon Cognitoã使ç¨ãã¦èªè¨¼æ©è½ãæ§ç¯ãã¾ãã
éçºè
ã¯Amplify CLIã使ç¨ãã¦ãªã½ã¼ã¹ã使ã»è¨å®ããããAmplifyã©ã¤ãã©ãªã使ã£ã¦ãµã¤ã³ã¤ã³ããµã¤ã³ã¢ãããªã©ã®æ©è½ãå®è£
ã§ãã¾ãã
ããã«ãAmplifyã®Authenticatorã³ã³ãã¼ãã³ããå©ç¨ãããã¨ã§ãã«ã¹ã¿ãã¤ãºå¯è½ãªèªè¨¼UIãç°¡åã«æ§ç¯ãããã¨ãã§ãã¾ãã
AWS Amplifyã¨ã®çµ±åã«ãã£ã¦ãéçºè
ã¯User Poolsã®æ©è½ãæå¤§éã«æ´»ç¨ãã¤ã¤ãè¿
éã«ã»ãã¥ã¢ãªèªè¨¼ã·ã¹ãã ãå®è£
ãããã¨ãå¯è½ã«ãªãã¾ãã
AWS SDKã¨ã®çµ±å
Amazon Cognito User Poolsã¨Amazon Cognito Identity Poolsã®ä¸¡æ¹ãAWS SDKsã使ã£ã¦çµ±åãããã¨ãã§ãã¾ãã
ããã¯ã¨ã³ãéçºè
ã¯ã鏿ããè¨èªã®SDKã使ç¨ãã¦Amazon Cognito APIã¨ç´æ¥ããåãããã«ã¹ã¿ã ã®èªè¨¼ãã¤ã¯ããµã¼ãã¹ãæ§ç¯ã§ãã¾ãã
User Pools APIã使ç¨ãã¦ã¦ã¼ã¶ã¼ç®¡çãèªè¨¼ããã»ã¹ãå¶å¾¡ããIdentity Pools APIã使ç¨ãã¦AWSãªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹æ¨©éã管çã§ãã¾ãã
AWS SDKã¨ã®çµ±åã«ãã£ã¦ãéçºè
ã¯ããç´°ããå¶å¾¡ã¨æè»æ§ãæã£ã¦èªè¨¼ã»èªå¯ã·ã¹ãã ãå®è£
ãããã¨ãå¯è½ã«ãªãã¾ãã
Amazon Verified Permissionsã¨ã®çµ±å
Amazon Cognito User Poolsã¯ãAmazon Verified Permissionsã¨çµ±åãã¦é«åº¦ãªèªå¯æ©è½ãå®ç¾ã§ãã¾ãã
ã¢ããªã±ã¼ã·ã§ã³ã¯User Poolsããçºè¡ãããã¢ã¯ã»ã¹ãã¼ã¯ã³ã¾ãã¯IDãã¼ã¯ã³ãVerified Permissionsã«æ¸¡ããã¨ã§ã詳細ãªèªå¯å¤æãå¾ããã¨ãã§ãã¾ãã
Amazon Verified Permissionsã¯ãCedar Policy Languageã§è¨è¿°ãããããªã·ã¼ã«åºã¥ãã¦ãã¦ã¼ã¶ã¼ã®å±æ§ããªã¯ã¨ã¹ãã®ã³ã³ããã¹ããèæ
®ãã許å¯ã¾ãã¯æå¦ã®æ±ºå®ãä¸ãã¾ãã
ã¾ããAmazon Verified Permissionsã®ä¸æ ¸æ©è½ã§ããããªã·ã¼ã¹ãã¢ã¯ãèªå¯ããªã·ã¼ãéä¸ç®¡çããããã®ãªãã¸ããªã§ãã
ããªã·ã¼ã¹ãã¢ãè¨å®ããéã¯ãå¦çãããã¼ã¯ã³ã¿ã¤ã(ã¢ã¯ã»ã¹ãã¼ã¯ã³ã¾ãã¯IDãã¼ã¯ã³)ã鏿ããAmazon Cognito User Poolsãã¢ã¤ãã³ãã£ãã£ã½ã¼ã¹ã¨ãã¦è¨å®ãã¾ãã
ããªã·ã¼ã¹ãã¢ã使ç¨ãããã¨ã§ãããªã·ã¼å
ã§ã¦ã¼ã¶ã¼ã»ã°ã«ã¼ãã»ã¢ã¯ã·ã§ã³ã»ãªã½ã¼ã¹ãé層çã«åç
§ã§ããããã«ãªããããç´°ããªèªå¯ã«ã¼ã«ã®å®ç¾©ãå¯è½ã«ãªãã¾ãã
ãã®çµ±åã«ãã£ã¦ãAmazon Cognito User Poolsã®èªè¨¼æ©è½ã¨Amazon Verified Permissionsã®æè»ãªèªå¯æ©è½ãçµã¿åãããããç´°ããã¢ã¯ã»ã¹å¶å¾¡ãå®ç¾ãããã¨ãã§ãã¾ãã
ç¹ã«ãAmazon API Gatewayã¨é£æºããããã¨ã§ãRESTful APIã«å¯¾ããå¼·åãªèªå¯ã¡ã«ããºã ãæ§ç¯ãããã¨ãå¯è½ã§ãã
Amazon Cognito User Poolsã¨Amazon Verified Permissionsã¨ã®çµ±åã«ããèªè¨¼ã»èªå¯ããã»ã¹ã¨å©ç¹ãã¾ã¨ããã¨æ¬¡ã®ããã«ãªãã¾ãã
Amazon Cognito User Poolsã«ããèªè¨¼ããã»ã¹
- ã¦ã¼ã¶ã¼ã¯Amazon Cognito User Poolsãçµç±ãã¦èªè¨¼ãè¡ãã¾ãã
- èªè¨¼æåå¾ãUser Poolsã¯ã¢ã¯ã»ã¹ãã¼ã¯ã³ã¾ãã¯IDãã¼ã¯ã³ãçºè¡ãã¾ãã
- ã¢ããªã±ã¼ã·ã§ã³ã¯ããã®ãã¼ã¯ã³ãVerified Permissionsã«æ¸¡ãã¦èªå¯å¤æãè¦æ±ãã¾ãã
Amazon Verified Permissionsã«ããèªå¯ããã»ã¹
- Amazon Verified Permissionsã¯åãåã£ããã¼ã¯ã³ãæ¤è¨¼ãã¾ãã
ãã¼ã¯ã³ã®æå¹æ§ãçºè¡å ãæå¹æéãªã©ããã§ãã¯ãã¾ãã
ã¦ã¼ã¶ã¼ãã¼ã«ãAmazon Verified Permissionsã®è¨å®æ¸ã¿ã¢ã¤ãã³ãã£ãã£ã½ã¼ã¹ã§ãããã¨ã確èªãã¾ãã - ãã¼ã¯ã³å ã®æ å ±(ã¯ã¬ã¼ã )ãæ½åºããããªã·ã¼è©ä¾¡ã®å ¥åã¨ãã¦ä½¿ç¨ãã¾ãã
- Cedar Policy Languageã§è¨è¿°ãããããªã·ã¼ã«åºã¥ãã¦ãèªå¯å¤æãè¡ãã¾ãã
ã¦ã¼ã¶ã¼ã®å±æ§(ã°ã«ã¼ãæå±ãã«ã¹ã¿ã 屿§ãªã©)
ãªã¯ã¨ã¹ãã®ã³ã³ããã¹ã(ãªã½ã¼ã¹èå¥åãã¢ã¯ã·ã§ã³ç¨®å¥ãªã©)
ãã®ä»ã®ã«ã¹ã¿ã ã³ã³ããã¹ãæ å ± - 許å¯(Allow)ã¾ãã¯æå¦(Deny)ã®æ±ºå®ãè¿ãã¾ãã
- ãã¼ã¯ã³ã®å¤±å¹ã¨åé¤ãããã¦ã¼ã¶ã¼ã®æ±ã
Verified Permissionsã¯ãã¢ã¤ãã³ãã£ãã£ã½ã¼ã¹ããç¥ãå¾ãæ å ±ã¨ã¦ã¼ã¶ã¼ãã¼ã¯ã³ã®æå¹æéã®ã¿ãæ¤è¨¼ãã¾ãã
ãã¼ã¯ã³ã®å¤±å¹ãã¦ã¼ã¶ã¼ã®åé¤ç¶æ ã¯ç¢ºèªãã¾ããã
ãã¼ã¯ã³ã失å¹ããããã¦ã¼ã¶ã¼ãã¼ã«ããã¦ã¼ã¶ã¼ãåé¤ããããããå ´åã§ãããã¼ã¯ã³ã®æå¹æéãåããã¾ã§ã¯æå¹ã¨è¦ãªããã¾ãã
Amazon Cognito User Poolsã¨Amazon Verified Permissionsãçµ±åãããå©ç¹
Amazon Cognito User Poolsã¨Amazon Verified Permissionsãçµ±åãããå©ç¹ã«ã¯æ¬¡ã®ãããªãã®ãããã¾ãã
- ããç´°ããã¢ã¯ã»ã¹å¶å¾¡
ã¦ã¼ã¶ã¼å±æ§ã»ã°ã«ã¼ãæå±ã»ãªã¯ã¨ã¹ãã³ã³ããã¹ããªã©ã«åºã¥ã詳細ãªèªå¯ã«ã¼ã«ãå®ç¾©ã§ãã¾ãã - æè»ãªããªã·ã¼ç®¡ç
Cedar Policy Languageã使ç¨ãã¦ãè¤éãªèªå¯ãã¸ãã¯ã表ç¾ã§ãã¾ãã - ä¸å¤®é権çãªèªå¯
ã¢ããªã±ã¼ã·ã§ã³å ¨ä½ã§ä¸è²«ããèªå¯ã«ã¼ã«ãé©ç¨ã§ãã¾ãã - ã¹ã±ã¼ã©ããªãã£
Amazon Verified Permissionsã®ããã¼ã¸ããµã¼ãã¹ãå©ç¨ãããã¨ã§ãå¤§è¦æ¨¡ãªã¢ããªã±ã¼ã·ã§ã³ã§ãå¹ççã«èªå¯ãå¦çã§ãã¾ãã - RBACã¨ABACã®çµã¿åãã
IDãã¼ã¯ã³ã使ç¨ãããã¨ã§ããã¼ã«ãã¼ã¹ã®ã¢ã¯ã»ã¹å¶å¾¡(Role-Based Access Control, RBAC)ã¨å±æ§ãã¼ã¹ã®ã¢ã¯ã»ã¹å¶å¾¡(Attribute-Based Access Control, ABAC)ãçµã¿åããããã¨ãã§ãã¾ãã
ã¦ã¼ã¶ã¼ã®å±æ§ã¨ã°ã«ã¼ãã¡ã³ãã¼ã·ããã«åºã¥ãã¦ãããç´°ããèªå¯å¤æãå¯è½ã«ãªãã¾ãã
Amazon API Gatewayã®èªè¨¼ã»èªå¯ã§Amazon Cognito User Poolsã¨Amazon Verified Permissionsã使ç¨ããå ´åã®ããã»ã¹ã¨å©ç¹
Amazon API Gatewayã§Amazon Cognito User Poolsã使ç¨ãã¦èªè¨¼ãè¡ããAmazon Verified Permissionsã§èªå¯ãè¡ãå ´åãä¾ã«ã¨ã£ã¦ããã®ããã»ã¹ã¨å©ç¹ã説æãã¾ãã

Amazon API Gatewayã®èªè¨¼ã»èªå¯ã§ä½¿ç¨ããå ´åã®ããã»ã¹
- ã¦ã¼ã¶ã¼èªè¨¼(Amazon Cognito User Pools)
ã¦ã¼ã¶ã¼ã¯Amazon Cognitã¾ãã¯ä»ã®OIDC IdPãéãã¦èªè¨¼ãè¡ãã¾ãã
IdPã¯ãã¦ã¼ã¶ã¼æ å ±ãå«ãIDãã¼ã¯ã³ã¨ã¢ã¯ã»ã¹ãã¼ã¯ã³(JWT)ãçºè¡ãã¾ãã - APIãªã¯ã¨ã¹ã
ã¯ã©ã¤ã¢ã³ãã¯Amazon API Gatewayã«ãªã¯ã¨ã¹ããéä¿¡ããéãJWTãAuthorizationãããã¼ã«å«ãã¾ãã - Amazon API Gatewayã®å¦ç
API Gatewayã¯ãèªå¯æ±ºå®ã®ãã£ãã·ã¥ãããå ´åã¯ããã使ç¨ãã¾ãã
ãã£ãã·ã¥ããªãå ´åãç¡å¹ãªå ´åãAPI Gatewayã¯Lambdaãªã¼ã½ã©ã¤ã¶ã¼ãå¼ã³åºãã¾ãã - Lambdaãªã¼ã½ã©ã¤ã¶ã¼ã®å¦ç
AWS Lambda颿°ã¯ãIsAuthorizedWithToken APIã使ç¨ãã¦Amazon Verified Permissionsã«èªå¯ãªã¯ã¨ã¹ããéä¿¡ãã¾ãã
ãã®éãã¦ã¼ã¶ã¼ã®ãã¼ã¯ã³(ããªã³ã·ãã«)ãAPIã¡ã½ããã¨ãã¹(ã¢ã¯ã·ã§ã³)ãApplication(ãªã½ã¼ã¹)ãå«ãã¾ãã - èªå¯å¤æ(Amazon Verified Permissions)
Amazon Verified Permissionsã¯ãã¼ã¯ã³ãæ¤è¨¼ããããªã·ã¼ã¹ãã¢ã«ããCedar Policy Languageã§è¨è¿°ãããããªã·ã¼ã«åºã¥ãã¦èªå¯å¤æãè¡ãã¾ãã
ã¦ã¼ã¶ã¼ã®å±æ§ã»ãªã¯ã¨ã¹ãã®ã³ã³ããã¹ãã»ãã®ä»ã®æ å ±ãèæ ®ãã許å¯(Allow)ã¾ãã¯æå¦(Deny)ã®æ±ºå®ãè¿ãã¾ãã - Lambdaãªã¼ã½ã©ã¤ã¶ã¼ã®ã¬ã¹ãã³ã¹
Lambdaãªã¼ã½ã©ã¤ã¶ã¼ã¯Verified Permissionsããã®èªå¯çµæã«åºã¥ãã¦ãAPI Gatewayã«è¨±å¯(Allow)ã¾ãã¯æå¦(Deny)ã®ã¬ã¹ãã³ã¹ãè¿ãã¾ãã - Amazon API Gatewayã®æçµå¦ç
API Gatewayã¯ãLambdaãªã¼ã½ã©ã¤ã¶ã¼ã®çµæã«åºã¥ãã¦ãã¼ã¿ãè¿ãããACCESS_DENIEDã¬ã¹ãã³ã¹ãè¿ãã¾ãã
- ã¦ã¼ã¶ã¼èªè¨¼(Amazon Cognito User Pools)
Amazon API Gatewayã®èªè¨¼ã»èªå¯ã§ä½¿ç¨ããå ´åã®å©ç¹
Amazon API Gatewayã®èªè¨¼ã»èªå¯ã§ä½¿ç¨ããå ´åã®å©ç¹ã«ã¯æ¬¡ã®ãããªãã®ãæãããã¾ãã- ã»ãã¥ã¢ãªèªè¨¼
Amazon Cognito User Pools ã®å ç¢ãªèªè¨¼ã¡ã«ããºã ãå©ç¨ã§ãã¾ãã
å¤è¦ç´ èªè¨¼ãã½ã¼ã·ã£ã« ID ãããã¤ãã¨ã®çµ±åãªã©ã®æ©è½ãæ´»ç¨ã§ãã¾ãã - ããç´°ããèªå¯å¶å¾¡
Amazon Verified Permissions ã使ç¨ãã¦ã詳細ãªèªå¯ã«ã¼ã«ãå®ç¾©ã§ãã¾ãã
ã¦ã¼ã¶ã¼å±æ§ã»ã°ã«ã¼ãæå±ã»ãªã¯ã¨ã¹ãã³ã³ããã¹ããªã©ã«åºã¥ãèªå¯ãå¯è½ã§ãã - æè»ãªããªã·ã¼ç®¡ç
Cedar Policy Language ã使ç¨ãã¦ãè¤éãªèªå¯ãã¸ãã¯ã表ç¾ã§ãã¾ãã
ããªã·ã¼ã®ä¸å¤®ç®¡çãå¯è½ã§ãä¸è²«ããèªå¯ã«ã¼ã«ãé©ç¨ã§ãã¾ãã - ã¹ã±ã¼ã©ããªãã£ã¨ããã©ã¼ãã³ã¹
API Gatewayã»Cognitoã»Verified Permissionsã¯ãã¹ã¦ããã¼ã¸ããµã¼ãã¹ã§ãããé«ãã¹ã±ã¼ã©ããªãã£ãæä¾ãã¾ãã
Lambda ãªã¼ã½ã©ã¤ã¶ã¼ã使ç¨ãããã¨ã§ãèªè¨¼ã»èªå¯ã®ãã¸ãã¯ãã«ã¹ã¿ãã¤ãºã§ãã¾ãã - ã»ãã¥ãªãã£ã®åä¸
èªè¨¼ã¨èªå¯ãåé¢ãããã¨ã§ãããã»ãã¥ã¢ãªã¢ã¼ããã¯ãã£ãå®ç¾ã§ãã¾ãã
ãã¼ã¯ã³ãã¼ã¹ã®èªè¨¼ã«ãããã¹ãã¼ãã¬ã¹ã§å®å ¨ãªéä¿¡ãå¯è½ã§ãã - éçºå¹çã®åä¸
èªè¨¼ã»èªå¯ãã¸ãã¯ãã¢ããªã±ã¼ã·ã§ã³ã³ã¼ãããåé¢ã§ãã¾ãã
ããã¼ã¸ããµã¼ãã¹ã使ç¨ãããã¨ã§ãéçºè ã¯æ¬è³ªçãªãã¸ãã¹ãã¸ãã¯ã«éä¸ã§ãã¾ãã
- ã»ãã¥ã¢ãªèªè¨¼
ãã®ãããªãAmazon Cognito User Poolsã¨Amazon Verified Permissionsã®çµ±åãããã³Amazon API Gatewayãªã©ã®AWSãµã¼ãã¹ã§ã®ä½¿ç¨ã«ãã£ã¦ãAmazon Cognito User Poolsã®å¼·åãªèªè¨¼æ©è½ã¨Amazon Verified Permissionsã®æè»ãªèªå¯æ©è½ãçµã¿åãããã»ãã¥ã¢ã§ç®¡çããããã¢ã¯ã»ã¹å¶å¾¡ãå®ç¾ã§ãã¾ãã
Amazon Cognito Identity Poolsã¨Amazon Verified Permissionsã®å½¹å²ã¨ç¨éã®éã
Amazon Cognito Identity Poolsã¨Amazon Verified Permissionsã¯ãã©ã¡ããAmazon Cognito User Poolsã§èªè¨¼ããå¾ã®èªå¯æ©è½ãæä¾ãã¦ãã¾ãã
ããããããããã®å½¹å²ã¨ç¨éã«ã¯æ¬¡ã®ãããªéããããã¾ãã
é ç® | Amazon Cognito Identity Pools | Amazon Verified Permissions |
---|---|---|
主ãªå½¹å² | AWSãµã¼ãã¹ã¸ã®ä¸æçãªã¢ã¯ã»ã¹æ¨©éã®ä»ä¸ | ããç´°ããã¢ããªã±ã¼ã·ã§ã³ã¬ãã«ã®èªå¯ |
ç¹å¾´ |
|
|
使ç¨ä¾ | ã¢ãã¤ã«ã¢ããªããS3ãã±ããã«ç´æ¥ã¢ã¯ã»ã¹ããå ´åãªã© | è¤éãªçµç¹æ§é ãæã¤ã¢ããªã±ã¼ã·ã§ã³ã§ã®æ¨©é管çãåçãªã¢ã¯ã»ã¹å¶å¾¡ãå¿ è¦ãªå ´åãªã© |
ã¹ã³ã¼ã | 主ã«AWSãµã¼ãã¹ã¸ã®ã¢ã¯ã»ã¹ã«ç¦ç¹ | ã¢ããªã±ã¼ã·ã§ã³åºæã®èªå¯ã«éç¹ |
ç²åº¦ | IAMãã¼ã«ãã¼ã¹ã®æ¯è¼çç²ãç²åº¦ã®å¶å¾¡ | ããç´°ããç²åº¦ã®å¶å¾¡ãå¯è½ |
å¶å¾¡ã®æè»æ§ | IAMããªã·ã¼ã«ããå¶å¾¡ | Cedarè¨èªã使ç¨ãã¦ããè¤éã§åçãªèªå¯ã«ã¼ã«ãå®ç¾©å¯è½ |
ã©ã¡ãã鏿ãããã¯å
·ä½çãªã¦ã¼ã¹ã±ã¼ã¹ã¨è¦ä»¶ã«ãã£ã¦ç°ãªããå ´åã«ãã£ã¦ã¯ä¸¡æ¹ãçµã¿åããã¦ä½¿ç¨ãããã¨ãå¯è½ã§ãã
ãããã®ãã¨ãããAWSãµã¼ãã¹ã¸ã®ã¢ã¯ã»ã¹å¶å¾¡ã主ãªç®çã§ããã°Amazon Cognito Identity Poolsããã¢ããªã±ã¼ã·ã§ã³åºæã®è¤éãªèªå¯ãã¸ãã¯ãå¿
è¦ãªå ´åã¯Amazon Verified Permissionsã鏿ããã®ãããã§ãããã
ï¼åèè³æï¼
AWS Documentation(Amazon Cognito)
[AWS Black Belt Online Seminar]Amazon Cognito
Tech Blog with related articles referenced
ã¾ã¨ã
ä»åã¯Amazon Cognitoã®æ´å²å¹´è¡¨ã使ãã¦ãAmazon Cognitoã®æ©è½ä¸è¦§ã¨æ¦è¦ãè¦ã¦ãã¾ããã
Amazon Cognitoã¯ã2014å¹´ã«ãµã¼ãã¹ãéå§ãã¦ä»¥æ¥ãã¦ã¼ã¶ã¼èªè¨¼ã¨èªå¯ã®è¤éããè§£æ¶ããã¢ããªã±ã¼ã·ã§ã³éçºè
ã«ã¨ã£ã¦å©ä¾¿æ§ã®é«ãã»ãã¥ãªãã£æ©è½ãæä¾ãç¶ãã¦ãã¾ãã
User Poolsã¯ããµã¤ã³ã¢ããã¨ãµã¤ã³ã¤ã³ã®ããã»ã¹ãç°¡ç´ åãã夿§ãªèªè¨¼ãªãã·ã§ã³ãæä¾ãããã¨ã§ãã¨ã³ãã¦ã¼ã¶ã¼ã«ã¨ã£ã¦ä½¿ããããèªè¨¼ä½é¨ãå®ç¾ãã¾ãã
䏿¹ãIdentity Poolsã¯èªè¨¼æ¸ã¿ããã³æªèªè¨¼ã®ã¦ã¼ã¶ã¼ã«ä¸æçãªAWSã¯ã¬ãã³ã·ã£ã«ãæä¾ããAWSãªã½ã¼ã¹ã¸ã®ã»ãã¥ã¢ãªã¢ã¯ã»ã¹ãèªå¯ãã¾ãã
ã¾ããä»ã¾ã§ã®10å¹´éã§Amazon Cognitoã¯å¤ãã®éè¦ãªã¢ãããã¼ããè¡ããã½ã¼ã·ã£ã«ãã°ã¤ã³ã®ãµãã¼ãã»ç®¡çãããã¦ã¼ã¶ã¼ãã£ã¬ã¯ããªã»ã¢ããªã±ã¼ã·ã§ã³ãã¼ã¿ã®åæã»ã»ãã¥ãªãã£ã®å¼·åã¨ãã£ãæ©è½ã段éçã«æ¡å¼µãã¦ãã¾ããã
ç¹ã«ãAmazon Verified Permissionsã¨ã®çµ±åãªã©ãæè¿ã®ã¢ãããã¼ãã§ã¯ã»ãã¥ãªãã£ã¨å©ä¾¿æ§ãããã«åä¸ãããæ©è½ãå°å
¥ãããå¾åãããã¾ãã
Amazon Cognitoã®ä»å¾ã®ååã¯ãå¼ãç¶ãã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£ã¨ã¦ã¼ã¶ã¼ããã¸ã¡ã³ãã®ãã¼ãºã«å¿ããæ©è½ã追å ããããã¨ãæå¾
ããã¾ãã
ä»å¾ãç¶ç¶çã«Amazon Cognitoãã©ã®ãããªæ©è½ãæä¾ãã¦ããã®ããã®ååãã¦ã©ãããã¦ããããã¨æãã¾ãã
ãªããä»åã®è¨äºã®è±èªçãAmazon Cognito以å¤ã®ãµã¼ãã¹ãå«ããAWSãµã¼ãã¹å
¨ä½ã®æ´å²å¹´è¡¨ãããã¾ãã®ã§ãèå³ãããã¾ããã御覧ãã ããã
- [English Edition] AWS History and Timeline regarding Amazon Cognito - Overview, Functions, Features, Summary of Updates, and Introduction
- æ´å²ã»å¹´è¡¨ã§ã¿ãAWSå ¨ãµã¼ãã¹ä¸è¦§ ï¼ã¢ãã¦ã³ã¹æ¥ãGeneral Availability(GA)ãAWSãµã¼ãã¹æ¦è¦ã®ã¾ã¨ãï¼
- [English Edition] AWS History and Timeline - Almost All AWS Services List, Announcements, General Availability(GA)