Primer commit
This commit is contained in:
@@ -0,0 +1,62 @@
|
||||
# Environment and secrets
|
||||
.env
|
||||
.env.*
|
||||
credentials
|
||||
aws-credentials
|
||||
aws_session.json
|
||||
|
||||
# AWS keys and certificates
|
||||
*.pem
|
||||
*.key
|
||||
*.crt
|
||||
*.p12
|
||||
|
||||
# Amplify / Cognito / AWS Mobile
|
||||
amplify/
|
||||
# Preserve local Amplify config? ignore current cloud backend
|
||||
amplify/#current-cloud-backend/
|
||||
aws-exports.js
|
||||
aws-exports.ts
|
||||
aws-exports*.js
|
||||
aws-exports*.ts
|
||||
.aws-amplify/
|
||||
.awsmobile
|
||||
|
||||
# Serverless / SAM
|
||||
.serverless/
|
||||
.aws-sam/
|
||||
.aws-sam/build/
|
||||
|
||||
# IoT certificates / keys
|
||||
certs/
|
||||
private/
|
||||
*.jks
|
||||
|
||||
# Build artifacts
|
||||
dist/
|
||||
build/
|
||||
out/
|
||||
|
||||
# Node / Python
|
||||
node_modules/
|
||||
venv/
|
||||
.venv/
|
||||
__pycache__/
|
||||
*.py[cod]
|
||||
|
||||
# Terraform
|
||||
.terraform/
|
||||
*.tfstate
|
||||
*.tfstate.*
|
||||
crash.log
|
||||
|
||||
# Editor/OS
|
||||
.vscode/
|
||||
.idea/
|
||||
.DS_Store
|
||||
|
||||
# Misc
|
||||
coverage/
|
||||
npm-debug.log*
|
||||
yarn-debug.log*
|
||||
yarn-error.log*
|
||||
@@ -0,0 +1,104 @@
|
||||
iot-cognito
|
||||
=============
|
||||
|
||||
Resumen
|
||||
-------
|
||||
Este proyecto crea la infraestructura de identidad y autenticación para un proyecto IoT educativo usando Amazon Cognito.
|
||||
|
||||
El objetivo es proporcionar un User Pool y un App Client que puedan ser consumidos por otros proyectos (por ejemplo, una API y un frontend Vue) sin contener lógica de aplicación, Lambdas, APIs ni almacenamiento de datos.
|
||||
|
||||
Qué problema resuelve
|
||||
----------------------
|
||||
Proporciona una fuente centralizada de usuarios y credenciales (Cognito User Pool) y un App Client para una SPA (Vue) de modo que otras aplicaciones puedan autenticarse y validar JWTs emitidos por Cognito.
|
||||
|
||||
Recursos que crea
|
||||
-----------------
|
||||
- AWS::Cognito::UserPool (iot-dashboard-users)
|
||||
- AWS::Cognito::UserPoolClient (iot-dashboard-vue)
|
||||
|
||||
Ambos recursos incluyen tags para facilitar identificación (Project: iot-project, Component: cognito, Environment: dev).
|
||||
|
||||
Outputs
|
||||
-------
|
||||
El stack exporta los siguientes valores (Outputs + Exports):
|
||||
- UserPoolId
|
||||
- UserPoolClientId
|
||||
- UserPoolArn
|
||||
|
||||
Estos valores serán consumidos por los proyectos:
|
||||
- iot-lambda-dashboardApi
|
||||
- iot-front-dashboard
|
||||
|
||||
Validar el template
|
||||
-------------------
|
||||
Usar el validador de CloudFormation:
|
||||
|
||||
```bash
|
||||
aws cloudformation validate-template \
|
||||
--template-body file://template.yml
|
||||
```
|
||||
|
||||
Desplegar el stack
|
||||
------------------
|
||||
Desplegar con AWS CLI. Este template no crea roles ni recursos IAM nombrados, por lo que no es necesario pasar CAPABILITY_NAMED_IAM.
|
||||
|
||||
```bash
|
||||
aws cloudformation deploy \
|
||||
--template-file template.yml \
|
||||
--stack-name iot-cognito
|
||||
```
|
||||
|
||||
Si el despliegue falla por permisos relacionados con IAM (no esperado para este template), añadir la capability requerida:
|
||||
|
||||
```bash
|
||||
aws cloudformation deploy \
|
||||
--template-file template.yml \
|
||||
--stack-name iot-cognito \
|
||||
--capabilities CAPABILITY_NAMED_IAM
|
||||
```
|
||||
|
||||
Obtener los Outputs
|
||||
-------------------
|
||||
Para ver los Outputs directamente desde el stack:
|
||||
|
||||
```bash
|
||||
aws cloudformation describe-stacks \
|
||||
--stack-name iot-cognito \
|
||||
--query "Stacks[0].Outputs" --output table
|
||||
```
|
||||
|
||||
O listar los Exports (útil si otro stack los importa):
|
||||
|
||||
```bash
|
||||
aws cloudformation list-exports --query "Exports[?starts_with(Name, 'iot-cognito')]==[] || Exports" --output table
|
||||
```
|
||||
|
||||
Eliminar el stack
|
||||
-----------------
|
||||
|
||||
```bash
|
||||
aws cloudformation delete-stack --stack-name iot-cognito
|
||||
```
|
||||
|
||||
Notas de uso
|
||||
------------
|
||||
- El App Client creado es público (GenerateSecret: false) y está pensado para una SPA (Vue). No se incluye client secret.
|
||||
- No se crean Lambdas, API Gateway, S3, DynamoDB ni otros recursos fuera del alcance de identidad/usuario.
|
||||
- Mantener este proyecto simple y didáctico facilita que los alumnos entiendan Cognito: User Pools, App Clients, credenciales y JWTs.
|
||||
|
||||
Cómo consumir los valores desde otros stacks
|
||||
-------------------------------------------
|
||||
En otros templates CloudFormation se puede usar `Fn::ImportValue` con los nombres exportados. Por ejemplo:
|
||||
|
||||
```yaml
|
||||
Parameters:
|
||||
CognitoUserPoolId:
|
||||
Type: String
|
||||
Default: !ImportValue "iot-cognito-UserPoolId"
|
||||
```
|
||||
|
||||
Ajustar el nombre del export si el stack se despliega con otro nombre distinto a `iot-cognito`.
|
||||
|
||||
Contacto
|
||||
--------
|
||||
Proyecto educativo preparado para ser utilizado por los ejercicios de la materia.
|
||||
@@ -0,0 +1,68 @@
|
||||
AWSTemplateFormatVersion: '2010-09-09'
|
||||
Description: >-
|
||||
AWS Cognito infrastructure for the IoT Dashboard project.
|
||||
Creates a Cognito User Pool and a public App Client for a Vue SPA.
|
||||
|
||||
Resources:
|
||||
IotDashboardUserPool:
|
||||
Type: AWS::Cognito::UserPool
|
||||
Properties:
|
||||
UserPoolName: iot-dashboard-users
|
||||
AutoVerifiedAttributes:
|
||||
- email
|
||||
UsernameAttributes:
|
||||
- email
|
||||
MfaConfiguration: OFF
|
||||
Policies:
|
||||
PasswordPolicy:
|
||||
MinimumLength: 8
|
||||
RequireUppercase: false
|
||||
RequireNumbers: false
|
||||
RequireSymbols: false
|
||||
AdminCreateUserConfig:
|
||||
AllowAdminCreateUserOnly: false
|
||||
Tags:
|
||||
- Key: Project
|
||||
Value: iot-project
|
||||
- Key: Component
|
||||
Value: cognito
|
||||
- Key: Environment
|
||||
Value: dev
|
||||
|
||||
IotDashboardUserPoolClient:
|
||||
Type: AWS::Cognito::UserPoolClient
|
||||
Properties:
|
||||
ClientName: iot-dashboard-vue
|
||||
GenerateSecret: false
|
||||
UserPoolId: !Ref IotDashboardUserPool
|
||||
ExplicitAuthFlows:
|
||||
- ALLOW_USER_PASSWORD_AUTH
|
||||
- ALLOW_REFRESH_TOKEN_AUTH
|
||||
- ALLOW_USER_SRP_AUTH
|
||||
PreventUserExistenceErrors: ENABLED
|
||||
Tags:
|
||||
- Key: Project
|
||||
Value: iot-project
|
||||
- Key: Component
|
||||
Value: cognito
|
||||
- Key: Environment
|
||||
Value: dev
|
||||
|
||||
Outputs:
|
||||
UserPoolId:
|
||||
Description: Cognito User Pool ID (iot-dashboard-users)
|
||||
Value: !Ref IotDashboardUserPool
|
||||
Export:
|
||||
Name: !Sub "${AWS::StackName}-UserPoolId"
|
||||
|
||||
UserPoolClientId:
|
||||
Description: Cognito User Pool App Client ID (iot-dashboard-vue)
|
||||
Value: !Ref IotDashboardUserPoolClient
|
||||
Export:
|
||||
Name: !Sub "${AWS::StackName}-UserPoolClientId"
|
||||
|
||||
UserPoolArn:
|
||||
Description: ARN of the Cognito User Pool
|
||||
Value: !GetAtt IotDashboardUserPool.Arn
|
||||
Export:
|
||||
Name: !Sub "${AWS::StackName}-UserPoolArn"
|
||||
Reference in New Issue
Block a user