Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Missing AWS Cognito Support #232

Closed
hashibot opened this issue Jun 13, 2017 · 29 comments
Closed

Missing AWS Cognito Support #232

hashibot opened this issue Jun 13, 2017 · 29 comments

Comments

@hashibot
Copy link

@hashibot hashibot commented Jun 13, 2017

This issue was originally opened by @BerndWessels as hashicorp/terraform#8309. It was migrated here as part of the provider split. The original body of the issue is below.


Hi there,

Terraform Version

0.7.0

Affected Resource(s)

  • aws

Expected Behavior

Support for AWS Cognito Identities and User Pools

Actual Behavior

Not supported yet

References

https://aws.amazon.com/cognito/

Question

Is anybody already working on this?

@nelg
Copy link

@nelg nelg commented Jul 24, 2017

Just wanted this, and found it missing from Terraform. Will try with cloud formation until it's available

@Ninir
Copy link
Contributor

@Ninir Ninir commented Jul 24, 2017

Hi @nelg

At the moment, only Identity pools are supported. I know that a few other people are working on resources (including me for roles attachment).

What is missing from your perspective?

@nelg
Copy link

@nelg nelg commented Jul 24, 2017

At the moment, my work around in cloudformation uses the following types:
AWS::Cognito::UserPool
AWS::Cognito::UserPoolClient

I think I will need
AWS::Cognito::IdentityPoolRoleAttachment

as well.

@et304383
Copy link

@et304383 et304383 commented Sep 7, 2017

I can't believe CloudFormation beat Terraform in the race to support user pools.

@Ninir
Copy link
Contributor

@Ninir Ninir commented Sep 8, 2017

Hey folks,

Will try to end the work on Cognito User pools very quickly, including all the current options provided by the API.
The one about IdentityPoolRoleAttachment is almost ended for me, the code is just crazy... so taking some time to review from another member :)

Please be patient a bit more: winter is Cognito User Pools are coming! 😄

@jch254
Copy link

@jch254 jch254 commented Oct 10, 2017

Any updates with this one? Cheers

@volkodava
Copy link

@volkodava volkodava commented Oct 23, 2017

Hi @ALL.

I would appreciate some guidance here from anyone who has managed to successfully configure lambda trigger for cognito user pool using terraform (http://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-identity-pools-working-with-aws-lambda-triggers.html).

@Ninir Do you know if User Pools are prod ready and has a configuration parameter for lambda trigger? How can I track a progress?

Much appreciated for your help.

@Ninir
Copy link
Contributor

@Ninir Ninir commented Oct 24, 2017

Hi folks,

Just to let you know that Cognito Identity Pool Roles Attachment has been merged yesterday: #863

Work is continuing for User Pools, hope to include it in the next AWS release 🚀

@volkodava Progress for user pools is here! :)

@radeksimko
Copy link
Member

@radeksimko radeksimko commented Oct 25, 2017

Also I have a branch ready with aws_cognito_user_pool_domain - the plan is to raise the PR after we merge @Ninir's #1419

@AndrewFarley
Copy link

@AndrewFarley AndrewFarley commented Oct 25, 2017

@Ninir I compiled and am trying out the merge as of today, it looks great in my initial tests. Cheers!

@jch254
Copy link

@jch254 jch254 commented Oct 26, 2017

Absolute champions!!

@m1keil
Copy link

@m1keil m1keil commented Oct 26, 2017

thank you very much for your hard work!

@et304383
Copy link

@et304383 et304383 commented Oct 31, 2017

Well since CloudFormation is a pile of garbage and won't let us configure alternative username attributes, full support for user pools would be critical to have in terraform.

@zsims
Copy link

@zsims zsims commented Nov 4, 2017

@et304383 please keep your personal opinion off here, thanks. Some of us are Keen to follow the progress of the issue.

@et304383
Copy link

@et304383 et304383 commented Nov 4, 2017

@zsims I am interested in the progress of this item as well. I'm expressing frustration with no automation tools fully supporting cognito.

It's not an opinion. Cognito support in CloudFormation is half complete so I'm looking forward to full support in Terraform.

@josselin-c
Copy link

@josselin-c josselin-c commented Nov 6, 2017

Is #1106 in the scope of this issue?

@jch254
Copy link

@jch254 jch254 commented Nov 10, 2017

Hey thanks for all the hard work, anyone have a rough estimate of how far off this is? Cheers

@Ninir
Copy link
Contributor

@Ninir Ninir commented Nov 16, 2017

Hi folks, User Pools are now available using the AWS Provider version 1.3.0!

To do so, upgrade your local binaries with: terraform init -upgrade.

Happy Terraforming! 🚀

@et304383
Copy link

@et304383 et304383 commented Nov 17, 2017

YAY!!!!!!!!!!!

@et304383
Copy link

@et304383 et304383 commented Nov 17, 2017

@Ninir is support for user pool clients next? I just encountered a roadblock on this... :(

@jch254
Copy link

@jch254 jch254 commented Nov 17, 2017

@Ninir absolute champion squad! I'm gonna give it a try now, tjx

@m1keil
Copy link

@m1keil m1keil commented Nov 19, 2017

A word of warning to everyone (maybe this should go in the docs?):

Some actions such as adding/removing attributes require re-creating the user pool. This will cause you to lose any existing users.

Be sure to guard against it with:

lifecycle {
    prevent_destroy = "true"
}
@et304383
Copy link

@et304383 et304383 commented Nov 19, 2017

@m1keil that is applicable to all resources. It's not specific to cognito user pools or this thread.

@Ninir
Copy link
Contributor

@Ninir Ninir commented Nov 20, 2017

Hi @et304383 !

#1803 is out and I'll review it after we release 1.3.1 (which contains some bug fixes regarding load balancers & IAM policies).

1.3.1 should come today or in the coming days :)

@tomelliff
Copy link
Contributor

@tomelliff tomelliff commented Jan 11, 2018

@et304383 Adding support for user pool app clients with #2874

I'm also working on user groups right now and then after those plus the fix to the IAM role attachment token validation is merged I think I can replace all my Cloudformation resources so that will probably be the end of the Cognito work I'm doing right now. Let me know if I'm missing anything else you think is important/critical.

@bflad
Copy link
Contributor

@bflad bflad commented Jan 12, 2018

The aws_cognito_user_pool_client and aws_cognito_user_pool_domain resources have been released in terraform-provider-aws version 1.7.0. Please see the Terraform documentation on provider versioning or reach out if you need any assistance upgrading.

@cooloon
Copy link

@cooloon cooloon commented Feb 6, 2018

Hi there,

Having resources for Cognito User Pools and Cognito Federated Identities, it's time to talk aboutCognito Sync, isn't it?

The edit page of Cognito Identity console looks like:

screenshot cognitosync

So the resouces for those configuration may be:

  • aws_cognito_sync_push_synchronization
  • aws_cognito_sync_stream
  • aws_cognito_sync_event

Developer Guide
https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-sync.html

CLI API
https://docs.aws.amazon.com/cli/latest/reference/cognito-sync/index.html

Go API
https://github.com/aws/aws-sdk-go/blob/master/service/cognitosync/cognitosynciface/interface.go

Is it reasonable to create a new exclusive issue for Cognito Sync ?

@bflad
Copy link
Contributor

@bflad bflad commented Mar 5, 2018

Is it reasonable to create a new exclusive issue for Cognito Sync ?

@cooloon Yes, please! In fact, I would suggest creating issues for each of the expected resources. 😄

That said, we're also getting to a point where its going to be hard to determine what the definition of done is for this issue. We have some new issues springing up:

  • Cognito Identity Provider support: #3279
  • Cognito Sync support: (pending above note 😉 )
  • aws_cognito_user_pool_resource_server support: #3616

I think is about time we close this nebulous ticket (for such a large AWS service) and create tickets for anything else specific that is missing. As of v1.9.0 of the AWS provider we support:

  • aws_cognito_identity_pool
  • aws_cognito_identity_pool_roles_attachment
  • aws_cognito_user_group
  • aws_cognito_user_pool
  • aws_cognito_user_pool_client
  • aws_cognito_user_pool_domain

Thanks everyone!

@bflad bflad closed this Mar 5, 2018
@hashibot
Copy link

@hashibot hashibot bot commented Apr 7, 2020

I'm going to lock this issue because it has been closed for 30 days . This helps our maintainers find and focus on the active issues.

If you feel this issue should be reopened, we encourage creating a new issue linking back to this one for added context. Thanks!

@hashibot hashibot locked and limited conversation to collaborators Apr 7, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
You can’t perform that action at this time.