用户需求
创建用户池
创建身份池
创建ES
启用Amazon Cognito 身份验证
以管理员身份创建用户账户
创建用户组
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:sts::账号iD:assumed-role/Cognito_用户池Auth_Role/CognitoIdentityCredentials"
},
"Action": "es:ESHttp*",
"Resource": "arn:aws:es:us-east-1:账号iD:domain/es名称/*"
}
]
}
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"es:esHttp*"
],
"Resource": "arn:aws:es:region:账号ID:domain/es名称/*"
}
]
}
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Federated": "cognito-identity.amazonaws.com"
},
"Action": "sts:AssumeRoleWithWebIdentity"
}
]
}
编辑Cognito用户池中的用户组
修改Cognito身份池认证配置
Amazon Elasticsearch Service入门-使用Amazon Cognito进行Kibana访问控制
原文:https://www.cnblogs.com/zhanmeiliang/p/13193567.html