跳至内容

Migrating workloads from one AWS account to another

0

I want a seamless Cognito User Pool migration between AWS accounts, where users don’t have to reset passwords or re-register. Since Cognito does not natively support direct user export/import with passwords due to security design. Is there any best way to do with minimum downtime ?

1 回答
0

See whether this can help:

  1. Create a New User Pool in the Destination Account • Enable User Migration Lambda Trigger. • Ensure the new pool supports the same attributes and authentication flow (e.g., USER_PASSWORD_AUTH).
  2. Set Up a Lambda Function

o Authenticate the user against the old user pool. o Return user attributes to the new pool. o Create the user in the new pool without requiring password reset.

  1. Configure IAM Roles for Cross-Account Access • In the old account, create a role that allows: o cognito-idp:AdminInitiateAuth o cognito-idp:AdminGetUser o cognito-idp:ListUsers • Trust the Lambda execution role from the new account.
  2. Attach the Lambda to the New User Pool • Go to User Pool > Triggers > Migration. • Select your Lambda function.
专家

已回答 10 个月前

AWS
专家

已审核 10 个月前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。