प्राधिकरण: IAM, Lambda Authorizers और Cognito
IAM SigV4 हस्ताक्षरों, कस्टम Lambda Authorizers या Amazon Cognito User Pool Authorizers से API एंडपॉइंट सुरक्षित कीजिए।
प्राधिकरण: IAM, Lambda Authorizers और Cognito, CoddyKit पर Cloud & IT Cert Prep का एक निःशुल्क पाठ है। यह 4 में से 3वाँ पाठ है। आप नीचे पूरा पाठ निःशुल्क पढ़ सकते हैं—फिर अंतर्निहित कोड संपादक और 24/7 एआई ट्यूटर के साथ ब्राउज़र में इसका व्यावहारिक अभ्यास कर सकते हैं। यह Cloud & IT Cert Prep सीखने के मार्ग का हिस्सा है और आपकी प्रगति वेब तथा CoddyKit ऐप पर सिंक होती रहती है। Cloud & IT Cert Prep पाठ्यक्रम में कुल 4 पाठ शामिल हैं।
API Authorization क्यों महत्वपूर्ण है
Authorisation controls के बिना कोई भी internet client आपके API Gateway endpoints को कॉल करके data तक पहुँच सकता है या उसे बदल सकता है। API Gateway तीन native authorisation mechanisms प्रदान करता है: IAM (SigV4), Lambda Authorisers और Amazon Cognito User Pool Authorisers। प्रत्येक mechanism अलग use case के लिए है: AWS service-to-service calls के लिए IAM, custom token या request-based auth के लिए Lambda authorisers, और web/mobile user authentication के लिए Cognito।
SigV4 के साथ IAM Authorization
IAM authorisation के लिए callers को AWS Signature Version 4 (SigV4) का उपयोग करके requests sign करनी होती हैं। Caller के पास AWS credentials (access key + secret key या STS से प्राप्त temporary credentials) होने चाहिए और IAM policy में API के ARN पर execute-api:Invoke की अनुमति होनी चाहिए। यह AWS के भीतर machine-to-machine (server-to-server) calls के लिए आदर्श है: Lambda द्वारा किसी अन्य API को कॉल करना, EC2 द्वारा internal API को कॉल करना, या cross-account service access। Browser clients के लिए SigV4 का उपयोग करना आसान नहीं है।
# IAM policy to allow invoking a specific API endpoint
{
'Version': '2012-10-17',
'Statement': [{
'Effect': 'Allow',
'Action': 'execute-api:Invoke',
'Resource': 'arn:aws:execute-api:us-east-1:123456789012:abc123/prod/GET/orders'
}]
}Lambda Authorizers: Token-Based
Lambda Authoriser (पहले Custom Authoriser कहलाता था) वह Lambda function है जिसे आप लिखते हैं और API Gateway backend integration को कॉल करने से पहले Invoke करता है। token-based authorisers के लिए API Gateway Authorization header से token (JWT, OAuth, API key) निकालकर आपके Lambda को भेजता है। आपका Lambda token को Validate करता है (जैसे public key से JWT signature verify करना या third-party identity provider को कॉल करना) और फिर ऐसा IAM policy document लौटाता है जो request को allow या deny करता है।
def lambda_handler(event, context):
token = event['authorizationToken']
# Validate token (JWT verification, introspect OAuth, etc.)
if is_valid_token(token):
return {
'principalId': 'user123',
'policyDocument': {
'Version': '2012-10-17',
'Statement': [{'Effect': 'Allow', 'Action': 'execute-api:Invoke',
'Resource': event['methodArn']}]
},
'context': {'userId': 'user123', 'role': 'admin'}
}
raise Exception('Unauthorized')Lambda Authorizers: Request-Based
request-based Lambda authorisers के लिए API Gateway केवल token ही नहीं, बल्कि पूरे request context (headers, query strings, stage variables, path parameters) को आपके Lambda तक भेजता है। यह उन authorisation प्रक्रियाओं के लिए उपयोगी है जो कई request attributes पर निर्भर करती हैं: IP allowlists, header combinations या multi-factor authentication checks। Request-based authorisers REST API और HTTP API दोनों में supported हैं।
Lambda Authorizer Caching
हर API request पर Lambda authoriser को कॉल करने से latency और cost बढ़ती है। authoriser result caching enable करें: authoriser द्वारा लौटाई गई IAM policy को configurable TTL (0–3600 seconds) तक token value के आधार पर cache करें। उसी token वाले बाद के requests Lambda invocation को छोड़कर cached policy का उपयोग करते हैं। TTL को token expiry time के अनुरूप रखें—यदि कोई token 1 hour तक valid है, तो authoriser result को भी उसी अवधि के लिए cache करें। Caching REST API में उपलब्ध है; HTTP API JWT authorisers में built-in caching होता है।
Amazon Cognito User Pool Authorizer
Cognito User Pool Authorisers Lambda function के बिना सीधे API Gateway में Cognito-issued JWTs को Validate करते हैं। जब कोई user Cognito के माध्यम से authenticate करता है (Hosted UI, SDK या federated identity provider के जरिए), तो Cognito ID token या access token जारी करता है। Client इस token को Authorization header में शामिल करता है। API Gateway Cognito User Pool के आधार पर token signature और expiry verify करता है। यदि token valid हो, तो request आगे बढ़ती है; अन्यथा API Gateway 401 लौटाता है।
aws apigateway create-authorizer \
--rest-api-id 'abc123' \
--name 'CognitoAuthorizer' \
--type COGNITO_USER_POOLS \
--provider-arns 'arn:aws:cognito-idp:us-east-1:123456789012:userpool/us-east-1_XXXXXXX' \
--identity-source 'method.request.header.Authorization'HTTP API में JWT Authorizer
HTTP API में Lambda के बिना native JWT authoriser support उपलब्ध है। आप JWT issuer URL (Cognito, Auth0, Okta) और audience specify करते हैं, और API Gateway JWTs को अपने-आप Validate करता है। यह मूलतः Cognito User Pool authoriser जैसा है, लेकिन standards-compliant किसी भी OIDC provider के साथ काम करता है। Token validation (signature, expiry, audience) API Gateway internally करता है—इसमें Lambda authorisers की तुलना में latency कम होती है और Lambda cost नहीं आती।
aws apigatewayv2 create-authorizer \
--api-id 'abc123' \
--authorizer-type JWT \
--name 'JWTAuthorizer' \
--identity-source '$request.header.Authorization' \
--jwt-configuration '{
"Issuer": "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_XXXXXXX",
"Audience": ["your-client-id"]
}'Cognito Identity Pools बनाम User Pools
API authorisation के लिए Cognito User Pools का उपयोग करें: ये user authentication manage करते हैं और JWTs जारी करते हैं। Cognito Identity Pools (Federated Identities) अलग होते हैं—ये third-party tokens (User Pools, social logins, SAML से प्राप्त) को temporary AWS credentials में बदलते हैं (STS AssumeRoleWithWebIdentity के माध्यम से)। Identity Pools का उपयोग तब किया जाता है जब आपके app को client से सीधे AWS services (S3, DynamoDB) तक पहुँच चाहिए। API Gateway auth के लिए User Pool JWTs सही विकल्प हैं; Identity Pool credentials browser/mobile से सीधे AWS SDK calls के लिए होते हैं।
API Gateway पर Resource Policies
REST APIs में resource policies supported हैं—ये API से attached JSON policies होती हैं, जो IP address, VPC endpoint, source account या ARN के आधार पर access control करती हैं। Resource policies का उपयोग इन कार्यों के लिए करें: केवल specific IP ranges को अपने API को कॉल करने की अनुमति देना, किसी specific VPC endpoint (private API) से आने वाले requests तक access सीमित करना, या cross-account invocations की अनुमति देना। Resource policies method-level authorisers के अतिरिक्त काम करती हैं—request के सफल होने के लिए दोनों का उसे allow करना आवश्यक है।
# Allow only specific IP range to call the API
{
'Version': '2012-10-17',
'Statement': [{
'Effect': 'Allow',
'Principal': '*',
'Action': 'execute-api:Invoke',
'Resource': 'arn:aws:execute-api:us-east-1:123456789012:abc123/*',
'Condition': {'IpAddress': {'aws:SourceIp': '203.0.113.0/24'}}
}]
}Mutual TLS Authentication
Mutual TLS (mTLS) में TLS handshake के दौरान client और server दोनों को certificates प्रस्तुत करने होते हैं। Custom domain names configure होने पर API Gateway REST और HTTP APIs के लिए mTLS support करता है। Clients को आपके द्वारा S3 के truststore में upload किए गए Certificate Authority (CA) से signed valid certificate प्रस्तुत करना आवश्यक है। mTLS का उपयोग financial services, IoT device authentication और B2B integrations में किया जाता है, जहाँ token-based auth से आगे बढ़कर मजबूत client identity verification आवश्यक होती है।
सही Authorizer Type चुनना
SAA-C03 exam के लिए authoriser चयन: IAM (SigV4) → समान या cross accounts के भीतर AWS service-to-service calls; Cognito User Pool → Cognito के माध्यम से authenticated web/mobile app users; Lambda Authoriser → custom auth logic (third-party identity providers, पुराने token formats, OAuth introspection, IP + token का संयुक्त उपयोग); JWT Authoriser (HTTP API) → किसी भी standards-compliant provider के OIDC/OAuth2 tokens, Lambda authorisers की तुलना में कम cost पर। कोई authoriser नहीं → public API।
त्वरित जाँच
इस lesson में बताए गए AWS Solutions Architect (SAA-C03) concepts की अपनी समझ जाँचें।
Lesson Recap
इस lesson में आपने सीखा: IAM (SigV4) authorisation AWS credentials का उपयोग करने वाली service-to-service calls के लिए है; Cognito User Pool Authorisers web और mobile apps के लिए Cognito-issued JWTs को native रूप से Validate करते हैं; और Lambda Authorisers third-party identity providers या complex authorisation logic के लिए custom token validation लागू करते हैं, जिसमें optional result caching उपलब्ध है। अब हम API Gateway में throttling, caching और usage plans का अध्ययन करेंगे।
एआई शिक्षक के साथ Cloud & IT Cert Prep सीखें — निःशुल्क
अपने ब्राउज़र में वास्तविक कोड लिखें और चलाएँ, चौबीसों घंटे एआई शिक्षक से तुरंत सहायता पाएँ, और वेब या ऐप पर वहीं से शुरू करें जहाँ आपने छोड़ा था।
- पाठ्यक्रम
- 150
- पाठ
- 600
अक्सर पूछे जाने वाले प्रश्न
क्या “प्राधिकरण: IAM, Lambda Authorizers और Cognito” पाठ निःशुल्क है?
हाँ—“प्राधिकरण: IAM, Lambda Authorizers और Cognito” का पूरा पाठ यहाँ वेब पर निःशुल्क पढ़ा जा सकता है। इंटरैक्टिव अभ्यास (अंतर्निहित कोड संपादक और 24/7 एआई ट्यूटर) करने और Cloud & IT Cert Prep पाठ्यक्रम का बाकी हिस्सा अनलॉक करने के लिए CoddyKit PRO लें। Cloud & IT Cert Prep पाठ्यक्रम में कुल 4 पाठ शामिल हैं।
“प्राधिकरण: IAM, Lambda Authorizers और Cognito” में मैं क्या सीखूँगा?
IAM SigV4 हस्ताक्षरों, कस्टम Lambda Authorizers या Amazon Cognito User Pool Authorizers से API एंडपॉइंट सुरक्षित कीजिए। आप ब्राउज़र में सीधे चलाए जाने वाले व्यावहारिक कोड के साथ Cloud & IT Cert Prep का अभ्यास करते हैं, और पाठ पूरा करते समय 24/7 एआई ट्यूटर आपके प्रश्नों के उत्तर देता है।
क्या Cloud & IT Cert Prep शुरू करने के लिए मुझे किसी अनुभव की आवश्यकता है?
पहले के अनुभव की आवश्यकता नहीं है। CoddyKit पर Cloud & IT Cert Prep शुरुआती से लेकर उन्नत शिक्षार्थियों तक सभी के लिए व्यवस्थित किया गया है, इसलिए आप यहीं से या शुरुआत से सीखना शुरू कर सकते हैं और अपनी गति से आगे बढ़ सकते हैं। यह 4 में से 3वाँ पाठ है।
“प्राधिकरण: IAM, Lambda Authorizers और Cognito” पाठ पूरा करने में कितना समय लगता है?
CoddyKit का अधिकांश पाठ लगभग 5–10 मिनट में पूरा हो जाता है। हर पाठ छोटा और संवादात्मक है, इसलिए आप लगातार प्रगति करते हैं और वेब या ऐप पर वहीं से सीखना जारी रख सकते हैं जहाँ आपने छोड़ा था।
क्या मैं इस Cloud & IT Cert Prep पाठ में कोड लिख और चला सकता हूँ?
हाँ। हर Cloud & IT Cert Prep पाठ में एक अंतर्निर्मित कोड संपादक शामिल है, जिससे आप सीधे अपने ब्राउज़र में वास्तविक कोड लिख और चला सकते हैं और तुरंत एआई प्रतिक्रिया पा सकते हैं—स्थानीय सेटअप की आवश्यकता नहीं है।
इस पाठ्यक्रम के सभी पाठ
- REST API बनाम HTTP API बनाम WebSocket API
- एकीकरण: Lambda, HTTP और मॉक
- प्राधिकरण: IAM, Lambda Authorizers और Cognito
- थ्रॉटलिंग, कैशिंग और उपयोग योजनाएँ