Skip to content

AWS Cognito

Goal

After completing this guide, your Amazon load balancer will work with the AWS ALB & Amazon Cognito Authentication app.


Prerequisites

This guide assumes the following:

  • You have setup a Jira or Confluence instance on AWS with an ALB or ELB load balancer

  • You have setup Amazon Cognito with your identity provider

  • A (trial) subscription for the AWS ALB Auth app

  • Admin access to your Atlassian product and AWS

Guide

  1. Go to the AWS ALB & Amazon Cognito Authentication configuration and click AWS Cognito.
    1 quick start.png

  2. This tutorial assumes that the username is sent in the x-amzn-oidc-data header via an claim called email. If that does not matches your setup, you can change the used header token via the Token Header Name option and the Username Claim.
    2 token name.png

  3. This app automatically checks the signature of the x-amzn-oidc-dataAdditionally, you can also check the issuer of this token, as well as Amazon Resource Name of the load balancer which sends the header. 
    3 security settings.png

    The Issuer is https://cognito-idp.<REGION>.amazonaws.com/<POOL Id> . You must replace <REGION> and <POOL Id> with the corresponding value for your Cognito configuration. 

    The ARN can be found in the Description tab of your Load Balancer in AWS.
    3 load balancer.png

  4. Finally, click Save to save the configuration.