I am currently working on one project where it requires the custom authentication process. This application will be deployed on AWS platform, in which I am considering to use below AWS services like
- API Gateway
- Custom Authorization
- EKS
The plan is to deploy all backend services in the docker containers and use EKS service for container orchestration process.
All input request will be validated through API gateway and routed to the respective backend services.
We are going to use custom authorization process with below possible steps:
- Our application (say CHILD-APP) will be integrated with an existing application (say PARENT-APP), where the PARENT-APP will take care of the user authentication.
- On successful user authentication, the PARENT-APP will request the access token (JWT Token) to CHILD-APP.
- This access token will be used by CHILD-APP User Interface to make the backend request calls.
- We are using custom access token validation process to check the token integrity, the username validation and other additional validations (cannot be exposed due to compliances).
- Currently I am using the Spring Boot API Gateway for URL routings, and for access token validations.
- Also using custom Spring Cloud Eureka server to register the services.
Questions:
- How to use the AWS API Gateway for such custom authentication and authorization process?
- Can I use the Spring Cloud Eureka server and custom authorization along with the AWS API Gateway?
Any help related to this is appreciated.
Thanks,
Avinash