I have an amplify project with a an appsync graphql api set up through amplify-cli. The project has cognito user pools integration. My goal is to have a nodeJS script on an external server perform queries on my graphql api. My question is related to correct way to set up authentication for the schema...
An excerpt of a particular model my schema I would like to access:
type Phase @model @auth(rules: [
{allow: private, provider: iam}
{allow: groups, groups: ["companyAdmin"], provider: userPools},
{allow: groups, groups: ["extConnection"], operations: [create, read, update], provider: userPools},
{allow: groups, groupsField: "readGroups", operations: [create, read], provider: userPools},
{allow: groups, groupsField: "editGroups", provider: userPools}]) {
id: ID!
description: String
editGroups: [String]
readGroups: [String]
}
My confusion stems from reading documentation on how to call the app-sync client endpoint via the nodejs @aws-sdk v3.
Here it seems they are referring to using the connection profiles that have an iam access key id and secrey key: https://docs.aws.amazon.com/sdk-for-javascript/v2/developer-guide/loading-node-credentials-shared.html
If I create an IAM user and provide it the built in appsync access policies:
AWSAppSyncSchemaAuthor ::: AWS managed: Provides access to create, update, and query the schema.
AWSAppSyncPushToCloudWatchLogs ::: AWS managed: Allows AppSync to push logs to user's CloudWatch account.
and since my model has an auth rule for iam
{allow: private, provider: iam}
I should be able to allow a particular IAM role or user to access these by adding this user to the custom-roles.json on my amplify app configuration per (since the allow private iam line above apparently only allows iam requests from auto generated scoped down rules): https://docs.amplify.aws/cli/graphql/authorization-rules/#use-iam-authorization-within-the-appsync-console ....
However, this is not ideal because I have many other models in the schema that require IAM interaction from internal lambda functions for example, but now this IAM user would have access to any model that has allow:private provider: iam so therefore question...
- Can I have granular rules for the @auth directive IAM provider that limits access to a model only for a particular IAM user?
OR
- Or should I instead use a cognito user from one of my user pools, that has the group "extConnection" which would satisfy the auth rule on this model:
{allow: groups, groups: ["extConnection"], operations: [create, read, update], provider: userPools},
But then how would I build the the request for this via something like axios npm package to make the query? Will I need to create a REST API Gateway to handle this as a middleman between the external server and the graphql endpoint?