AWS ALB with cognito, map one to one between rule and user from cognito-userpool

Viewed 81

I have server applications running on ec2 machines and ALB above them that route the traffic to them. I must use host header rule to route the requests to the loadbalancer. For each rule I also add authentication with cognito.
I want that each user from cognito user-pool will be able to enter to one and only one specific instance (in other words, will be allowed to route to one rule) with its token returned from cognito.
Is there a way to do it?
Right now, I need to set all the possible URLs in the URL callback field of cognito and after log in of one user he can access all the other domains (thanks to his token) and I don't want this behavior.
After log with cognito user, a session cookie is created, but ALB does not distinguish between token values, and I can't specify user in the listener rule itself of the ALB to tell him what suppose to be the cookie value to allow the traffic to that rule (that instance).

Thank you and let me know if I need to clarify the problem.

0 Answers
Related