Add Cognito User Pool modules: pool, client, domain, and managed login branding - #2412
Add Cognito User Pool modules: pool, client, domain, and managed login branding#2412jonpspri wants to merge 2 commits into
Conversation
Docs Build 📝Thank you for contribution!✨ The docsite for this PR is available for download as an artifact from this run: You can compare to the docs for the File changes:
Click to see the diff comparison.NOTE: only file modifications are shown here. New and deleted files are excluded. diff --git a/home/runner/work/community.aws/community.aws/docsbuild/base/collections/community/aws/codepipeline_module.html b/home/runner/work/community.aws/community.aws/docsbuild/head/collections/community/aws/codepipeline_module.html
index 6475cd3..0986edf 100644
--- a/home/runner/work/community.aws/community.aws/docsbuild/base/collections/community/aws/codepipeline_module.html
+++ b/home/runner/work/community.aws/community.aws/docsbuild/head/collections/community/aws/codepipeline_module.html
@@ -22,7 +22,7 @@
<script src="../../../_static/sphinx_highlight.js?v=6ffebe34"></script>
<script src="../../../_static/js/theme.js"></script>
<link rel="search" title="Search" href="../../../search.html" />
- <link rel="next" title="community.aws.config_aggregation_authorization module – Manage cross-account AWS Config authorizations" href="config_aggregation_authorization_module.html" />
+ <link rel="next" title="community.aws.cognito_managed_login_branding module – Manage AWS Cognito Managed Login Branding styles" href="cognito_managed_login_branding_module.html" />
<link rel="prev" title="community.aws.codecommit_repository module – Manage repositories in AWS CodeCommit" href="codecommit_repository_module.html" /><!-- extra head elements for Ansible beyond RTD Sphinx Theme -->
@@ -570,7 +570,7 @@ see <a class="reference internal" href="#ansible-collections-community-aws-codep
<footer><div class="rst-footer-buttons" role="navigation" aria-label="Footer">
<a href="codecommit_repository_module.html" class="btn btn-neutral float-left" title="community.aws.codecommit_repository module – Manage repositories in AWS CodeCommit" accesskey="p" rel="prev"><span class="fa fa-arrow-circle-left" aria-hidden="true"></span> Previous</a>
- <a href="config_aggregation_authorization_module.html" class="btn btn-neutral float-right" title="community.aws.config_aggregation_authorization module – Manage cross-account AWS Config authorizations" accesskey="n" rel="next">Next <span class="fa fa-arrow-circle-right" aria-hidden="true"></span></a>
+ <a href="cognito_managed_login_branding_module.html" class="btn btn-neutral float-right" title="community.aws.cognito_managed_login_branding module – Manage AWS Cognito Managed Login Branding styles" accesskey="n" rel="next">Next <span class="fa fa-arrow-circle-right" aria-hidden="true"></span></a>
</div>
<hr/>
diff --git a/home/runner/work/community.aws/community.aws/docsbuild/base/collections/community/aws/config_aggregation_authorization_module.html b/home/runner/work/community.aws/community.aws/docsbuild/head/collections/community/aws/config_aggregation_authorization_module.html
index c3e2b58..77b1ac8 100644
--- a/home/runner/work/community.aws/community.aws/docsbuild/base/collections/community/aws/config_aggregation_authorization_module.html
+++ b/home/runner/work/community.aws/community.aws/docsbuild/head/collections/community/aws/config_aggregation_authorization_module.html
@@ -23,7 +23,7 @@
<script src="../../../_static/js/theme.js"></script>
<link rel="search" title="Search" href="../../../search.html" />
<link rel="next" title="community.aws.config_aggregator module – Manage AWS Config aggregations across multiple accounts" href="config_aggregator_module.html" />
- <link rel="prev" title="community.aws.codepipeline module – Create or delete AWS CodePipelines" href="codepipeline_module.html" /><!-- extra head elements for Ansible beyond RTD Sphinx Theme -->
+ <link rel="prev" title="community.aws.cognito_user_pool_info module – Retrieve information about an AWS Cognito User Pool" href="cognito_user_pool_info_module.html" /><!-- extra head elements for Ansible beyond RTD Sphinx Theme -->
@@ -367,7 +367,7 @@ see <a class="reference internal" href="#ansible-collections-community-aws-confi
<footer><div class="rst-footer-buttons" role="navigation" aria-label="Footer">
- <a href="codepipeline_module.html" class="btn btn-neutral float-left" title="community.aws.codepipeline module – Create or delete AWS CodePipelines" accesskey="p" rel="prev"><span class="fa fa-arrow-circle-left" aria-hidden="true"></span> Previous</a>
+ <a href="cognito_user_pool_info_module.html" class="btn btn-neutral float-left" title="community.aws.cognito_user_pool_info module – Retrieve information about an AWS Cognito User Pool" accesskey="p" rel="prev"><span class="fa fa-arrow-circle-left" aria-hidden="true"></span> Previous</a>
<a href="config_aggregator_module.html" class="btn btn-neutral float-right" title="community.aws.config_aggregator module – Manage AWS Config aggregations across multiple accounts" accesskey="n" rel="next">Next <span class="fa fa-arrow-circle-right" aria-hidden="true"></span></a>
</div>
diff --git a/home/runner/work/community.aws/community.aws/docsbuild/base/collections/community/aws/index.html b/home/runner/work/community.aws/community.aws/docsbuild/head/collections/community/aws/index.html
index 7f63cd4..6a1f41e 100644
--- a/home/runner/work/community.aws/community.aws/docsbuild/base/collections/community/aws/index.html
+++ b/home/runner/work/community.aws/community.aws/docsbuild/head/collections/community/aws/index.html
@@ -205,6 +205,14 @@
<li><p><a class="reference internal" href="codebuild_project_module.html#ansible-collections-community-aws-codebuild-project-module"><span class="std std-ref">codebuild_project module</span></a> – Create or delete an AWS CodeBuild project</p></li>
<li><p><a class="reference internal" href="codecommit_repository_module.html#ansible-collections-community-aws-codecommit-repository-module"><span class="std std-ref">codecommit_repository module</span></a> – Manage repositories in AWS CodeCommit</p></li>
<li><p><a class="reference internal" href="codepipeline_module.html#ansible-collections-community-aws-codepipeline-module"><span class="std std-ref">codepipeline module</span></a> – Create or delete AWS CodePipelines</p></li>
+<li><p><a class="reference internal" href="cognito_managed_login_branding_module.html#ansible-collections-community-aws-cognito-managed-login-branding-module"><span class="std std-ref">cognito_managed_login_branding module</span></a> – Manage AWS Cognito Managed Login Branding styles</p></li>
+<li><p><a class="reference internal" href="cognito_managed_login_branding_info_module.html#ansible-collections-community-aws-cognito-managed-login-branding-info-module"><span class="std std-ref">cognito_managed_login_branding_info module</span></a> – Retrieve information about AWS Cognito Managed Login Branding styles</p></li>
+<li><p><a class="reference internal" href="cognito_user_pool_module.html#ansible-collections-community-aws-cognito-user-pool-module"><span class="std std-ref">cognito_user_pool module</span></a> – Manage AWS Cognito User Pools</p></li>
+<li><p><a class="reference internal" href="cognito_user_pool_client_module.html#ansible-collections-community-aws-cognito-user-pool-client-module"><span class="std std-ref">cognito_user_pool_client module</span></a> – Manage AWS Cognito User Pool Clients</p></li>
+<li><p><a class="reference internal" href="cognito_user_pool_client_info_module.html#ansible-collections-community-aws-cognito-user-pool-client-info-module"><span class="std std-ref">cognito_user_pool_client_info module</span></a> – Retrieve information about AWS Cognito User Pool Clients</p></li>
+<li><p><a class="reference internal" href="cognito_user_pool_domain_module.html#ansible-collections-community-aws-cognito-user-pool-domain-module"><span class="std std-ref">cognito_user_pool_domain module</span></a> – Manage AWS Cognito User Pool domains</p></li>
+<li><p><a class="reference internal" href="cognito_user_pool_domain_info_module.html#ansible-collections-community-aws-cognito-user-pool-domain-info-module"><span class="std std-ref">cognito_user_pool_domain_info module</span></a> – Retrieve information about an AWS Cognito User Pool domain</p></li>
+<li><p><a class="reference internal" href="cognito_user_pool_info_module.html#ansible-collections-community-aws-cognito-user-pool-info-module"><span class="std std-ref">cognito_user_pool_info module</span></a> – Retrieve information about an AWS Cognito User Pool</p></li>
<li><p><a class="reference internal" href="config_aggregation_authorization_module.html#ansible-collections-community-aws-config-aggregation-authorization-module"><span class="std std-ref">config_aggregation_authorization module</span></a> – Manage cross-account AWS Config authorizations</p></li>
<li><p><a class="reference internal" href="config_aggregator_module.html#ansible-collections-community-aws-config-aggregator-module"><span class="std std-ref">config_aggregator module</span></a> – Manage AWS Config aggregations across multiple accounts</p></li>
<li><p><a class="reference internal" href="config_delivery_channel_module.html#ansible-collections-community-aws-config-delivery-channel-module"><span class="std std-ref">config_delivery_channel module</span></a> – Manage AWS Config delivery channels</p></li>
diff --git a/home/runner/work/community.aws/community.aws/docsbuild/base/collections/index_module.html b/home/runner/work/community.aws/community.aws/docsbuild/head/collections/index_module.html
index 70b206e..c18a6ee 100644
--- a/home/runner/work/community.aws/community.aws/docsbuild/base/collections/index_module.html
+++ b/home/runner/work/community.aws/community.aws/docsbuild/head/collections/index_module.html
@@ -148,6 +148,14 @@
<li><p><a class="reference internal" href="community/aws/codebuild_project_module.html#ansible-collections-community-aws-codebuild-project-module"><span class="std std-ref">community.aws.codebuild_project</span></a> – Create or delete an AWS CodeBuild project</p></li>
<li><p><a class="reference internal" href="community/aws/codecommit_repository_module.html#ansible-collections-community-aws-codecommit-repository-module"><span class="std std-ref">community.aws.codecommit_repository</span></a> – Manage repositories in AWS CodeCommit</p></li>
<li><p><a class="reference internal" href="community/aws/codepipeline_module.html#ansible-collections-community-aws-codepipeline-module"><span class="std std-ref">community.aws.codepipeline</span></a> – Create or delete AWS CodePipelines</p></li>
+<li><p><a class="reference internal" href="community/aws/cognito_managed_login_branding_module.html#ansible-collections-community-aws-cognito-managed-login-branding-module"><span class="std std-ref">community.aws.cognito_managed_login_branding</span></a> – Manage AWS Cognito Managed Login Branding styles</p></li>
+<li><p><a class="reference internal" href="community/aws/cognito_managed_login_branding_info_module.html#ansible-collections-community-aws-cognito-managed-login-branding-info-module"><span class="std std-ref">community.aws.cognito_managed_login_branding_info</span></a> – Retrieve information about AWS Cognito Managed Login Branding styles</p></li>
+<li><p><a class="reference internal" href="community/aws/cognito_user_pool_module.html#ansible-collections-community-aws-cognito-user-pool-module"><span class="std std-ref">community.aws.cognito_user_pool</span></a> – Manage AWS Cognito User Pools</p></li>
+<li><p><a class="reference internal" href="community/aws/cognito_user_pool_client_module.html#ansible-collections-community-aws-cognito-user-pool-client-module"><span class="std std-ref">community.aws.cognito_user_pool_client</span></a> – Manage AWS Cognito User Pool Clients</p></li>
+<li><p><a class="reference internal" href="community/aws/cognito_user_pool_client_info_module.html#ansible-collections-community-aws-cognito-user-pool-client-info-module"><span class="std std-ref">community.aws.cognito_user_pool_client_info</span></a> – Retrieve information about AWS Cognito User Pool Clients</p></li>
+<li><p><a class="reference internal" href="community/aws/cognito_user_pool_domain_module.html#ansible-collections-community-aws-cognito-user-pool-domain-module"><span class="std std-ref">community.aws.cognito_user_pool_domain</span></a> – Manage AWS Cognito User Pool domains</p></li>
+<li><p><a class="reference internal" href="community/aws/cognito_user_pool_domain_info_module.html#ansible-collections-community-aws-cognito-user-pool-domain-info-module"><span class="std std-ref">community.aws.cognito_user_pool_domain_info</span></a> – Retrieve information about an AWS Cognito User Pool domain</p></li>
+<li><p><a class="reference internal" href="community/aws/cognito_user_pool_info_module.html#ansible-collections-community-aws-cognito-user-pool-info-module"><span class="std std-ref">community.aws.cognito_user_pool_info</span></a> – Retrieve information about an AWS Cognito User Pool</p></li>
<li><p><a class="reference internal" href="community/aws/config_aggregation_authorization_module.html#ansible-collections-community-aws-config-aggregation-authorization-module"><span class="std std-ref">community.aws.config_aggregation_authorization</span></a> – Manage cross-account AWS Config authorizations</p></li>
<li><p><a class="reference internal" href="community/aws/config_aggregator_module.html#ansible-collections-community-aws-config-aggregator-module"><span class="std std-ref">community.aws.config_aggregator</span></a> – Manage AWS Config aggregations across multiple accounts</p></li>
<li><p><a class="reference internal" href="community/aws/config_delivery_channel_module.html#ansible-collections-community-aws-config-delivery-channel-module"><span class="std std-ref">community.aws.config_delivery_channel</span></a> – Manage AWS Config delivery channels</p></li>
|
There was a problem hiding this comment.
Pull request overview
This PR adds new Cognito-focused Ansible modules to the collection (user pool client management, user pool introspection, and managed login branding management) along with integration coverage and supporting metadata/constraints updates.
Changes:
- Added new modules:
cognito_userpoolclient,cognito_user_pool_info, andcognito_managed_login_branding. - Added integration tests for the new modules, including check_mode/idempotency/partial-update scenarios.
- Updated collection metadata (
meta/runtime.yml) and test constraints/changelog fragment for boto dependency minimums.
Reviewed changes
Copilot reviewed 22 out of 22 changed files in this pull request and generated 5 comments.
Show a summary per file
| File | Description |
|---|---|
| tests/integration/targets/cognito_userpoolclient/tasks/main.yml | Integration test entrypoint for user pool client + info scenarios. |
| tests/integration/targets/cognito_userpoolclient/tasks/01_prerequisites.yml | Creates a Cognito user pool used by the integration tests. |
| tests/integration/targets/cognito_userpoolclient/tasks/10_user_pool_info.yml | Exercises the new cognito_user_pool_info info module. |
| tests/integration/targets/cognito_userpoolclient/tasks/20_userpoolclient.yml | Core CRUD/check_mode/idempotency tests for cognito_userpoolclient. |
| tests/integration/targets/cognito_userpoolclient/tasks/30_additional_params.yml | Additional parameter coverage (token validity, units merge, clearing lists). |
| tests/integration/targets/cognito_userpoolclient/tasks/99_cleanup.yml | Cleanup of created Cognito clients/pool. |
| tests/integration/targets/cognito_userpoolclient/defaults/main.yml | Default names for pool/client resources in tests. |
| tests/integration/targets/cognito_userpoolclient/meta/main.yml | Integration target metadata. |
| tests/integration/targets/cognito_userpoolclient/aliases | Declares which integration aliases/targets to run. |
| tests/integration/targets/cognito_managed_login_branding/tasks/main.yml | Integration test entrypoint with botocore feature gate. |
| tests/integration/targets/cognito_managed_login_branding/tasks/01_prerequisites.yml | Creates ESSENTIALS-tier pool + domain + app client required for branding APIs. |
| tests/integration/targets/cognito_managed_login_branding/tasks/10_branding.yml | CRUD/check_mode/validation/return_merged_resources coverage for branding module. |
| tests/integration/targets/cognito_managed_login_branding/tasks/99_cleanup.yml | Cleanup for branding resources, client, domain, and pool. |
| tests/integration/targets/cognito_managed_login_branding/defaults/main.yml | Default names and domain prefix sanitization for tests. |
| tests/integration/targets/cognito_managed_login_branding/meta/main.yml | Integration target metadata. |
| tests/integration/targets/cognito_managed_login_branding/aliases | Declares which integration alias/target to run. |
| tests/integration/constraints.txt | Updates the “oldest supported” integration dependency pins. |
| plugins/modules/cognito_userpoolclient.py | New module implementing create/update/delete for user pool app clients with partial-update preservation. |
| plugins/modules/cognito_user_pool_info.py | New info module exposing detailed user pool configuration via DescribeUserPool. |
| plugins/modules/cognito_managed_login_branding.py | New module managing managed-login branding (settings/assets/defaults, merged reads). |
| meta/runtime.yml | Registers new modules in the collection action group list. |
| changelogs/fragments/bump-boto-dependencies.yml | Changelog fragment documenting dependency minimum bumps. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Build failed. ✔️ ansible-galaxy-importer SUCCESS in 3m 49s (non-voting) |
7e279b7 to
9e6aa68
Compare
|
Build failed. ✔️ ansible-galaxy-importer SUCCESS in 5m 07s (non-voting) |
|
Build failed. ✔️ ansible-galaxy-importer SUCCESS in 5m 10s (non-voting) |
|
Build failed. ✔️ ansible-galaxy-importer SUCCESS in 3m 51s (non-voting) |
…n branding New modules: - cognito_user_pool: create/update/delete user pools with full field preservation on partial updates (deep merge for nested params) - cognito_user_pool_info: read-only user pool lookup - cognito_user_pool_client: create/update/delete app clients with duplicate name detection and field preservation on updates - cognito_user_pool_client_info: lookup by client_id, name, or list all - cognito_user_pool_domain: create/update/delete user pool domains with pool-ID mismatch validation - cognito_user_pool_domain_info: read-only domain lookup - cognito_managed_login_branding: create/update/delete managed login branding with support for custom settings, assets, and Cognito defaults - cognito_managed_login_branding_info: read-only branding lookup All modules registered in meta/runtime.yml action_groups.aws. Integration tests for all four targets and unit tests for deep merge, domain pool-ID mismatch, and client duplicate name detection.
|
Build failed. ✔️ ansible-galaxy-importer SUCCESS in 3m 55s (non-voting) |
- Add choices to argument_spec for list params (auto_verified_attributes, alias_attributes, username_attributes, recovery_mechanisms.name) to match DOCUMENTATION - Add no_log=False to password_policy and temporary_password_validity_days to suppress false-positive secret detection - Remove unused imports in unit tests (pylint)
|
Build failed. ✔️ ansible-galaxy-importer SUCCESS in 5m 32s (non-voting) |
Summary
Adds 8 new Cognito modules with full integration and unit test coverage:
State modules (create/update/delete):
user_pool_idAnalyticsConfigurationandRefreshTokenRotation). Fails on ambiguous name-based lookups when duplicate client names existmanaged_login_versionsupport. Validates that existing domains belong to the requesteduser_pool_idbefore operatingreturn_merged_resourcesInfo modules (read-only):
user_pool_idclient_id,name, or list all clientsmanaged_login_branding_idorclient_idAll modules registered in
meta/runtime.ymlaction_groups.aws.Test plan
ansible-test integration cognito_user_pool— ok=85, changed=19ansible-test integration cognito_user_pool_client— ok=85, changed=18ansible-test integration cognito_user_pool_domain— ok=25, changed=6ansible-test integration cognito_managed_login_branding— ok=75, changed=16ansible-test units— 18 unit tests pass across Python 3.9–3.14_deep_mergecorrectness (sibling preservation, nested merge, immutability)ansible-test sanity— validate-modules, pep8