You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Terraform中为HTTP API Gateway路由关联授权器?

Got it! Let me walk you through how to attach an authorizer to an HTTP API Gateway route in Terraform—it’s actually straightforward once you know which fields to use. Here’s a step-by-step breakdown with examples:

Step 1: Define Your HTTP API Gateway Authorizer

First, you’ll need to create the authorizer resource itself. This example uses a JWT authorizer, but the process works similarly for custom Lambda authorizers (just adjust the authorizer_type and related config):

resource "aws_apigatewayv2_authorizer" "example_jwt" {
  api_id           = aws_apigatewayv2_api.example.id # Link to your existing API
  name             = "my-jwt-authorizer"
  authorizer_type  = "JWT" # Use "CUSTOM" for Lambda authorizers
  identity_sources = ["$request.header.Authorization"] # Where to pull the auth token from

  # JWT-specific config (skip this block for custom authorizers)
  jwt_configuration {
    issuer   = "https://your-auth-provider.com/" # e.g., Auth0, Cognito
    audience = ["your-api-audience"]
  }
}
Step 2: Attach the Authorizer to Your Route

The key part is updating your route resource to reference the authorizer. You’ll need two critical fields:

  • authorization_type: Must exactly match your authorizer’s type (JWT/CUSTOM)
  • authorizer_id: The ID of the authorizer you created earlier

Here’s how that looks in a route definition:

resource "aws_apigatewayv2_route" "protected_route" {
  api_id    = aws_apigatewayv2_api.example.id
  route_key = "GET /protected-endpoint"
  target    = "integrations/${aws_apigatewayv2_integration.example.id}" # Link to your backend integration

  # Attach the authorizer here
  authorization_type = "JWT"
  authorizer_id      = aws_apigatewayv2_authorizer.example_jwt.id
}
Full Working Example (Including API and Integration)

To put it all together, here’s a complete snippet that creates the API, authorizer, integration, and protected route:

# Create the base HTTP API
resource "aws_apigatewayv2_api" "example" {
  name          = "my-http-api"
  protocol_type = "HTTP"
}

# Create a sample integration (e.g., proxy to an external backend)
resource "aws_apigatewayv2_integration" "example" {
  api_id           = aws_apigatewayv2_api.example.id
  integration_type = "HTTP_PROXY"
  integration_uri  = "https://api.example.com/backend"
}

# Define the JWT authorizer (using Cognito as an example)
resource "aws_apigatewayv2_authorizer" "example_jwt" {
  api_id           = aws_apigatewayv2_api.example.id
  name             = "my-cognito-jwt-authorizer"
  authorizer_type  = "JWT"
  identity_sources = ["$request.header.Authorization"]

  jwt_configuration {
    issuer   = "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_XXXXXXXXX" # Replace with your Cognito issuer
    audience = ["your-cognito-client-id"]
  }
}

# Attach the authorizer to the protected route
resource "aws_apigatewayv2_route" "protected_route" {
  api_id    = aws_apigatewayv2_api.example.id
  route_key = "GET /protected"
  target    = "integrations/${aws_apigatewayv2_integration.example.id}"

  authorization_type = "JWT"
  authorizer_id      = aws_apigatewayv2_authorizer.example_jwt.id
}
Quick Notes to Avoid Pitfalls
  • Matching Types: A common mistake is mismatching authorization_type in the route with the authorizer’s authorizer_type—this will throw Terraform errors, so double-check they align.
  • Default Auth: If you want all routes to use this authorizer by default, set it in the API’s default_route_settings block instead of per-route. Per-route attachment is better for granular control (e.g., keeping some routes public).
  • Identity Sources: The identity_sources in your authorizer must point to where your auth token lives—this could be a header, query param, or even a cookie. Adjust the value based on your setup (e.g., ["$request.querystring.token"] for a query param token).

内容的提问来源于stack exchange,提问作者Em Ma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 15:12:45