如何在Terraform中为HTTP API Gateway路由关联授权器?
Got it! Let me walk you through how to attach an authorizer to an HTTP API Gateway route in Terraform—it’s actually straightforward once you know which fields to use. Here’s a step-by-step breakdown with examples:
First, you’ll need to create the authorizer resource itself. This example uses a JWT authorizer, but the process works similarly for custom Lambda authorizers (just adjust the authorizer_type and related config):
resource "aws_apigatewayv2_authorizer" "example_jwt" { api_id = aws_apigatewayv2_api.example.id # Link to your existing API name = "my-jwt-authorizer" authorizer_type = "JWT" # Use "CUSTOM" for Lambda authorizers identity_sources = ["$request.header.Authorization"] # Where to pull the auth token from # JWT-specific config (skip this block for custom authorizers) jwt_configuration { issuer = "https://your-auth-provider.com/" # e.g., Auth0, Cognito audience = ["your-api-audience"] } }
The key part is updating your route resource to reference the authorizer. You’ll need two critical fields:
authorization_type: Must exactly match your authorizer’s type (JWT/CUSTOM)authorizer_id: The ID of the authorizer you created earlier
Here’s how that looks in a route definition:
resource "aws_apigatewayv2_route" "protected_route" { api_id = aws_apigatewayv2_api.example.id route_key = "GET /protected-endpoint" target = "integrations/${aws_apigatewayv2_integration.example.id}" # Link to your backend integration # Attach the authorizer here authorization_type = "JWT" authorizer_id = aws_apigatewayv2_authorizer.example_jwt.id }
To put it all together, here’s a complete snippet that creates the API, authorizer, integration, and protected route:
# Create the base HTTP API resource "aws_apigatewayv2_api" "example" { name = "my-http-api" protocol_type = "HTTP" } # Create a sample integration (e.g., proxy to an external backend) resource "aws_apigatewayv2_integration" "example" { api_id = aws_apigatewayv2_api.example.id integration_type = "HTTP_PROXY" integration_uri = "https://api.example.com/backend" } # Define the JWT authorizer (using Cognito as an example) resource "aws_apigatewayv2_authorizer" "example_jwt" { api_id = aws_apigatewayv2_api.example.id name = "my-cognito-jwt-authorizer" authorizer_type = "JWT" identity_sources = ["$request.header.Authorization"] jwt_configuration { issuer = "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_XXXXXXXXX" # Replace with your Cognito issuer audience = ["your-cognito-client-id"] } } # Attach the authorizer to the protected route resource "aws_apigatewayv2_route" "protected_route" { api_id = aws_apigatewayv2_api.example.id route_key = "GET /protected" target = "integrations/${aws_apigatewayv2_integration.example.id}" authorization_type = "JWT" authorizer_id = aws_apigatewayv2_authorizer.example_jwt.id }
- Matching Types: A common mistake is mismatching
authorization_typein the route with the authorizer’sauthorizer_type—this will throw Terraform errors, so double-check they align. - Default Auth: If you want all routes to use this authorizer by default, set it in the API’s
default_route_settingsblock instead of per-route. Per-route attachment is better for granular control (e.g., keeping some routes public). - Identity Sources: The
identity_sourcesin your authorizer must point to where your auth token lives—this could be a header, query param, or even a cookie. Adjust the value based on your setup (e.g.,["$request.querystring.token"]for a query param token).
内容的提问来源于stack exchange,提问作者Em Ma

