如何通过SAM模板为API Gateway配置Route53自定义域名
为API Gateway配置自定义域名(结合Route53托管区域)
针对你的三个问题,直接给出明确结论:
1. 是否需要先创建API别名?
不需要。API别名主要用于蓝绿部署、版本切换等场景,单纯绑定自定义域名到API Gateway的stage即可,无需额外创建别名。不管是REST API还是HTTP API,直接关联已部署的stage就能完成自定义域名的映射。
2. 是否需要使用AWS颁发的证书?
是的,必须使用AWS Certificate Manager(ACM)颁发的证书,且需满足以下要求:
- 证书必须覆盖你的自定义域名(比如
api.int.coredev.xxx.com) - 如果是REST API,证书必须部署在
us-east-1区域(因CloudFront参与分发);如果是HTTP API,证书可部署在API所在的区域 - 证书需完成域名验证(DNS验证更适配Route53托管区域,AWS会自动添加验证记录)
3. 还需要定义哪些其他资源?
在SAM模板中,你需要添加以下核心资源:
- ACM证书:若还没有对应域名的证书,需定义
AWS::CertificateManager::Certificate资源(推荐用DNS验证,结合Route53自动完成验证) - API Gateway自定义域名:根据API类型选择
AWS::ApiGateway::DomainName(REST API)或AWS::ApiGatewayV2::DomainName(HTTP API),关联ACM证书和API的stage - Route53记录集:
AWS::Route53::RecordSet,将自定义域名指向API Gateway自定义域名对应的CloudFront域名(REST API)或区域域名(HTTP API) - 基础路径映射:REST API需
AWS::ApiGateway::BasePathMapping完成自定义域名到API stage的路径映射;HTTP API可直接在DomainName资源中配置映射
SAM模板示例片段
Resources: # 1. ACM证书(DNS验证,自动关联Route53托管区域) ApiCertificate: Type: AWS::CertificateManager::Certificate Properties: DomainName: api.int.coredev.xxx.com ValidationMethod: DNS DomainValidationOptions: - DomainName: api.int.coredev.xxx.com HostedZoneId: !Ref YourHostedZoneId # 替换为你的Route53托管区域ID # 2. API Gateway自定义域名(以HTTP API为例) ApiDomainName: Type: AWS::ApiGatewayV2::DomainName Properties: DomainName: api.int.coredev.xxx.com DomainNameConfigurations: - CertificateArn: !Ref ApiCertificate EndpointType: REGIONAL SecurityPolicy: TLS_1_2 # 3. 基础路径映射(HTTP API) ApiMapping: Type: AWS::ApiGatewayV2::ApiMapping Properties: ApiId: !Ref YourApiGatewayId # 替换为你的API Gateway ID DomainName: !Ref ApiDomainName Stage: !Ref YourApiStageName # 替换为你的API stage名称 # 4. Route53记录集 ApiRoute53Record: Type: AWS::Route53::RecordSet Properties: HostedZoneId: !Ref YourHostedZoneId Name: api.int.coredev.xxx.com Type: A AliasTarget: HostedZoneId: !GetAtt ApiDomainName.RegionalHostedZoneId DNSName: !GetAtt ApiDomainName.RegionalDomainName
内容的提问来源于stack exchange,提问作者Ram
相关产品推荐
相关产品推荐

