You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法通过Terraform设置REST API的API Key必填状态

核心问题分析

核心问题出在你的API Gateway POST方法没开启API Key强制验证——虽然你已经把API Key和使用计划、Stage关联好了,但方法本身的验证开关没打开,所以控制台里的状态一直是False。

修复步骤

针对你的Terraform代码,需要做这几处修改:

1. 给POST方法添加安全规则

在/endpoint的post节点下,添加security配置,明确要求使用API Key验证:

post = {
  # 原有代码保留
  security = [
    {
      api_key = []
    }
  ]
  # 下面的x-amazon-apigateway-integration等配置不动
}

2. 在OpenAPI根节点定义API Key验证规则

在和paths、definitions同级的位置,添加components节点,指定API Key通过x-api-key请求头传递:

components = {
  securitySchemes = {
    api_key = {
      type = "apiKey"
      name = "x-api-key"
      in = "header"
    }
  }
}

3. 删除无效的参数映射

你现在在x-amazon-apigateway-integration里写的request_parameters是把查询参数apikey映射到请求头,这和你要的通过x-api-key头传密钥的需求完全不符,直接删掉这段:

# 删掉这部分
request_parameters = {
  "method.request.header.X-API-KEY" = "method.request.querystring.apikey"
}

4. 修正集成类型的重复定义

你在x-amazon-apigateway-integration里重复写了两次type(HTTP_PROXY和aws_proxy),这会导致配置冲突,统一改成aws_proxy就行(因为你集成的是Lambda)。

修改后的OpenAPI代码片段参考
resource "aws_api_gateway_rest_api" "rest_api" {
  name                         = local.rest_api_name
  disable_execute_api_endpoint = true
  body = jsonencode(
    {
      openapi = "3.0.3"
      info = {
        title       = local.rest_api_title
        description = ""
        version     = "0.0.1"
      }
      # 新增:API Key安全方案定义
      components = {
        securitySchemes = {
          api_key = {
            type = "apiKey"
            name = "x-api-key"
            in = "header"
          }
        }
      }
      paths = {
        "/endpoint" = {
          post = {
            # 新增:开启API Key验证
            security = [
              {
                api_key = []
              }
            ]
            x-amazon-apigateway-integration = {
              httpMethod           = "POST"
              payloadFormatVersion = "1.0"
              # 修正:统一集成类型为aws_proxy
              type                 = "aws_proxy"
              uri                  = aws_lambda_function.api_lambda.invoke_arn
              passthroughBehavior  = "when_no_match"
              contentHandling      = "CONVERT_TO_TEXT"
              responses = {
                default = {
                  statusCode = "500"
                }
              }
            }
            # 原有requestBody和responses保持不变
            requestBody = {
              description = "A provisioning request descriptor wrapped as a string into a simple object"
              schema = {
                "$ref" = "#/definitions/CustomNotificationRequest"
              }
              required = true
            }
            responses = {
              "202" = {
                description = "It asynchronously returns the request result"
                schema = {
                  "$ref" = "#/definitions/Response"
                }
              }
              "200" = {
                description = "If successful returns a provisioning deployment task token that can be used for polling the request status"
                schema = {
                  "$ref" = "#/definitions/TraceableResponse"
                }
              }
              "400" = {
                description = "Invalid input"
                schema = {
                  "$ref" = "#/definitions/ValidationError"
                }
              }
              "500" = {
                description = "System problem"
                schema = {
                  "$ref" = "#/definitions/SystemError"
                }
              }
            }
          }
        }
      }
      definitions = {
        # 原有定义保持不变
        CustomNotificationRequest = {
          type = "object"
          properties = {
            respondToUrl = {
              type        = "string"
              description = "URL to be contacted to notify that the hook is completed. This represents the fact that the third-party interaction has been performed on your end"
            }
            fields = {
              type        = "object"
              description = "A free-form object containing all the action's input data coming from witboost"
            }
          }
        }
        # 其他定义省略...
      }
    }
  )

  endpoint_configuration {
    types = ["REGIONAL"]
  }
}
额外提醒
  • 确认你的API Key本身是启用状态(控制台里API Key的"Enabled"开关要开着)。
  • 你的部署触发器已经配置了基于API定义的SHA1校验,修改代码后会自动触发重新部署,不用手动操作。

内容的提问来源于stack exchange,提问作者whatsinthename

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 21:20:25