无法通过Terraform设置REST API的API Key必填状态
核心问题分析
核心问题出在你的API Gateway POST方法没开启API Key强制验证——虽然你已经把API Key和使用计划、Stage关联好了,但方法本身的验证开关没打开,所以控制台里的状态一直是False。
修复步骤
针对你的Terraform代码,需要做这几处修改:
1. 给POST方法添加安全规则
在/endpoint的post节点下,添加security配置,明确要求使用API Key验证:
post = { # 原有代码保留 security = [ { api_key = [] } ] # 下面的x-amazon-apigateway-integration等配置不动 }
2. 在OpenAPI根节点定义API Key验证规则
在和paths、definitions同级的位置,添加components节点,指定API Key通过x-api-key请求头传递:
components = { securitySchemes = { api_key = { type = "apiKey" name = "x-api-key" in = "header" } } }
3. 删除无效的参数映射
你现在在x-amazon-apigateway-integration里写的request_parameters是把查询参数apikey映射到请求头,这和你要的通过x-api-key头传密钥的需求完全不符,直接删掉这段:
# 删掉这部分 request_parameters = { "method.request.header.X-API-KEY" = "method.request.querystring.apikey" }
4. 修正集成类型的重复定义
你在x-amazon-apigateway-integration里重复写了两次type(HTTP_PROXY和aws_proxy),这会导致配置冲突,统一改成aws_proxy就行(因为你集成的是Lambda)。
修改后的OpenAPI代码片段参考
resource "aws_api_gateway_rest_api" "rest_api" { name = local.rest_api_name disable_execute_api_endpoint = true body = jsonencode( { openapi = "3.0.3" info = { title = local.rest_api_title description = "" version = "0.0.1" } # 新增:API Key安全方案定义 components = { securitySchemes = { api_key = { type = "apiKey" name = "x-api-key" in = "header" } } } paths = { "/endpoint" = { post = { # 新增:开启API Key验证 security = [ { api_key = [] } ] x-amazon-apigateway-integration = { httpMethod = "POST" payloadFormatVersion = "1.0" # 修正:统一集成类型为aws_proxy type = "aws_proxy" uri = aws_lambda_function.api_lambda.invoke_arn passthroughBehavior = "when_no_match" contentHandling = "CONVERT_TO_TEXT" responses = { default = { statusCode = "500" } } } # 原有requestBody和responses保持不变 requestBody = { description = "A provisioning request descriptor wrapped as a string into a simple object" schema = { "$ref" = "#/definitions/CustomNotificationRequest" } required = true } responses = { "202" = { description = "It asynchronously returns the request result" schema = { "$ref" = "#/definitions/Response" } } "200" = { description = "If successful returns a provisioning deployment task token that can be used for polling the request status" schema = { "$ref" = "#/definitions/TraceableResponse" } } "400" = { description = "Invalid input" schema = { "$ref" = "#/definitions/ValidationError" } } "500" = { description = "System problem" schema = { "$ref" = "#/definitions/SystemError" } } } } } } definitions = { # 原有定义保持不变 CustomNotificationRequest = { type = "object" properties = { respondToUrl = { type = "string" description = "URL to be contacted to notify that the hook is completed. This represents the fact that the third-party interaction has been performed on your end" } fields = { type = "object" description = "A free-form object containing all the action's input data coming from witboost" } } } # 其他定义省略... } } ) endpoint_configuration { types = ["REGIONAL"] } }
额外提醒
- 确认你的API Key本身是启用状态(控制台里API Key的"Enabled"开关要开着)。
- 你的部署触发器已经配置了基于API定义的SHA1校验,修改代码后会自动触发重新部署,不用手动操作。
内容的提问来源于stack exchange,提问作者whatsinthename
相关产品推荐
相关产品推荐

