You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于源IP控制API网关访问的可行性及IP来源疑问

关于API网关IP访问控制的疑问

我正在研究API网关的访问控制方案,之前尝试过API密钥方式但未成功。之后我通过ResourcePolicy配置仅允许特定IP访问API网关,该IP是从Lambda事件的sourceIp和X-Forwarded-For参数中获取的,配置代码如下:

MyApiGateway:
  Type: AWS::Serverless::Api
  Properties:
    AccessLogSetting:
      DestinationArn: !GetAtt MyLogGroupForApi.Arn
      Format: $context.extendedRequestId $context.identity.sourceIp $context.identity.caller 
$context.identity.user [$context.requestTime] "$context.httpMethod $context.resourcePath 
$context.protocol" $context.status $context.responseLength $context.requestId
    Variables:
      stageName: test
        Name:
          !Sub
          - '${TheEnv}-${TheAppNameForResources}-api'
          - TheEnv: !Ref Environment
            TheAppNameForResources: !Ref AppNameForResources
            TheBucketRegion: !Ref AWS::Region
    TracingEnabled: true
    OpenApiVersion: 3.0.2
    Cors:
      AllowHeaders: "'Content-Type,X-Amz-Date,Authorization,X-Api-Key,X-Amz-Security-Token'"
      AllowMethods: "'*'"
      AllowOrigin: "'*'"
    StageName: test
    Auth:
      ResourcePolicy:
        CustomStatements:
          - Effect: Allow
            Principal: "*"
            Action: "execute-api:Invoke"
            Resource: "execute-api:/test/GET/pets"
            Condition:
              IpAddress:
                aws:SourceIp:
                  - "201.02.02.002"

配置后测试有效:个人电脑访问API网关会收到未授权错误,办公电脑则可正常访问。现在有几个疑问:

  • 这个aws:SourceIp对应的IP来源是什么?
  • 是否可以依赖这个IP进行API访问限制?
  • 如果该IP并非静态IP,这个方案就不可行,需要重新寻找其他方法,有没有替代方案?

内容的提问来源于stack exchange,提问作者Ram

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 06:03:42