如何在CloudFormation脚本中正确指定API Gateway URL?
CloudFormation配置API Gateway端点正确方式及部署说明
核心结论
API Gateway必须完成**部署(Deployment)并关联阶段(Stage)**才能生成可访问的端点URL,以下是两种主流配置方案:
方案1:用SAM自动管理API Gateway(推荐)
使用AWS::Serverless::Function的Api事件时,SAM会自动帮你创建RestApi、Deployment、Stage等资源,无需手动编写冗余配置。只需通过CloudFormation内置函数动态引用生成的资源即可获取端点。
修正后的模板示例:
Parameters: StageName: Type: String Default: prod Description: API Gateway阶段名称 Resources: MyDemoLambdaApiFunction: Type: AWS::Serverless::Function Properties: Description: Currently does not support S3 upload event. Handler: app.lambda_handler Runtime: python3.11 CodeUri: . MemorySize: 1028 Events: MyDemoAPI: Type: Api Properties: Path: /test Method: GET RestApiId: !Ref MyDemoApi # 关联自定义RestApi(可选,如需配置CORS、域名等) Tracing: Active # 可选:自定义API Gateway配置时添加此资源 MyDemoApi: Type: AWS::Serverless::Api Properties: StageName: !Ref StageName DefinitionBody: swagger: '2.0' info: title: !Sub ${AWS::StackName}-DemoApi paths: /test: get: x-amazon-apigateway-integration: httpMethod: POST type: aws_proxy uri: !Sub arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${MyDemoLambdaApiFunction.Arn}/invocations Outputs: MyApiUrl: Description: API Gateway访问端点 Value: !Sub "https://${MyDemoApi}.execute-api.${AWS::Region}.amazonaws.com/${StageName}/test"
如果不手动定义MyDemoApi,SAM会自动生成默认RestApi,可通过!Ref MyDemoLambdaApiFunctionMyDemoAPI(SAM自动命名规则)引用该资源。
方案2:原生CloudFormation手动配置API Gateway
若需完全自定义API Gateway的每一个环节,需依次创建RestApi、资源路径、方法、部署、阶段,并配置Lambda调用权限:
Resources: # 1. 创建RestApi MyRestApi: Type: AWS::ApiGateway::RestApi Properties: Name: dev-demo-lambda-api-poc Description: Demo API Gateway # 2. 定义/api/test路径 TestResource: Type: AWS::ApiGateway::Resource Properties: ParentId: !GetAtt MyRestApi.RootResourceId PathPart: test RestApiId: !Ref MyRestApi # 3. 关联Lambda与GET方法 TestMethod: Type: AWS::ApiGateway::Method Properties: HttpMethod: GET ResourceId: !Ref TestResource RestApiId: !Ref MyRestApi AuthorizationType: NONE Integration: Type: AWS_PROXY IntegrationHttpMethod: POST Uri: !Sub arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${MyDemoLambdaApiFunction.Arn}/invocations # 4. 创建部署(必须,否则API无法访问) ApiDeployment: Type: AWS::ApiGateway::Deployment Properties: RestApiId: !Ref MyRestApi Description: Demo deployment DependsOn: TestMethod # 确保方法创建完成后再部署 # 5. 创建阶段 ApiStage: Type: AWS::ApiGateway::Stage Properties: DeploymentId: !Ref ApiDeployment RestApiId: !Ref MyRestApi StageName: prod # 6. 允许API Gateway调用Lambda LambdaInvokePermission: Type: AWS::Lambda::Permission Properties: Action: lambda:InvokeFunction FunctionName: !Ref MyDemoLambdaApiFunction Principal: apigateway.amazonaws.com SourceArn: !Sub arn:aws:execute-api:${AWS::Region}:${AWS::AccountId}:${MyRestApi}/${ApiStage}/GET/test Outputs: MyApiUrl: Description: API Gateway访问端点 Value: !Sub "https://${MyRestApi}.execute-api.${AWS::Region}.amazonaws.com/${ApiStage}/test"
关键说明
- 部署的必要性:RestApi仅定义了API结构,必须创建
AWS::ApiGateway::Deployment并关联Stage,才会生成可对外访问的URL。没有部署的API无法被调用。 - 端点URL生成:标准格式为
https://<RestApiId>.execute-api.<Region>.amazonaws.com/<StageName>/<Path>,通过!Ref和!Sub动态生成,避免硬编码错误。 - 你当前模板的错误根源:手动创建的
Deployment引用了字符串参数MyApi,但RestApiId需要的是RestApi资源的逻辑ID(如!Ref MyRestApi),而非API名称,导致404错误。
内容的提问来源于stack exchange,提问作者Ram
相关产品推荐
相关产品推荐

