多Git仓库下API Gateway关联Lambda的CloudFormation模板设计咨询
单CloudFormation栈管理多仓库Lambda代理的API Gateway设计方案
核心思路
以单个CloudFormation栈作为API Gateway的唯一可信配置源,栈中仅定义API Gateway的路径结构、方法配置及与Lambda的集成关系,不负责管理分散在各仓库的Lambda函数本身。Lambda的ARN通过参数或外部配置(如SSM参数)引入,实现API配置与Lambda部署的解耦。
模板设计步骤
1. 定义入参:接收外部Lambda的ARN
将各仓库Lambda的ARN作为模板参数,部署时传入对应值,或通过SSM参数存储ARN并在模板中引用,避免硬编码。
Parameters: AccountsProfileLambdaArn: Type: String Description: ARN of the Lambda function handling /accounts/profile (from its repo) AccountsPreferencesLambdaArn: Type: String Description: ARN of the Lambda function handling /accounts/preferences (from its repo) ApiGatewayStageName: Type: String Default: prod Description: Stage name for the API Gateway deployment
2. 构建API Gateway基础资源
先创建RestApi主资源,再逐层定义路径资源(如/accounts、/accounts/profile):
Resources: ApiGatewayRestApi: Type: AWS::ApiGateway::RestApi Properties: Name: UserAccountsApi Description: API Gateway for user account endpoints with multi-repo Lambda proxies AccountsResource: Type: AWS::ApiGateway::Resource Properties: ParentId: !GetAtt ApiGatewayRestApi.RootResourceId PathPart: accounts RestApiId: !Ref ApiGatewayRestApi AccountsProfileResource: Type: AWS::ApiGateway::Resource Properties: ParentId: !Ref AccountsResource PathPart: profile RestApiId: !Ref ApiGatewayRestApi AccountsPreferencesResource: Type: AWS::ApiGateway::Resource Properties: ParentId: !Ref AccountsResource PathPart: preferences RestApiId: !Ref ApiGatewayRestApi
3. 配置Lambda代理集成与方法
为每个路径配置代理集成,关联对应的Lambda ARN,并启用ANY方法(或按需指定GET/POST等):
AccountsProfileProxyMethod: Type: AWS::ApiGateway::Method Properties: HttpMethod: ANY ResourceId: !Ref AccountsProfileResource RestApiId: !Ref ApiGatewayRestApi AuthorizationType: NONE Integration: Type: AWS_PROXY IntegrationHttpMethod: POST Uri: !Sub "arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${AccountsProfileLambdaArn}/invocations" AccountsPreferencesProxyMethod: Type: AWS::ApiGateway::Method Properties: HttpMethod: ANY ResourceId: !Ref AccountsPreferencesResource RestApiId: !Ref ApiGatewayRestApi AuthorizationType: NONE Integration: Type: AWS_PROXY IntegrationHttpMethod: POST Uri: !Sub "arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${AccountsPreferencesLambdaArn}/invocations"
4. 添加API Gateway调用Lambda的权限
为每个Lambda创建权限,允许API Gateway触发调用:
AccountsProfileLambdaPermission: Type: AWS::Lambda::Permission Properties: FunctionName: !Ref AccountsProfileLambdaArn Action: lambda:InvokeFunction Principal: apigateway.amazonaws.com SourceArn: !Sub "arn:aws:execute-api:${AWS::Region}:${AWS::AccountId}:${ApiGatewayRestApi}/${ApiGatewayStageName}/*/accounts/profile" AccountsPreferencesLambdaPermission: Type: AWS::Lambda::Permission Properties: FunctionName: !Ref AccountsPreferencesLambdaArn Action: lambda:InvokeFunction Principal: apigateway.amazonaws.com SourceArn: !Sub "arn:aws:execute-api:${AWS::Region}:${AWS::AccountId}:${ApiGatewayRestApi}/${ApiGatewayStageName}/*/accounts/preferences"
5. 配置API部署与阶段
最后添加部署资源,将配置推送到指定阶段:
ApiGatewayDeployment: Type: AWS::ApiGateway::Deployment DependsOn: - AccountsProfileProxyMethod - AccountsPreferencesProxyMethod Properties: RestApiId: !Ref ApiGatewayRestApi StageName: !Ref ApiGatewayStageName
配套交付流程
- 各Lambda仓库独立部署自身函数,部署完成后更新对应的SSM参数或记录ARN,作为API Gateway栈的部署输入。
- 所有API Gateway的路径、集成变更必须通过修改此CloudFormation模板完成,禁止在AWS控制台手动修改,确保模板为唯一可信源。
内容的提问来源于stack exchange,提问作者Raghav
相关产品推荐
相关产品推荐

