You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

多Git仓库下API Gateway关联Lambda的CloudFormation模板设计咨询

单CloudFormation栈管理多仓库Lambda代理的API Gateway设计方案

核心思路

以单个CloudFormation栈作为API Gateway的唯一可信配置源,栈中仅定义API Gateway的路径结构、方法配置及与Lambda的集成关系,不负责管理分散在各仓库的Lambda函数本身。Lambda的ARN通过参数或外部配置(如SSM参数)引入,实现API配置与Lambda部署的解耦。

模板设计步骤

1. 定义入参:接收外部Lambda的ARN

将各仓库Lambda的ARN作为模板参数,部署时传入对应值,或通过SSM参数存储ARN并在模板中引用,避免硬编码。

Parameters:
  AccountsProfileLambdaArn:
    Type: String
    Description: ARN of the Lambda function handling /accounts/profile (from its repo)
  AccountsPreferencesLambdaArn:
    Type: String
    Description: ARN of the Lambda function handling /accounts/preferences (from its repo)
  ApiGatewayStageName:
    Type: String
    Default: prod
    Description: Stage name for the API Gateway deployment

2. 构建API Gateway基础资源

先创建RestApi主资源,再逐层定义路径资源(如/accounts、/accounts/profile):

Resources:
  ApiGatewayRestApi:
    Type: AWS::ApiGateway::RestApi
    Properties:
      Name: UserAccountsApi
      Description: API Gateway for user account endpoints with multi-repo Lambda proxies

  AccountsResource:
    Type: AWS::ApiGateway::Resource
    Properties:
      ParentId: !GetAtt ApiGatewayRestApi.RootResourceId
      PathPart: accounts
      RestApiId: !Ref ApiGatewayRestApi

  AccountsProfileResource:
    Type: AWS::ApiGateway::Resource
    Properties:
      ParentId: !Ref AccountsResource
      PathPart: profile
      RestApiId: !Ref ApiGatewayRestApi

  AccountsPreferencesResource:
    Type: AWS::ApiGateway::Resource
    Properties:
      ParentId: !Ref AccountsResource
      PathPart: preferences
      RestApiId: !Ref ApiGatewayRestApi

3. 配置Lambda代理集成与方法

为每个路径配置代理集成,关联对应的Lambda ARN,并启用ANY方法(或按需指定GET/POST等):

AccountsProfileProxyMethod:
    Type: AWS::ApiGateway::Method
    Properties:
      HttpMethod: ANY
      ResourceId: !Ref AccountsProfileResource
      RestApiId: !Ref ApiGatewayRestApi
      AuthorizationType: NONE
      Integration:
        Type: AWS_PROXY
        IntegrationHttpMethod: POST
        Uri: !Sub "arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${AccountsProfileLambdaArn}/invocations"

  AccountsPreferencesProxyMethod:
    Type: AWS::ApiGateway::Method
    Properties:
      HttpMethod: ANY
      ResourceId: !Ref AccountsPreferencesResource
      RestApiId: !Ref ApiGatewayRestApi
      AuthorizationType: NONE
      Integration:
        Type: AWS_PROXY
        IntegrationHttpMethod: POST
        Uri: !Sub "arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${AccountsPreferencesLambdaArn}/invocations"

4. 添加API Gateway调用Lambda的权限

为每个Lambda创建权限,允许API Gateway触发调用:

AccountsProfileLambdaPermission:
    Type: AWS::Lambda::Permission
    Properties:
      FunctionName: !Ref AccountsProfileLambdaArn
      Action: lambda:InvokeFunction
      Principal: apigateway.amazonaws.com
      SourceArn: !Sub "arn:aws:execute-api:${AWS::Region}:${AWS::AccountId}:${ApiGatewayRestApi}/${ApiGatewayStageName}/*/accounts/profile"

  AccountsPreferencesLambdaPermission:
    Type: AWS::Lambda::Permission
    Properties:
      FunctionName: !Ref AccountsPreferencesLambdaArn
      Action: lambda:InvokeFunction
      Principal: apigateway.amazonaws.com
      SourceArn: !Sub "arn:aws:execute-api:${AWS::Region}:${AWS::AccountId}:${ApiGatewayRestApi}/${ApiGatewayStageName}/*/accounts/preferences"

5. 配置API部署与阶段

最后添加部署资源,将配置推送到指定阶段:

ApiGatewayDeployment:
    Type: AWS::ApiGateway::Deployment
    DependsOn:
      - AccountsProfileProxyMethod
      - AccountsPreferencesProxyMethod
    Properties:
      RestApiId: !Ref ApiGatewayRestApi
      StageName: !Ref ApiGatewayStageName

配套交付流程

  • 各Lambda仓库独立部署自身函数,部署完成后更新对应的SSM参数或记录ARN,作为API Gateway栈的部署输入。
  • 所有API Gateway的路径、集成变更必须通过修改此CloudFormation模板完成,禁止在AWS控制台手动修改,确保模板为唯一可信源。

内容的提问来源于stack exchange,提问作者Raghav

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 01:20:29