Api Gateway V2配置Lambda Authorizer提示缺少/*路由问题求助
我已经花了好几个晚上尝试解决这个问题,但毫无进展。我正在为API Gateway V2配置Lambda Authorizer,不管用Terraform还是AWS控制台都失败了。
我的Terraform配置如下:
resource "aws_apigatewayv2_authorizer" "lambda_authorizer" { api_id = aws_apigatewayv2_api.api.id authorizer_type = "REQUEST" identity_sources = ["$request.header.Authorization"] name = "lambda_authorizer-${var.app_name}-${var.environment}" authorizer_payload_format_version = "2.0" authorizer_result_ttl_in_seconds = 0 enable_simple_responses = true authorizer_uri = aws_lambda_function.authorizer.invoke_arn } resource "aws_lambda_permission" "my_authorizer_lambda_permission" { statement_id = "AllowAPIGatewayInvoke" action = "lambda:InvokeFunction" function_name = aws_lambda_function.authorizer.function_name principal = "apigateway.amazonaws.com" source_arn = "arn:aws:execute-api:${data.aws_region.current.id}:${data.aws_caller_identity.current.account_id}:${aws_apigatewayv2_api.api.id}/*/*/*" } resource "aws_apigatewayv2_integration" "integration" { api_id = aws_apigatewayv2_api.api.id integration_type = "HTTP_PROXY" integration_uri = aws_service_discovery_service.ecs-discovery-service.arn integration_method = "ANY" connection_type = "VPC_LINK" connection_id = aws_apigatewayv2_vpc_link.vpc_link.id payload_format_version = "1.0" } resource "aws_apigatewayv2_route" "route" { api_id = aws_apigatewayv2_api.api.id route_key = "ANY /{proxy+}" target = "integrations/${aws_apigatewayv2_integration.integration.id}" authorization_type = "CUSTOM" authorizer_id = aws_apigatewayv2_authorizer.lambda_authorizer.id depends_on = [aws_apigatewayv2_authorizer.lambda_authorizer] } resource "aws_apigatewayv2_stage" "stage" { api_id = aws_apigatewayv2_api.api.id name = "${var.app_name}-${var.environment}" auto_deploy = true default_route_settings { logging_level = "INFO" detailed_metrics_enabled = true data_trace_enabled = true throttling_rate_limit = 20 #Amount of requests per second throttling_burst_limit = 50 #Concurrent requests } access_log_settings { destination_arn = aws_cloudwatch_log_group.api_gw_access_log_group.arn format = jsonencode({ requestId = "$context.requestId" sourceIp = "$context.identity.sourceIp" requestTime = "$context.requestTime" protocol = "$context.protocol" httpMethod = "$context.httpMethod" resourcePath = "$context.resourcePath" routeKey = "$context.routeKey" status = "$context.status" responseLength = "$context.responseLength" integrationErrorMessage = "$context.integrationErrorMessage" } ) } }
部署能正常完成,Authorizer也已经关联到API Gateway,但不管用Terraform还是控制台配置,都会遇到错误(控制台配置时使用不同source_arn的错误提示为:The source ARN does not match the one configured on the authorizer)。
我已经配置了ANY /{proxy+}的路由,完全无法理解问题出在哪。
我试过把同一个Lambda函数配置成普通API端点,错误就消失了,但原问题还是存在,非常奇怪。
另外,我能看到请求到达了API Gateway,但Lambda日志里完全没有记录,推测这就是返回403状态码的原因——Lambda Authorizer未返回策略时的默认行为。
更新
我尝试把source_arn修改为:
source_arn = "${aws_apigatewayv2_api.api.execution_arn}/authorizers/${aws_apigatewayv2_authorizer.lambda_authorizer.id}"
问题依然存在。
更新9/9
我尝试修改source_arn适配不同Lambda版本:
source_arn = "${aws_apigatewayv2_api.api.execution_arn}/authorizers/${aws_apigatewayv2_authorizer.lambda_authorizer.id}/*/*"
同时也试过:
source_arn = "${aws_apigatewayv2_api.api.execution_arn}/*"
但还是出现相同错误,请求依然到不了Lambda(只有API Gateway有日志记录)。请求帮忙解决这个问题。
内容的提问来源于stack exchange,提问作者Jeppe Christensen
相关产品推荐
相关产品推荐

