在CDK(alpha版本)中为HttpApi附加资源策略
为API Gateway V2 HttpApi添加资源策略对接EventBridge
HttpApi确实支持资源策略,只是操作路径和传统RestApi略有不同,以下是几种可行的配置方式:
控制台操作
- 登录AWS控制台,进入API Gateway V2服务
- 选中目标HttpApi,切换到「权限」标签页
- 点击「添加资源策略」,粘贴符合EventBridge需求的策略文档(示例见下文)
AWS CLI配置
创建一个包含权限策略的JSON文件(比如eventbridge-policy.json):
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "events.amazonaws.com" }, "Action": "execute-api:Invoke", "Resource": "arn:aws:execute-api:你的区域:你的账号ID:你的HttpApiID/*/*/*" } ] }
执行CLI命令更新HttpApi的策略:
aws apigatewayv2 update-api \ --api-id 你的HttpApiID \ --policy file://eventbridge-policy.json
CloudFormation/CDK配置
如果用基础设施即代码,直接在HttpApi资源中定义Policy属性:
CloudFormation YAML示例
Resources: TargetHttpApi: Type: AWS::ApiGatewayV2::Api Properties: Name: EventBridgeTargetHttpApi ProtocolType: HTTP Policy: !Sub | { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "events.amazonaws.com" }, "Action": "execute-api:Invoke", "Resource": "arn:aws:execute-api:${AWS::Region}:${AWS::AccountId}:${TargetHttpApi}/*/*/*" } ] }
安全优化建议
如果需要限制仅特定EventBridge规则调用你的HttpApi,可在策略中添加Condition字段,指定规则的ARN:
"Condition": { "ArnEquals": { "aws:SourceArn": "arn:aws:events:你的区域:你的账号ID:rule/你的规则名称" } }
内容的提问来源于stack exchange,提问作者vertti
相关产品推荐
相关产品推荐

