You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在CDK(alpha版本)中为HttpApi附加资源策略

为API Gateway V2 HttpApi添加资源策略对接EventBridge

HttpApi确实支持资源策略,只是操作路径和传统RestApi略有不同,以下是几种可行的配置方式:

控制台操作

  1. 登录AWS控制台,进入API Gateway V2服务
  2. 选中目标HttpApi,切换到「权限」标签页
  3. 点击「添加资源策略」,粘贴符合EventBridge需求的策略文档(示例见下文)

AWS CLI配置

创建一个包含权限策略的JSON文件(比如eventbridge-policy.json):

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "Service": "events.amazonaws.com"
      },
      "Action": "execute-api:Invoke",
      "Resource": "arn:aws:execute-api:你的区域:你的账号ID:你的HttpApiID/*/*/*"
    }
  ]
}

执行CLI命令更新HttpApi的策略:

aws apigatewayv2 update-api \
    --api-id 你的HttpApiID \
    --policy file://eventbridge-policy.json

CloudFormation/CDK配置

如果用基础设施即代码,直接在HttpApi资源中定义Policy属性:

CloudFormation YAML示例

Resources:
  TargetHttpApi:
    Type: AWS::ApiGatewayV2::Api
    Properties:
      Name: EventBridgeTargetHttpApi
      ProtocolType: HTTP
      Policy: !Sub |
        {
          "Version": "2012-10-17",
          "Statement": [
            {
              "Effect": "Allow",
              "Principal": {
                "Service": "events.amazonaws.com"
              },
              "Action": "execute-api:Invoke",
              "Resource": "arn:aws:execute-api:${AWS::Region}:${AWS::AccountId}:${TargetHttpApi}/*/*/*"
            }
          ]
        }

安全优化建议

如果需要限制仅特定EventBridge规则调用你的HttpApi,可在策略中添加Condition字段,指定规则的ARN:

"Condition": {
  "ArnEquals": {
    "aws:SourceArn": "arn:aws:events:你的区域:你的账号ID:rule/你的规则名称"
  }
}

内容的提问来源于stack exchange,提问作者vertti

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 17:32:46