在Serverless的API Gateway配置中添加安全报头失败:无效配置
问题描述
我通过Serverless框架部署多个由API Gateway触发的Lambda函数,尝试在serverless.yml的provider.apiGateway段配置全局安全头,但收到警告:
Warning: Invalid configuration encountered
at 'provider.apiGateway': unrecognized property 'response'
我的配置片段如下:
serverless.yml
service: my-service provider: name: aws runtime: nodejs14.x stage: dev region: us-east-1 profile: xyz apiGateway: restApiId: # 可指定现有API Gateway ID restApiRootResourceId: # 可指定现有根资源ID response: headers: Strict-Transport-Security: "'max-age=31536000; includeSubDomains'" functions: helloWorld: handler: handler.hello events: - http: path: 'hello' method: get cors: true
handler.js
'use strict'; module.exports.hello = async (event) => { return { statusCode: 500, error: 'Error' }; };
请问如何在API Gateway全局配置中添加安全头,避免为每个函数单独配置?
解决方案
Serverless框架的provider.apiGateway配置段并不支持response属性,因此会触发无效配置警告。要全局添加安全头,推荐以下两种方法:
方法1:通过CloudFormation自定义资源配置全局响应头
利用Serverless支持CloudFormation资源的特性,定义AWS::ApiGateway::GatewayResponse资源,针对API Gateway的所有响应类型(成功响应、错误响应等)统一添加安全头。
修改serverless.yml,添加Resources段:
service: my-service provider: name: aws runtime: nodejs14.x stage: dev region: us-east-1 profile: xyz apiGateway: restApiId: # 可指定现有API Gateway ID restApiRootResourceId: # 可指定现有根资源ID functions: helloWorld: handler: handler.hello events: - http: path: 'hello' method: get cors: true resources: Resources: # 针对2XX成功响应添加安全头 GatewayResponseDefault2XX: Type: 'AWS::ApiGateway::GatewayResponse' Properties: ResponseParameters: gatewayresponse.header.Strict-Transport-Security: "'max-age=31536000; includeSubDomains'" gatewayresponse.header.X-Content-Type-Options: "'nosniff'" gatewayresponse.header.X-Frame-Options: "'DENY'" ResponseType: DEFAULT_2XX RestApiId: Ref: ApiGatewayRestApi # 针对4XX客户端错误响应添加安全头 GatewayResponseDefault4XX: Type: 'AWS::ApiGateway::GatewayResponse' Properties: ResponseParameters: gatewayresponse.header.Strict-Transport-Security: "'max-age=31536000; includeSubDomains'" gatewayresponse.header.X-Content-Type-Options: "'nosniff'" gatewayresponse.header.X-Frame-Options: "'DENY'" ResponseType: DEFAULT_4XX RestApiId: Ref: ApiGatewayRestApi # 针对5XX服务端错误响应添加安全头 GatewayResponseDefault5XX: Type: 'AWS::ApiGateway::GatewayResponse' Properties: ResponseParameters: gatewayresponse.header.Strict-Transport-Security: "'max-age=31536000; includeSubDomains'" gatewayresponse.header.X-Content-Type-Options: "'nosniff'" gatewayresponse.header.X-Frame-Options: "'DENY'" ResponseType: DEFAULT_5XX RestApiId: Ref: ApiGatewayRestApi
这段配置会为API Gateway的2XX、4XX、5XX所有响应类型自动添加指定的安全头,无需为每个函数单独配置。
方法2:使用Serverless插件简化配置
如果不想手动编写CloudFormation资源,可以使用serverless-api-gateway-response插件:
- 安装插件:
npm install serverless-api-gateway-response --save-dev
- 在
serverless.yml中配置插件和全局响应头:
service: my-service provider: name: aws runtime: nodejs14.x stage: dev region: us-east-1 profile: xyz apiGateway: restApiId: # 可指定现有API Gateway ID restApiRootResourceId: # 可指定现有根资源ID plugins: - serverless-api-gateway-response custom: apiGatewayResponse: headers: Strict-Transport-Security: "'max-age=31536000; includeSubDomains'" X-Content-Type-Options: "'nosniff'" X-Frame-Options: "'DENY'" responses: DEFAULT_2XX: statusCode: 200 DEFAULT_4XX: statusCode: 400 DEFAULT_5XX: statusCode: 500 functions: helloWorld: handler: handler.hello events: - http: path: 'hello' method: get cors: true
插件会自动生成对应的CloudFormation资源,实现全局响应头的统一配置。
内容的提问来源于stack exchange,提问作者karPower
相关产品推荐
相关产品推荐

