You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform部署API Gateway后无法查看CloudWatch日志求助

排查API Gateway CloudWatch日志无法查看的问题

以下是针对Terraform构建的API Gateway日志缺失问题的核心排查点和对应配置修复方案:

  • 确认Stage级别的日志启用配置
    必须在API Gateway的Stage中明确开启访问日志和执行日志,Terraform配置示例:

    resource "aws_api_gateway_stage" "prod" {
      deployment_id = aws_api_gateway_deployment.main.id
      rest_api_id   = aws_api_gateway_rest_api.main.id
      stage_name    = "prod"
    
      # 配置访问日志输出到CloudWatch
      access_log_settings {
        destination_arn = aws_cloudwatch_log_group.api_gateway.arn
        format          = jsonencode({
          requestId = "$context.requestId",
          ip = "$context.identity.sourceIp",
          method = "$context.httpMethod",
          path = "$context.path",
          status = "$context.status"
        })
      }
    
      # 开启方法执行日志(INFO/ERROR级别)
      variables = {
        "cloudwatchLogLevel" = "INFO"
      }
    }
    

    注意:cloudwatchLogLevel变量控制方法级日志的输出,设置为OFF会完全关闭执行日志。

  • 配置API Gateway日志专属IAM角色
    API Gateway需要具备写入CloudWatch Logs的权限,必须配置Account级别的IAM角色并关联权限策略:

    # 日志角色
    resource "aws_iam_role" "api_gateway_logging" {
      name = "api-gateway-logging-role"
    
      assume_role_policy = jsonencode({
        Version = "2012-10-17"
        Statement = [{
          Action = "sts:AssumeRole"
          Effect = "Allow"
          Principal = { Service = "apigateway.amazonaws.com" }
        }]
      })
    }
    
    # 日志写入权限策略
    resource "aws_iam_role_policy" "api_gateway_logging" {
      name = "api-gateway-logging-policy"
      role = aws_iam_role.api_gateway_logging.id
    
      policy = jsonencode({
        Version = "2012-10-17"
        Statement = [{
          Action = ["logs:CreateLogStream", "logs:PutLogEvents"]
          Effect = "Allow"
          Resource = aws_cloudwatch_log_group.api_gateway.arn
        }]
      })
    }
    
    # 关联角色到API Gateway账号
    resource "aws_api_gateway_account" "main" {
      cloudwatch_role_arn = aws_iam_role.api_gateway_logging.arn
    }
    

    这是最容易遗漏的步骤,缺少该角色会导致API Gateway无法推送日志到CloudWatch。

  • 检查CloudWatch日志组配置
    确保日志组存在且权限正确,Terraform创建日志组示例:

    resource "aws_cloudwatch_log_group" "api_gateway" {
      name              = "/aws/api-gateway/${aws_api_gateway_rest_api.main.name}"
      retention_in_days = 30
    }
    

    日志组ARN必须与Stage配置中的destination_arn完全匹配,避免拼写错误。

  • 验证方法级日志设置
    若单个API方法手动关闭了日志,会覆盖Stage配置,检查aws_api_gateway_method的logging_level参数:

    resource "aws_api_gateway_method" "post_sns" {
      rest_api_id   = aws_api_gateway_rest_api.main.id
      resource_id   = aws_api_gateway_resource.sns.id
      http_method   = "POST"
      authorization = "NONE"
    
      # 确保日志级别不是OFF
      logging_level = "INFO"
    }
    
  • 确认部署已生效
    所有配置变更后必须重新部署到Stage,Terraform中需通过depends_on确保部署依赖最新配置:

    resource "aws_api_gateway_deployment" "main" {
      depends_on = [
        aws_api_gateway_method.post_sns,
        aws_api_gateway_integration.sns,
        aws_api_gateway_stage.prod
      ]
    
      rest_api_id = aws_api_gateway_rest_api.main.id
      stage_name  = "prod"
    }
    

    未重新部署会导致新的日志配置无法生效。

内容的提问来源于stack exchange,提问作者user12494839

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 05:42:16