You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过SAM部署AWS API Gateway时API Key无法按需配置问题

问题:AWS SAM部署API时无法单独配置端点的API Key要求

我有一个API,需要部分端点要求API Key,其余端点不需要。但无论如何配置,通过SAM部署都无法正确设置API Key的按需启用规则——只能为所有端点统一开启,无法单独配置。我不想为需要和不需要API Key的端点创建独立API,也不想在部署后手动配置。

当前配置

Template.yaml 核心配置

TestApi:
    Name: TestApi
    Type: AWS::Serverless::Api
    Properties:
      EndpointConfiguration: REGIONAL
      StageName: !Ref StageNameParameter
      Variables:
        Stage: !Ref StageNameParameter
      MethodSettings:
        - LoggingLevel:
            !FindInMap [AccountParameters, !Ref AccountType, ApiLoggingLevel]
          ResourcePath: "/*" 
          HttpMethod: "*" 
          DataTraceEnabled: !If [EnableAPIMonitoring, true, false] 
          MetricsEnabled: !If [EnableAPIMetrics, true, false] 
      Auth:
        #ApiKeyRequired: true # 全局开启会作用于所有方法,已注释
        Authorizers:
          AuthorizerFunction:
            :
          OktaAuthorizer:
            :
        DefaultAuthorizer: AuthorizerFunction
        ResourcePolicy:
          CustomStatements: [
            :
          ]
      DefinitionBody: # 使用DefinitionBody而非DefinitionUri,避免Swagger模板不被转换
        Fn::Transform:
          Name: AWS::Include
          Parameters:
            Location: api-definition/api-1.0.10-swagger.yaml
    
PublicFunction:
    Type: AWS::Serverless::Function
    Properties:
      CodeUri: lambdas/src/handlers/test/
      Handler: test.lambdaHandler
      Events:
        TestEvent:
          Type: Api
          Properties:
            Path: /test/me
            Method: get
            RestApiId: !Ref TestApi
            Auth:
              ApiKeyRequired: false
              Authorizer: OktaAuthorizer
      Policies:
        :
      
PrivateFunction:
    Type: AWS::Serverless::Function
    Properties:
      CodeUri: lambdas/src/handlers/test/
      Handler: private.lambdaHandler
      Policies:
        :
      Events:
        PrivateEvent:
          Type: Api
          Properties:
            Path: /test/private
            Method: post
            RestApiId: !Ref TestApi
            Auth:
              ApiKeyRequired: true
              Authorizer: AuthorizerFunction

OpenAPI 3.0 定义核心内容

openapi: 3.0.0
info:
  version: 1.0.9
  title: test-api
# x-amazon-apigateway-api-key-source: "HEADER"
paths:
  /test/me:
    get:
      summary: Test public
      operationId: TestEvent
      description: Public Test
      responses:
        200:
          $ref: "#/components/responses/OKFullResponse"
        400:
          $ref: "#/components/responses/BadRequest"
        404:
          $ref: "#/components/responses/NotFound"
        500:
          $ref: "#/components/responses/InternalServerError"
      security:
      - OktaAuthorizer: []
      x-amazon-apigateway-request-validator: "params-only"
      x-amazon-apigateway-integration:
        httpMethod: "POST"
        uri: {"Fn::Sub": "arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${PublicFunction.Arn}/invocations"}
        type: "aws_proxy"

  /test/private:
    post:
      summary: test
      operationId: testPost
      description: Test
      parameters:
        - $ref: "#/components/parameters/clientIdParam"
        - $ref: "#/components/parameters/clientSecretParam"
      responses:
        200:
          $ref: "#/components/responses/OKLiteResponse"
        400:
          $ref: "#/components/responses/BadRequest"
        404:
          $ref: "#/components/responses/NotFound"
        500:
          $ref: "#/components/responses/InternalServerError"
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/BodyModel'
        description: Request body 
      security:
      - client_id: []
      - client_secret: []
      - AuthorizerFunction: []
      x-amazon-apigateway-request-validator: "Validator"
      x-amazon-apigateway-integration:
        httpMethod: "POST"
        uri: {"Fn::Sub": "arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${PrivateFunction.Arn}/invocations"}
        type: "aws_proxy"

components:
  securitySchemes:
    api_key:
      description: An API key must accompany each request in the header
      type: apiKey
      name: x-api-key
      in: header
      x-amazon-apigateway-api-key-source : HEADER
    client_id:
      :
    client_secret:
      :
    OktaAuthApiAuthorizer:
      :
    AccountApiAuthorizerFunction:
      :

已尝试的配置方式

  • 仅在template.yaml的函数Api事件中设置ApiKeyRequired参数
  • 仅在OpenAPI定义中为需要的端点添加api_key安全规则(示例如下):
    /test/private:
        post:
          # ... 其余配置省略
          security:
          - api_key: []
          - client_id: []
          - client_secret: []
          - AuthorizerFunction: []
          # ... 其余配置省略
    
  • 组合上述两种配置方式

疑问

肯定存在某种配置方式可以在定义或模板中实现按需配置,无需手动修改,我到底遗漏了什么?


内容的提问来源于stack exchange,提问作者lisa bogart

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 03:12:05