使用OpenAPI定义API Gateway授权器部署后不显示的问题
尝试通过OpenAPI Specification定义授权器并关联到API的POST方法,但部署CloudFormation模板后,授权器未在API Gateway控制台显示,也未关联到目标POST方法。简化后的模板如下:
Type: AWS::Serverless::Api Properties: Name: !Sub \"API Gateway\" EndpointConfiguration: Type: REGIONAL DefinitionBody: openapi: 3.0.3 info: title: 'APIs' version: 1.0.0 paths: /callHistoryAsync: post: parameters: - name: 'xxxxx' in: 'query' required: true schema: type: 'string' x-amazon-apigateway-integration: type: aws requestParameters: integration.request.header.X-Amz-Invocation-Type: '''Event''' integration.request.querystring.store_id: \"method.request.querystring.xxxxx\" httpMethod: POST uri: !Sub 'arn:${AWS::Partition}:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${Function.Arn}/invocations' responses: '202': statusCode: '202' selectionPattern: \"\" responses: '202': description: successfully saved security: - Authorizer: [] components: securitySchemes: Authorizer: type: 'request' name: 'Authorization' in: 'header' x-amazon-apigateway-authorizer: authorizerUri: !FindInMap [ !Ref StageName, !Ref \"AWS::Region\", AuthArn ] identitySource: 'method.request.header.X-Authorization,method.request.header.X-Date' type: 'request'
你的模板存在几个关键问题,导致授权器无法正常创建和关联:
请求头名称不匹配
你在securitySchemes中定义的name: 'Authorization',但identitySource里指定的身份来源是X-Authorization,API Gateway会根据name字段匹配请求头,名称不一致会导致授权器无法正确识别身份信息。需将name改为X-Authorization,或把identitySource中的对应字段改为Authorization,保持两者一致。授权器配置缺失必要项
对于请求类型的授权器,建议明确添加authorizerResultTtlInSeconds(缓存过期时间,可选但能优化性能);更关键的是,要确保授权器Lambda函数拥有被API Gateway调用的权限——需额外配置AWS::Lambda::Permission资源,否则API Gateway无法触发授权器。模板转义字符异常
模板中存在多余的转义字符(如\"),YAML格式下不需要对双引号转义,这会导致CloudFormation解析模板时出现异常。例如Name: !Sub \"API Gateway\"应改为Name: !Sub "API Gateway",selectionPattern: \"\"改为selectionPattern: ""。授权器Lambda权限配置
必须为授权器Lambda添加权限,允许API Gateway调用它,示例配置如下:AuthLambdaInvokePermission: Type: AWS::Lambda::Permission Properties: FunctionName: !Ref AuthFunction Action: lambda:InvokeFunction Principal: apigateway.amazonaws.com SourceArn: !Sub 'arn:${AWS::Partition}:execute-api:${AWS::Region}:${AWS::AccountId}:${ServerlessApi}/*/POST/callHistoryAsync'
修复后的securitySchemes核心部分示例:
components: securitySchemes: Authorizer: type: 'request' name: 'X-Authorization' # 与identitySource中的请求头名称统一 in: 'header' x-amazon-apigateway-authorizer: authorizerUri: !FindInMap [ !Ref StageName, !Ref "AWS::Region", AuthArn ] identitySource: 'method.request.header.X-Authorization,method.request.header.X-Date' type: 'request' authorizerResultTtlInSeconds: 300 # 设置授权结果缓存时间
内容的提问来源于stack exchange,提问作者elena

