You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS SAM如何覆盖自动生成资源?添加API Gateway验证模型方案

为SAM自动生成的API Gateway添加验证模型的解决方案

SAM自动生成的ServerlessRestApi属于隐式资源,无法直接修改其属性来添加验证模型。你可以通过以下两种方案实现需求:

方案一:显式定义API Gateway资源(推荐)

通过手动创建AWS::Serverless::Api资源,完全掌控API结构,包含验证模型和请求验证器的定义,再让Lambda函数绑定到这个自定义API。

修改后的模板示例:

AWSTemplateFormatVersion: "2010-09-09"
Description: >-
  example-rest-api

Transform:
- AWS::Serverless-2016-10-31

Resources:
  # 显式定义API Gateway,包含验证规则
  MyRestApi:
    Type: AWS::Serverless::Api
    Properties:
      StageName: Prod
      DefinitionBody:
        swagger: '2.0'
        info:
          title: !Ref AWS::StackName
        paths:
          /:
            get:
              x-amazon-apigateway-integration:
                uri: !Sub arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${allEquipmentsFunction.Arn}/invocations
                httpMethod: POST
                type: aws_proxy
            post:
              x-amazon-apigateway-integration:
                uri: !Sub arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${saveEquipmentFunction.Arn}/invocations
                httpMethod: POST
                type: aws_proxy
              # 配置请求验证规则
              parameters:
                method.request.header.Content-Type:
                  required: true
                  type: string
              requestModels:
                application/json: EquipmentModel
              requestValidator: ValidateBodyAndHeaders
        # 定义JSON验证模型
        definitions:
          EquipmentModel:
            type: object
            properties:
              name:
                type: string
              type:
                type: string
            required:
              - name
        # 定义请求验证器
        x-amazon-apigateway-request-validators:
          ValidateBodyAndHeaders:
            validateRequestBody: true
            validateRequestParameters: true

  allEquipmentsFunction:
    Type: AWS::Serverless::Function
    Properties:
      Handler: src/handlers/myModel.getAll
      Runtime: nodejs18.x
      Architectures:
      - x86_64
      MemorySize: 128
      Timeout: 100
      Description: example description
      Events:
        ApiEvent:
          Type: Api
          Properties:
            RestApiId: !Ref MyRestApi # 绑定到自定义API
            Path: /
            Method: GET

  saveEquipmentFunction:
    Type: AWS::Serverless::Function
    Properties:
      Handler: src/handlers/myModel.save
      Runtime: nodejs18.x
      Architectures:
      - x86_64
      MemorySize: 128
      Timeout: 100
      Description: example description
      Events:
        Api:
          Type: Api
          Properties:
            RestApiId: !Ref MyRestApi # 绑定到自定义API
            Path: /
            Method: POST

  ApplicationResourceGroup:
    Type: AWS::ResourceGroups::Group
    Properties:
      Name:
        Fn::Join:
        - ''
        - - ApplicationInsights-SAM-
          - Ref: AWS::StackName
      ResourceQuery:
        Type: CLOUDFORMATION_STACK_1_0
  ApplicationInsightsMonitoring:
    Type: AWS::ApplicationInsights::Application
    Properties:
      ResourceGroupName:
        Fn::Join:
        - ''
        - - ApplicationInsights-SAM-
          - Ref: AWS::StackName
      AutoConfigurationEnabled: 'true'
    DependsOn: ApplicationResourceGroup

Outputs:
  WebEndpoint:
    Description: API Gateway endpoint URL for Prod stage
    Value: !Sub "https://${MyRestApi}.execute-api.${AWS::Region}.amazonaws.com/Prod/"

此方案中,SAM不会再生成默认的ServerlessRestApi,所有API配置完全由你控制,适合需要复杂API规则的场景。

方案二:为自动生成的API添加验证资源

如果仅需简单的验证规则,可直接为SAM自动生成的ServerlessRestApi添加模型和验证器资源,再在Lambda事件中引用。

示例模板片段:

Resources:
  # 新增验证模型
  EquipmentModel:
    Type: AWS::ApiGateway::Model
    Properties:
      RestApiId: !Ref ServerlessRestApi
      ContentType: application/json
      Name: EquipmentModel
      Schema:
        type: object
        properties:
          name:
            type: string
          type:
            type: string
        required:
          - name

  # 新增请求验证器
  RequestValidator:
    Type: AWS::ApiGateway::RequestValidator
    Properties:
      RestApiId: !Ref ServerlessRestApi
      Name: ValidateBody
      ValidateRequestBody: true
      ValidateRequestParameters: false

  # 修改POST方法的Lambda事件,引用验证规则
  saveEquipmentFunction:
    Type: AWS::Serverless::Function
    Properties:
      # 原有属性不变
      Events:
        Api:
          Type: Api
          Properties:
            Path: /
            Method: POST
            RequestModels:
              application/json: !Ref EquipmentModel
            RequestValidator: !Ref RequestValidator

这种方式无需替换自动生成的API,适合快速添加基础验证规则的场景,但API整体结构仍由SAM控制,灵活性有限。

内容的提问来源于stack exchange,提问作者Pehr Sibusiso

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 22:05:25