You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

API Gateway LambdaRestApi自定义域名请求时出现ECONNREFUSED错误

自定义域名绑定API Gateway后无法访问的问题排查与解决

我查过相关帖子,其中有一篇内容和我的情况最接近,但对里面的回答理解不透彻。

我通过AWS CDK创建LambdaRestApi,并用Route53托管区配置自定义域名作为端点。除了Route53别名记录连接API自定义域名这一步外,其他资源创建都正常。调用API的默认URL完全没问题,但访问自定义域名或Route53别名时,会报错Error: connect ECONNREFUSED。我怀疑问题和HTTP/HTTPS请求有关,但没法深入排查。

我的AWS CDK代码如下:

from aws_cdk import (
    Stack,
    aws_apigateway as apigateway,
    aws_lambda as lambda_,
    aws_iam as iam,
    aws_ecr as ecr,
    aws_route53 as route53,
    aws_route53_targets as targets,
    aws_certificatemanager as cman
)
from constructs import Construct


class ApiStack(Stack):

    def __init__(self, scope: Construct, construct_id: str, **kwargs) -> None:
        super().__init__(scope, construct_id,  **kwargs)

        repo_ = ecr.Repository.from_repository_arn(self,
                    'repo',
                    repository_arn=<image_arn>
                        
        tag_ = <image_tag>

        backend = lambda_.DockerImageFunction(self, 'myLambda',
                    code=lambda_.DockerImageCode.from_ecr(repository=repo_,
                                                          tag=tag_),
                    architecture=lambda_.Architecture.X86_64
                  )

        certificate = cman.Certificate.from_certificate_arn(self,
                                                            'cert', <cert ARN>
                                                            )

        api = apigateway.LambdaRestApi(self, "myAPI",
            handler=backend,
            proxy=False,
            endpoint_configuration=apigateway.EndpointConfiguration(
                                        types=[apigateway.EndpointType.REGIONAL]),
            domain_name=apigateway.DomainNameOptions(
                                    domain_name=<custom-domain-name>,
                                    certificate=certificate
    )
        )

        hosted_zone = route53.HostedZone.from_lookup(self, 'myHostedZone',
                                                domain_name=<hosted-zone-domain-name>)
                                                     )

        route53.ARecord(self, 'Arecord',
                        zone=hosted_zone,
                        target=route53.RecordTarget.from_alias(targets.ApiGateway(api)),
                        record_name=<domain-name>
                        )

排查与解决步骤

1. 检查证书与API Gateway区域一致性

  • ACM证书必须和API Gateway的REGIONAL端点在同一个区域,否则自定义域名的HTTPS配置会失效。如果证书在其他区域,要么把证书移到对应区域,要么重新在API所在区域申请证书。

2. 补全API Gateway基础路径映射

  • 你启用了proxy=False但未配置基础路径映射,API Gateway自定义域名需要明确绑定到API的某个阶段(比如默认的prod阶段),否则请求无法路由到后端Lambda。在创建api实例后添加以下代码:
    # 将自定义域名根路径映射到API的默认部署阶段
    api.domain_name.add_base_path_mapping(api, stage=api.deployment_stage)
    

3. 验证Route53别名目标正确性

  • 确认Route53的A记录别名指向的是API Gateway自定义域名的专属域名(格式类似d-xxxxxx.execute-api.region.amazonaws.com),而非API的默认调用域名。可以通过API Gateway控制台的"自定义域名"页面获取该地址,再对比Route53的记录目标。

4. 等待DNS解析生效

  • Route53别名记录的生效可能需要5-10分钟,首次配置时可以用dig或nslookup命令验证解析结果:
    dig <custom-domain-name>
    

5. 检查API部署状态

  • 确保API已完成部署,CDK创建LambdaRestApi时默认会生成部署,但如果后续修改过API资源,需重新触发部署以更新后端映射。

内容的提问来源于stack exchange,提问作者A Simple Programmer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 07:05:33