使用Terraform部署API Gateway集成SNS时遇BadRequestException错误
问题解决:API Gateway集成SNS的Terraform错误
错误原因
触发Invalid mapping expression specified错误的核心原因是:在API Gateway集成的request_parameters中,直接将SNS Topic的ARN作为值传递时,API Gateway会把该值当作映射表达式解析,而非静态字符串。API Gateway要求静态值必须用单引号(')包裹,否则会被当作表达式尝试解析,最终导致验证失败。
修复方案
修改aws_api_gateway_integration资源中的request_parameters部分,将Topic ARN用单引号包裹:
resource "aws_api_gateway_integration" "integration_get" { count = var.application_enabled ? 1 : 0 rest_api_id = aws_api_gateway_rest_api.api_trumpic[count.index].id resource_id = aws_api_gateway_resource.resource_trumpic[count.index].id http_method = aws_api_gateway_method.method_get[count.index].http_method credentials = aws_iam_role.cloudwatch[count.index].arn integration_http_method = "GET" type = "AWS" uri = "arn:aws:apigateway:us-west-2:sns:path//" request_parameters = { "integration.request.querystring.Message" = "method.request.querystring.xml" # 用单引号包裹静态ARN值,避免被当作表达式解析 "integration.request.querystring.TopicArn" = "'${aws_sns_topic.com-service-receive-notification-inbound[count.index].arn}'" } }
额外注意事项
- 确保关联的IAM角色(
aws_iam_role.cloudwatch)拥有调用SNSPublish动作的权限,可添加如下策略语句:{ "Effect": "Allow", "Action": "sns:Publish", "Resource": "${aws_sns_topic.com-service-receive-notification-inbound[count.index].arn}" } - 当前使用的API Gateway集成URI格式
arn:aws:apigateway:us-west-2:sns:path//符合SNS GET请求的集成要求,可正常将请求参数映射到SNS的Publish API参数。
内容的提问来源于stack exchange,提问作者Cho Cho
相关产品推荐
相关产品推荐

