开启FailOnWarnings后,AWS API Gateway无法获取Apple OpenID配置求助
问题场景
我用 AWS SAM 定义了一个 HttpApi,配置了 Apple Sign In 的 JWT 授权器,当设置FailOnWarnings: true时部署失败,报错提示无法连接 Apple 的 OIDC 发现端点https://appleid.apple.com/.well-known/openid-configuration,但我确认这个端点是可用且有效的。移除FailOnWarnings参数后能正常部署,授权器也能正常工作,但我希望保持严格模式。
SAM 模板代码:
MyApi: Type: AWS::Serverless::HttpApi Properties: FailOnWarnings: true # 移除该参数可成功部署 Auth: Authorizers: AppleSignIn: JwtConfiguration: audience: - com.domain.MyApp issuer: "https://appleid.apple.com" IdentitySource: "$request.header.Authorization"
部署报错信息:
资源处理程序返回消息:
导入期间发现警告:无法创建授权器'AppleSignIn':连接颁发者https://appleid.apple.com的https://appleid.apple.com/.well-known/openid-configuration时捕获异常。请稍后重试。错误:无效的颁发者:https://appleid.apple.com。颁发者必须有一个以'/.well-known/openid-configuration'结尾的有效发现端点。忽略。
(Service: AmazonApiGatewayV2; Status Code: 400; Error Code: BadRequestException; Request ID: 409removed8b6; Proxy: null) (Service: null; Status Code: 404; Error Code: BadRequestException; Request ID: null; Proxy: null) (RequestToken: 43fremoved3b9, HandlerErrorCode: GeneralServiceException)
可能原因
- AWS API Gateway 服务在部署阶段访问 Apple 的 OIDC 发现端点时出现临时网络波动,导致检测失败;而实际运行时授权流程的网络连接恢复正常,所以移除
FailOnWarnings后授权器能正常工作。 - API Gateway 部署时的 OIDC 端点检测逻辑和运行时逻辑存在差异,比如部署时的超时时间更短,或者使用了缓存的无效记录。
解决方案
1. 手动指定 JWKS URI 绕过自动发现
直接在 JWT 配置里添加 Apple 官方的 JWKS 地址,让 API Gateway 跳过 OIDC 发现端点的检测步骤,这样部署时就不会触发这个错误。修改后的模板如下:
MyApi: Type: AWS::Serverless::HttpApi Properties: FailOnWarnings: true Auth: Authorizers: AppleSignIn: JwtConfiguration: audience: - com.domain.MyApp issuer: "https://appleid.apple.com" jwksUri: "https://appleid.apple.com/auth/keys" # 手动指定JWKS地址 IdentitySource: "$request.header.Authorization"
Apple 的 JWKS 地址是固定的,手动配置后,API Gateway 会直接从该地址获取验证 JWT 所需的公钥,和自动发现的结果完全一致,同时能避开部署时的端点检测问题。
2. 多次重试部署
如果是临时网络问题,多试几次部署操作,大概率能避开网络波动,成功完成部署。
3. 延迟部署(可选)
如果重试无效,可以尝试给 API 资源添加部署延迟,比如通过自定义资源实现等待逻辑,但这种方式比较繁琐,优先推荐前两种方案。
内容的提问来源于stack exchange,提问作者Travis

