You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

开启FailOnWarnings后,AWS API Gateway无法获取Apple OpenID配置求助

AWS SAM HttpApi 开启 FailOnWarnings 时 Apple Sign In 授权器部署失败问题解决

问题场景

我用 AWS SAM 定义了一个 HttpApi,配置了 Apple Sign In 的 JWT 授权器,当设置FailOnWarnings: true时部署失败,报错提示无法连接 Apple 的 OIDC 发现端点https://appleid.apple.com/.well-known/openid-configuration,但我确认这个端点是可用且有效的。移除FailOnWarnings参数后能正常部署,授权器也能正常工作,但我希望保持严格模式。

SAM 模板代码:

MyApi:
  Type: AWS::Serverless::HttpApi
  Properties:
    FailOnWarnings: true     # 移除该参数可成功部署
    Auth:
      Authorizers:
        AppleSignIn:
          JwtConfiguration:
            audience:
            - com.domain.MyApp
            issuer: "https://appleid.apple.com"
          IdentitySource: "$request.header.Authorization"

部署报错信息:

资源处理程序返回消息:
导入期间发现警告:无法创建授权器'AppleSignIn':连接颁发者https://appleid.apple.com的https://appleid.apple.com/.well-known/openid-configuration时捕获异常。请稍后重试。错误:无效的颁发者:https://appleid.apple.com。颁发者必须有一个以'/.well-known/openid-configuration'结尾的有效发现端点。忽略。
(Service: AmazonApiGatewayV2; Status Code: 400; Error Code: BadRequestException; Request ID: 409removed8b6; Proxy: null) (Service: null; Status Code: 404; Error Code: BadRequestException; Request ID: null; Proxy: null) (RequestToken: 43fremoved3b9, HandlerErrorCode: GeneralServiceException)

可能原因

  • AWS API Gateway 服务在部署阶段访问 Apple 的 OIDC 发现端点时出现临时网络波动,导致检测失败;而实际运行时授权流程的网络连接恢复正常,所以移除FailOnWarnings后授权器能正常工作。
  • API Gateway 部署时的 OIDC 端点检测逻辑和运行时逻辑存在差异,比如部署时的超时时间更短,或者使用了缓存的无效记录。

解决方案

1. 手动指定 JWKS URI 绕过自动发现

直接在 JWT 配置里添加 Apple 官方的 JWKS 地址,让 API Gateway 跳过 OIDC 发现端点的检测步骤,这样部署时就不会触发这个错误。修改后的模板如下:

MyApi:
  Type: AWS::Serverless::HttpApi
  Properties:
    FailOnWarnings: true
    Auth:
      Authorizers:
        AppleSignIn:
          JwtConfiguration:
            audience:
            - com.domain.MyApp
            issuer: "https://appleid.apple.com"
            jwksUri: "https://appleid.apple.com/auth/keys"  # 手动指定JWKS地址
          IdentitySource: "$request.header.Authorization"

Apple 的 JWKS 地址是固定的,手动配置后,API Gateway 会直接从该地址获取验证 JWT 所需的公钥,和自动发现的结果完全一致,同时能避开部署时的端点检测问题。

2. 多次重试部署

如果是临时网络问题,多试几次部署操作,大概率能避开网络波动,成功完成部署。

3. 延迟部署(可选)

如果重试无效,可以尝试给 API 资源添加部署延迟,比如通过自定义资源实现等待逻辑,但这种方式比较繁琐,优先推荐前两种方案。

内容的提问来源于stack exchange,提问作者Travis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 19:31:04