无请求体的GET请求遭AWS API Gateway返回HTTP 413错误
GET请求无请求体却触发AWS API Gateway 413「Request Entity Too Large」错误排查
向AWS API Gateway发送无请求体的GET请求下载29MB+文件时,收到HTTP 413错误。按HTTP规范,413针对请求体过大,但GET请求无请求体;且QA环境可正常获取同一文件,生产环境配置为:仅$default阶段,路由ANY /path/{proxy+}集成ALB,无授权配置,已对比QA与生产的API Gateway配置未发现差异。
以下是curl命令执行详情:
curl -v https://api-gateway-host.us-east-1.amazonaws.com/path/to/file * Trying <IP address>:443... * Connected to api-gateway-host.us-east-1.amazonaws.com (<IP address>) port 443 (#0) * ALPN, offering h2 * ALPN, offering http/1.1 * successfully set certificate verify locations: * CAfile: /etc/ssl/cert.pem * CApath: none * TLSv1.2 (OUT), TLS handshake, Client hello (1): * TLSv1.2 (IN), TLS handshake, Server hello (2): * TLSv1.2 (IN), TLS handshake, Certificate (11): * TLSv1.2 (IN), TLS handshake, Server key exchange (12): * TLSv1.2 (IN), TLS handshake, Server finished (14): * TLSv1.2 (OUT), TLS handshake, Client key exchange (16): * TLSv1.2 (OUT), TLS change cipher, Change cipher spec (1): * TLSv1.2 (OUT), TLS handshake, Finished (20): * TLSv1.2 (IN), TLS change cipher, Change cipher spec (1): * TLSv1.2 (IN), TLS handshake, Finished (20): * SSL connection using TLSv1.2 / ECDHE-RSA-AES128-GCM-SHA256 * ALPN, server accepted to use h2 * Server certificate: * subject: CN=*.execute-api.us-east-1.amazonaws.com * start date: Aug 24 00:00:00 2022 GMT * expire date: Sep 22 23:59:59 2023 GMT * subjectAltName: host "api-gateway-host" matched cert's "*.execute-api.us-east-1.amazonaws.com" * issuer: C=US; O=Amazon; OU=Server CA 1B; CN=Amazon * SSL certificate verify ok. * Using HTTP2, server supports multi-use * Connection state changed (HTTP/2 confirmed) * Copying HTTP/2 data in stream buffer to connection buffer after upgrade: len=0 * Using Stream ID: 1 (easy handle 0x7f8fed80d400) > GET /path/to/file HTTP/2 > Host: api-gateway-host.us-east-1.amazonaws.com > user-agent: curl/7.77.0 > accept: */* > * Connection state changed (MAX_CONCURRENT_STREAMS == 128)! < HTTP/2 413 < date: Thu, 27 Oct 2022 21:43:06 GMT < content-type: application/json < content-length: 38 < apigw-requestid: arw4qjGbIAMEMugqerq= < vary: Origin < vary: Access-Control-Request-Method < vary: Access-Control-Request-Headers < x-content-type-options: nosniff < x-xss-protection: 1; mode=block < cache-control: no-cache, no-store, max-age=0, must-revalidate < pragma: no-cache < expires: 0 < * Connection #0 to host api-gateway-host.us-east-1.amazonaws.com left intact {"message":"Request Entity Too Large"}
可能的原因及排查步骤
1. API Gateway响应 payload 大小限制
AWS API Gateway对响应大小有默认限制,且部分场景下会将响应过大映射为413错误:
- REST API默认最大响应大小为10MB
- HTTP API默认最大响应大小为10MB,可通过阶段配置调整至最大29MB
排查:
- 确认API类型:HTTP API需检查生产环境阶段的
Payload size limit是否达标;REST API需检查集成设置或二进制支持配置 - 再次核对QA与生产环境的阶段响应限制配置,避免遗漏细节
2. ALB侧响应大小限制
集成的ALB默认最大响应大小为1MB,若后端返回超过该值,ALB会截断响应,API Gateway可能将此错误映射为413。
排查:
- 检查生产环境ALB的
Maximum response size配置,确认是否已调整至大于文件大小的值 - 对比QA环境ALB的同项配置,确认是否存在差异
3. 传输链路异常
ALB返回的响应在传输至API Gateway时若出现分块传输错误等异常,API Gateway可能误判为请求体过大。
排查:
- 启用API Gateway的
Full request/response logging,查看日志中是否有响应大小相关报错 - 查看ALB访问日志,确认ALB是否成功返回完整响应给API Gateway
4. HTTP/2协议适配问题
curl请求使用HTTP/2,部分场景下HTTP/2的帧大小限制可能触发该错误。
排查:
- 尝试用HTTP/1.1发起请求:
curl -v --http1.1 https://api-gateway-host.us-east-1.amazonaws.com/path/to/file,验证是否能成功获取文件 - 对比QA环境是否使用HTTP/1.1协议
解决方案建议
- 若为HTTP API,将阶段
Payload size limit调整至文件大小以上(最大支持29MB,超29MB需改用分段下载或S3预签名URL) - 调整ALB的
Maximum response size至大于文件大小的值 - REST API需启用二进制支持并配置正确的媒体类型,确保后端响应头(如
Content-Type)设置正确 - 若HTTP/2存在适配问题,可在API Gateway阶段禁用HTTP/2,强制使用HTTP/1.1
内容的提问来源于stack exchange,提问作者Jack Straw
相关产品推荐
相关产品推荐

