You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用SAM YAML模板将REST API端点设为私有未生效,求排查

问题排查与修正方案

核心问题分析

你的配置存在几个关键错误,导致API端点无法切换为Private:

  • Lambda函数冗余配置:AWS::Serverless::Function中的EndpointConfiguration属性属于API Gateway资源,Lambda无需该配置,多余设置会干扰SAM的资源关联逻辑。
  • VPC端点策略资源ARN无效:你使用了占位符*******,无法正确关联到创建的ServerlessApi,导致策略无法限制API访问范围,也会影响API与VPC端点的绑定。
  • 潜在变量缺失风险:若Environment参数未提前定义,StageName: !Ref "Environment"会引发隐性部署问题,虽无报错但会影响API正常创建。

修正后的配置代码

Parameters:
  # 补充定义必要参数,避免引用失败
  Environment:
    Type: String
    Default: prod
  tgwSubnetA:
    Type: AWS::EC2::Subnet::Id
  tgwSubnetB:
    Type: AWS::EC2::Subnet::Id
  tgwSubnetC:
    Type: AWS::EC2::Subnet::Id
  osSecurityGroup:
    Type: AWS::EC2::SecurityGroup::Id
  vpc:
    Type: AWS::EC2::VPC::Id

Resources:
  HealthFunction:
    Type: AWS::Serverless::Function 
    Properties:
      CodeUri: healthcheck
      Handler: healthcheck
      Runtime: go1.x
      Architectures:
        - x86_64
      Events:
        CatchAll:
          Type: Api 
          Properties:
            Path: /healthcheck
            Method: GET
            RestApiId: !Ref ServerlessApi
      Environment:
        Variables:
          DEFAULT_NAME: Ok

  APIGatewayVpcEndpoint:
    Type: "AWS::EC2::VPCEndpoint"
    Properties:
      SubnetIds:
        - !Ref tgwSubnetA
        - !Ref tgwSubnetB
        - !Ref tgwSubnetC
      SecurityGroupIds:
        - !Ref osSecurityGroup
      ServiceName: !Sub com.amazonaws.${AWS::Region}.execute-api
      VpcId: !Ref vpc
      VpcEndpointType: "Interface"
      PrivateDnsEnabled: false
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: "Allow"
            Principal: "*"
            Action:
              - "execute-api:Invoke"
            Resource:
              # 替换为正确的API ARN格式,关联目标ServerlessApi
              - !Sub "arn:aws:execute-api:${AWS::Region}:${AWS::AccountId}:${ServerlessApi}/${Environment}/*"

  ServerlessApi:
    Type: "AWS::Serverless::Api"
    Properties:
      StageName: !Ref "Environment"
      EndpointConfiguration:
        Type: "PRIVATE"
        VPCEndpointIds:
          - !Ref APIGatewayVpcEndpoint

验证步骤

  1. 部署完成后,进入API Gateway控制台,检查对应API的端点类型是否显示为PRIVATE。
  2. 确认VPC端点状态为Available,且已关联到目标API。
  3. 测试访问:仅能通过VPC内资源使用VPC端点的DNS名称访问API,公网无法访问则表示配置生效。

内容的提问来源于stack exchange,提问作者Alina

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 02:55:30