API Gateway V2集成SQS的CloudFormation模板报Not Found错误
问题排查:API Gateway HTTP API集成SQS返回"Not Found"
问题场景
使用CloudFormation模板部署与SQS集成的HTTP API,控制台显示正常,但POST请求返回:
{ "message": "Not Found" }
原模板如下:
AWSTemplateFormatVersion: "2010-09-09" Resources: ExecutionRole: Type: AWS::IAM::Role Properties: RoleName: ExecutionRole AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Service: - apigateway.amazonaws.com Action: - sts:AssumeRole Path: "/" Policies: - PolicyName: root PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - sqs:SendMessage - sqs:ReceiveMessage - sqs:DeleteMessage Resource: !Sub "arn:aws:sqs:${AWS::Region}:${AWS::AccountId}:sample-queue" - Effect: Allow Action: lambda:InvokeFunction Resource: "*" Queue: Type: AWS::SQS::Queue Properties: QueueName: sample-queue API: Type: AWS::ApiGatewayV2::Api Properties: Body: openapi: "3.0.1" info: title: "HttpApi" version: "2022-09-29 15:59:08UTC" paths: /: post: responses: default: description: "Default response for POST /" x-amazon-apigateway-integration: integrationSubtype: "SQS-SendMessage" credentials: !Sub "arn:aws:iam::${AWS::AccountId}:role/ExecutionRole" requestParameters: MessageBody: "$request.body" QueueUrl: !Sub "https://sqs.${AWS::Region}.amazonaws.com/${AWS::AccountId}/sample-queue" payloadFormatVersion: "1.0" type: "aws_proxy" connectionType: "INTERNET" timeoutInMillis: 30000 x-amazon-apigateway-importexport-version: "1.0" Stage: Type: AWS::ApiGatewayV2::Stage Properties: StageName: v1 ApiId: !Ref API Deployment: Type: AWS::ApiGatewayV2::Deployment Properties: ApiId: !Ref API StageName: !Ref Stage
问题原因及修复方案
- 集成类型错误:SQS服务集成的
type字段需设置为aws,而非aws_proxy。aws_proxy仅适用于Lambda代理集成,AWS服务集成必须使用aws类型。 - Deployment缺少依赖关系:Deployment资源需添加
DependsOn: API,确保API的OpenAPI定义完全加载后再执行部署,否则会导致部署时API路径未生效。 - ARN和QueueUrl引用优化:执行角色的Credentials改用
!GetAtt ExecutionRole.Arn替代硬编码ARN;QueueUrl直接用!Ref Queue获取队列URL,避免硬拼格式错误。 - 移除无用权限:原模板中
lambda:InvokeFunction权限为冗余配置,可移除以遵循最小权限原则。
修复后的模板
AWSTemplateFormatVersion: "2010-09-09" Resources: ExecutionRole: Type: AWS::IAM::Role Properties: RoleName: ExecutionRole AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Service: - apigateway.amazonaws.com Action: - sts:AssumeRole Path: "/" Policies: - PolicyName: SQSIntegrationPolicy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - sqs:SendMessage Resource: !GetAtt Queue.Arn Queue: Type: AWS::SQS::Queue Properties: QueueName: sample-queue API: Type: AWS::ApiGatewayV2::Api Properties: Body: openapi: "3.0.1" info: title: "HttpApi" version: "2022-09-29 15:59:08UTC" paths: /: post: responses: default: description: "Default response for POST /" x-amazon-apigateway-integration: integrationSubtype: "SQS-SendMessage" credentials: !GetAtt ExecutionRole.Arn requestParameters: MessageBody: "$request.body" QueueUrl: !Ref Queue payloadFormatVersion: "1.0" type: "aws" connectionType: "INTERNET" timeoutInMillis: 30000 x-amazon-apigateway-importexport-version: "1.0" Stage: Type: AWS::ApiGatewayV2::Stage Properties: StageName: v1 ApiId: !Ref API Deployment: Type: AWS::ApiGatewayV2::Deployment DependsOn: API Properties: ApiId: !Ref API StageName: !Ref Stage
验证步骤
- 重新部署修复后的CloudFormation模板。
- 从控制台复制API的Invoke URL,发送携带任意请求体的POST请求。
- 检查SQS队列是否收到消息,确认API返回200状态码。
内容的提问来源于stack exchange,提问作者Vikas
相关产品推荐
相关产品推荐

