创建AWS::ApiGateway::Authorizer返回AlreadyExists错误原因
问题背景
已有名为 My-Authorizer 的Lambda函数,通过Serverless框架结合CloudFormation资源部署API Gateway时,配置了指向该Lambda的授权器资源,配置片段如下:
Resources: ApiGateway: Type: AWS::ApiGateway::RestApi Properties: Name: "${self:service}-test" # 其余资源省略 MyAuthorizer: Type: AWS::ApiGateway::Authorizer DependsOn: ApiGateway Properties: Name: My-Authorizer Type: REQUEST RestApiId: Ref: ApiGateway AuthorizerUri: "arn:aws:apigateway:${self:custom.aws_region}:lambda:path/2015-03-31/functions/arn:aws:lambda:${self:custom.aws_region}:${self:custom.aws_account_id}:function:My-Authorizer/invocations"
部署过程中MyAuthorizer资源返回CREATE_FAILED状态,错误信息如下:
Resource handler returned message: "Invalid request input (Service: ApiGateway, Status Code: 400, Request ID: <some-request-id>)" (RequestToken: <some-request-token>, HandlerErrorCode: AlreadyExists)
已确认当前CloudFormation栈内不存在名为MyAuthorizer的存量资源,需要定位报错根因。
根因说明
该报错和当前CloudFormation栈内的资源逻辑ID无关,核心原因是API Gateway授权器的名称校验规则为同账号、同区域下跨所有REST API全局唯一,并非单栈、单API维度独立命名。
你配置的授权器名称My-Authorizer已经被同账号同区域下其他REST API(不管是否属于当前CloudFormation栈管理)创建的同名授权器占用,因此创建时返回AlreadyExists错误,错误信息前缀的Invalid request input是CloudFormation资源处理器的通用包装提示,不代表参数格式错误。
修复方案
- 修改当前授权器的
Name属性,使用带业务标识、环境标识的全局唯一名称,例如${self:service}-${sls:stage}-api-authorizer,避免命名冲突 - 登录API Gateway控制台,切换到对应区域查看所有授权器列表,找到名称为
My-Authorizer的存量资源,如果是废弃测试资源可直接删除后重新部署 - 如果存量同名授权器是需要复用的资源,不要在当前栈重复创建授权器资源,直接引用已有授权器的ID绑定到API方法即可
内容的提问来源于stack exchange,提问作者Ash
相关产品推荐
相关产品推荐

