You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何复用CDK创建的自定义授权器给其他仓库的AWS ApiGW方法

跨CDK仓库复用APIGW自定义授权器实现方案

CDK官方暂未提供直接导入现有APIGW自定义授权器的内置方法,可通过以下两种方案实现复用:


前提准备

首先需要获取现有自定义授权器的核心固定属性,两种方案均需要使用:

  • 授权器ARN
  • 授权器ID
  • 授权器类型(TOKEN/REQUEST)
  • 身份来源配置(如method.request.header.Authorization)
  • 授权结果缓存TTL时长

方案1:跨栈导出引用(适用同账号同区域场景)

该方案通过CDK原生的栈输出/导入能力传递属性,无需硬编码配置。

  • 第一步:在原有创建自定义授权器的CDK仓库中,通过CfnOutput导出核心属性并配置全局导出名:
import { CfnOutput, Duration, Stack, StackProps } from 'aws-cdk-lib';
import * as apigateway from 'aws-cdk-lib/aws-apigateway';
import * as lambda from 'aws-cdk-lib/aws-lambda';
import { Construct } from 'constructs';

// 原有授权器栈示例
export class OriginalAuthStack extends Stack {
  constructor(scope: Construct, id: string, props?: StackProps) {
    super(scope, id, props);

    const authHandler = new lambda.Function(this, 'AuthHandler', {
      // 原有Lambda配置
      runtime: lambda.Runtime.NODEJS_18_X,
      handler: 'index.handler',
      code: lambda.Code.fromAsset('auth')
    });

    const customAuthorizer = new apigateway.RequestAuthorizer(this, 'CustomAuthorizer', {
      handler: authHandler,
      identitySources: [apigateway.IdentitySource.header('Authorization')],
      resultsCacheTtl: Duration.minutes(5)
    });

    // 导出核心属性,配置全局唯一的exportName
    new CfnOutput(this, 'CustomAuthorizerArn', {
      value: customAuthorizer.authorizerArn,
      exportName: 'SharedCustomAuthorizerArn'
    });
    new CfnOutput(this, 'CustomAuthorizerId', {
      value: customAuthorizer.authorizerId,
      exportName: 'SharedCustomAuthorizerId'
    });
  }
}
  • 第二步:在新的APIGW仓库中,通过Fn.importValue导入属性,使用Authorizer.fromAuthorizerAttributes方法构造授权器实例,直接绑定到API方法即可:
import { Fn, Stack, StackProps } from 'aws-cdk-lib';
import * as apigateway from 'aws-cdk-lib/aws-apigateway';
import * as lambda from 'aws-cdk-lib/aws-lambda';
import { Construct } from 'constructs';

export class NewApiStack extends Stack {
  constructor(scope: Construct, id: string, props?: StackProps) {
    super(scope, id, props);

    const api = new apigateway.RestApi(this, 'NewApi', {
      restApiName: 'NewServiceApi'
    });

    const businessHandler = new lambda.Function(this, 'BusinessHandler', {
      runtime: lambda.Runtime.NODEJS_18_X,
      handler: 'index.handler',
      code: lambda.Code.fromAsset('business')
    });

    // 导入原有授权器属性
    const importedAuthorizerArn = Fn.importValue('SharedCustomAuthorizerArn');
    const importedAuthorizerId = Fn.importValue('SharedCustomAuthorizerId');

    // 构造授权器实例
    const importedAuthorizer = apigateway.Authorizer.fromAuthorizerAttributes(this, 'ImportedAuth', {
      authorizerArn: importedAuthorizerArn,
      authorizerId: importedAuthorizerId,
      // 此处类型和原有授权器保持一致,TOKEN类型则填AuthorizationType.CUSTOM
      authorizationType: apigateway.AuthorizationType.REQUEST
    });

    // 绑定授权器到API方法
    api.root.addMethod('GET', new apigateway.LambdaIntegration(businessHandler), {
      authorizer: importedAuthorizer
    });
  }
}

方案2:属性直接注入(适用跨账号/跨区域场景)

如果两个栈部署在不同账号或区域,无法通过跨栈导出引用传递属性,可以按以下步骤操作:

  • 第一步:原有授权器部署完成后,通过AWS控制台、CLI或SDK获取授权器的核心属性
  • 第二步:将属性硬编码到新仓库的CDK配置中,或存储到SSM参数存储、Secrets Manager中,部署时动态读取
  • 第三步:使用读取到的属性调用Authorizer.fromAuthorizerAttributes构造授权器实例,绑定逻辑和方案1完全一致

注意事项

  • 需确保新APIGW有调用授权器的权限:可在原有授权器关联的Lambda资源策略中,添加允许新APIGW所属账号或API ARN调用的规则
  • 构造导入的授权器实例时,所有配置(授权类型、身份来源、缓存TTL)必须和原有授权器完全一致,否则会出现校验异常
  • 跨区域复用的场景,需要保证授权器和新APIGW在同一区域,APIGW自定义授权器不支持跨区域调用

内容的提问来源于stack exchange,提问作者Michael Balber

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.04 09:15:01