You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在OpenAPI端点定义中引用现有API Gateway Authorizer(SAM/CF模板)

问题解答:在SAM/CloudFormation中引用已有授权器到OpenAPI端点

你遇到的核心问题是:无法直接在OpenAPI DefinitionBody的security字段中引用CloudFormation单独定义的AWS::ApiGateway::Authorizer资源。这是因为OpenAPI配置和CloudFormation资源属于两个不同的配置层面——OpenAPI的security字段要求引用的是自身securityDefinitions(OpenAPI 2.x)或components.securitySchemes(OpenAPI 3.x)中定义的授权方案,而CloudFormation的AWS::ApiGateway::Authorizer是栈内独立管理的资源,二者的引用机制不兼容。

不过有两种可行的解决方案,根据你的需求选择:

方案1:将授权器定义移到OpenAPI配置内

如果可以接受把授权器的配置整合到OpenAPI的DefinitionBody中,这是最直接的方式。SAM会自动根据OpenAPI中的授权方案创建对应的API Gateway Authorizer资源,你不需要单独定义AWS::ApiGateway::Authorizer。

示例配置(以OpenAPI 3.x为例):

"API": {
  "Type": "AWS::Serverless::Api",
  "Properties": {
    "DefinitionBody": {
      "openapi": "3.0.1",
      "info": { "title": "My API", "version": "1.0" },
      "components": {
        "securitySchemes": {
          "LambdaAuthorizer": {
            "type": "apiKey",
            "name": "Authorization",
            "in": "header",
            "x-amazon-apigateway-authtype": "custom",
            "x-amazon-apigateway-authorizer": {
              "type": "token",
              "authorizerUri": { "Fn::Sub": "arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${AuthLambda.Arn}/invocations" },
              "identityValidationExpression": "^[a-zA-Z0-9]{3,32}$",
              "authorizerResultTtlInSeconds": 300,
              "authorizerCredentials": { "Fn::GetAtt": ["LambdaAuthorizerRole", "Arn"] }
            }
          }
        }
      },
      "paths": {
        "/endpoint": {
          "post": {
            "responses": { "200": { "description": "200 response" } },
            "x-amazon-apigateway-integration": {
              "uri": { "Fn::Sub": "arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${AuthLambda.Arn}/invocations" },
              "responses": { "default": { "statusCode": "200", "contentHandling": "CONVERT_TO_TEXT" } },
              "passthroughBehavior": "when_no_match",
              "httpMethod": "POST",
              "contentHandling": "CONVERT_TO_TEXT",
              "type": "aws_proxy"
            },
            "security": [{ "LambdaAuthorizer": [] }]
          }
        }
      }
    }
  }
}

这样配置后,security字段就能直接引用OpenAPI内部定义的LambdaAuthorizer授权方案,SAM会自动处理后续的资源创建和关联。

方案2:保留独立的CloudFormation授权器,用SAM Events定义API端点

如果你必须保留单独的AWS::ApiGateway::Authorizer资源,可以放弃在DefinitionBody中定义端点,转而通过SAM函数的Events属性来创建API方法,这样就能直接引用CloudFormation中的授权器资源。

示例配置:

// 保留你的LambdaAuthorizer定义
"LambdaAuthorizer":{
  "Type": "AWS::ApiGateway::Authorizer",
  "Properties":{
    "IdentitySource":"method.request.header.Authorization",
    "Type":"TOKEN",
    "RestApiId":{ "Ref": "API" },
    "AuthorizerUri": {
      "Fn::Join" : ["", ["arn:aws:apigateway:", {"Ref": "AWS::Region"}, ":lambda:path/2015-03-31/functions/", {"Fn::GetAtt": ["AuthLambda", "Arn"]}, "/invocations"]]
    },
    "IdentityValidationExpression": "^[a-zA-Z0-9]{3,32}$",
    "AuthorizerResultTtlInSeconds": 300,
    "AuthorizerCredentials": { "Fn::GetAtt": ["LambdaAuthorizerRole", "Arn"] },
    "Name":"lambda-authorizer"
  }
},
// 简化API定义,不需要DefinitionBody中的paths
"API": {
  "Type": "AWS::Serverless::Api",
  "Properties": {
    // 基础配置,比如StageName等
    "StageName": "prod"
  }
},
// 用函数的Events定义端点并关联授权器
"MyEndpointFunction": {
  "Type": "AWS::Serverless::Function",
  "Properties": {
    "Handler": "index.handler",
    "Runtime": "nodejs18.x",
    "Events": {
      "PostEndpoint": {
        "Type": "Api",
        "Properties": {
          "RestApiId": { "Ref": "API" },
          "Path": "/endpoint",
          "Method": "POST",
          "Authorizer": { "Ref": "LambdaAuthorizer" }
        }
      }
    }
  }
}

这种方式下,API方法由SAM的Events属性创建,直接关联你已定义的LambdaAuthorizer资源,绕开了OpenAPI配置的限制。


内容的提问来源于stack exchange,提问作者JamesG

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:27:58