You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为私有子网内Lambda函数创建仅允许特定EC2调用的私有API网关?

Hey there, let's break down exactly how to build this locked-down setup—we'll ensure your private subnet Lambda is only reachable by that specific public subnet EC2, with zero access from anyone else.

Step 1: Confirm Your Lambda's VPC Configuration

First, double-check your Lambda’s existing setup in the private subnet:

  • Its security group must allow inbound HTTPS (port 443) traffic from the API Gateway’s VPC Link (we’ll create this later)—this is how the API will reach into the private subnet to invoke the Lambda.
  • Since it’s in a private subnet, make sure it has network access for its tasks: use a NAT Gateway if it needs internet access, or VPC endpoints for any AWS services it interacts with.
Step 2: Create a Private API Gateway

We’ll use a private API Gateway to restrict access exclusively to your VPC:

  • Head to the API Gateway console, create a new REST API (or HTTP API if you prefer) and select Private as the endpoint type.
  • Link your VPC to this API by creating an Interface VPC Endpoint for the execute-api service. When setting this up:
    • Select the public subnets where your target EC2 resides.
    • Attach a security group that allows inbound HTTPS (443) traffic from your EC2’s security group.
Step 3: Connect API Gateway to Your Private Lambda

Now we’ll bridge the API Gateway to your Lambda in the private subnet:

  • Add a new resource and method (e.g., POST/GET) to your private API.
  • For the integration type, choose Lambda Function and select your private subnet Lambda.
  • Since the Lambda is in a private subnet, create a VPC Link (under API Gateway > VPC Links) pointing to the Lambda’s VPC subnets and security group. Associate this link with your integration—it lets the API Gateway reach into the private subnet to invoke the Lambda.
  • Grant API Gateway permission to call your Lambda: You can do this via the console (it will prompt you to create the permission) or run this CLI command:
    aws lambda add-permission \
      --function-name YOUR_LAMBDA_NAME \
      --statement-id api-gateway-invoke \
      --action "lambda:InvokeFunction" \
      --principal apigateway.amazonaws.com \
      --source-arn "arn:aws:execute-api:REGION:ACCOUNT_ID:API_ID/*/METHOD/RESOURCE_PATH"
    
Step 4: Lock Access to Only Your Target EC2

We’ll use two layers of security to ensure no other entity can access the API:

Layer 1: API Gateway Resource Policy

Attach this policy to your private API to explicitly allow only your EC2. Use either the IP-based policy (if your EC2 has a static public IP) or security group-based policy (better for dynamic IPs):

IP-Based Policy Example

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "execute-api:Invoke",
      "Resource": "arn:aws:execute-api:REGION:ACCOUNT_ID:API_ID/*/*/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "YOUR_EC2_PUBLIC_IP/32"
        }
      }
    },
    {
      "Effect": "Deny",
      "Principal": "*",
      "Action": "execute-api:Invoke",
      "Resource": "arn:aws:execute-api:REGION:ACCOUNT_ID:API_ID/*/*/*",
      "Condition": {
        "NotIpAddress": {
          "aws:SourceIp": "YOUR_EC2_PUBLIC_IP/32"
        }
      }
    }
  ]
}

Security Group-Based Policy Example

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "execute-api:Invoke",
      "Resource": "arn:aws:execute-api:REGION:ACCOUNT_ID:API_ID/*/*/*",
      "Condition": {
        "StringEquals": {
          "aws:SourceVpc": "YOUR_VPC_ID",
          "aws:SourceSecurityGroup": "YOUR_EC2_SECURITY_GROUP_ID"
        }
      }
    }
  ]
}

Layer 2: Security Group Restrictions

  • Update your EC2’s security group to only allow outbound HTTPS (443) traffic to the API Gateway’s VPC endpoint security group.
  • Update the API Gateway VPC endpoint’s security group to only allow inbound HTTPS traffic from your EC2’s security group.
Step 5: Test the Setup
  • SSH into your target EC2 and send a test request to the private API’s endpoint (use the private DNS name of the execute-api VPC endpoint plus your API’s resource path).
  • Try accessing the API from outside the VPC (e.g., your local machine) or another EC2—you should get an access denied error.
  • Check CloudWatch logs for API Gateway and Lambda to confirm invocations work only from the allowed EC2.
Additional Tips
  • If using an HTTP API instead of REST, the core logic is the same, but the resource policy syntax may vary slightly.
  • Ensure your Lambda’s execution role includes the AWSLambdaVPCAccessExecutionRole managed policy for basic VPC access.
  • Enable API Gateway logging to monitor access attempts and troubleshoot issues quickly.

内容的提问来源于stack exchange,提问作者Venkata S S K M Chaitanya

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 07:21:30