如何限制AWS API端点访问权限?防止Lambda函数调用链接公开可访问
Hey there! Great question—securing your Lambda-invoking API endpoint is super important to keep random public access out. Let’s walk through the most practical, effective methods you can use, based on your specific use case:
If your API is only meant to be accessed by AWS services, or authenticated IAM users/roles, this is the most straightforward built-in option.
- Attach an IAM policy to the entity (user, role, or service) that needs access, granting permission for the
execute-api:Invokeaction on your API’s specific ARN. - Example policy snippet:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "execute-api:Invoke", "Resource": "arn:aws:execute-api:REGION:ACCOUNT_ID:API_ID/STAGE/*" } ] } - Only requests signed with valid AWS credentials will be allowed through—no random public calls can bypass this.
Perfect if you need to grant access to third-party developers or specific client apps.
- Enable the "API key required" setting on your API methods. Clients will need to send a valid key in the
x-api-keyheader with every request. - Pair this with usage plans to set rate limits and request quotas—this prevents abuse even if a key accidentally leaks.
- Important: Always enforce HTTPS for your API to avoid interception of the API key in transit.
For full control over authentication logic (like validating custom tokens, JWTs from OAuth providers, or even IP checks), use a Lambda authorizer.
- This authorizer Lambda runs before your target Lambda function. It validates the request’s credentials (e.g., a token in the
Authorizationheader) and returns an IAM policy allowing or denying access. - Common use cases: Validating tokens from Auth0, checking if the request comes from a trusted IP range, or verifying custom internal auth tokens.
If you only want specific IPs or IP ranges to access your API, set up a resource policy on API Gateway.
- Example policy that allows only a single IP range:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": "*", "Action": "execute-api:Invoke", "Resource": "arn:aws:execute-api:REGION:ACCOUNT_ID:API_ID/STAGE/*", "Condition": { "IpAddress": { "aws:SourceIp": ["192.168.1.0/24"] } } } ] } - Any request from an IP outside the specified range will be blocked immediately.
Ideal if your API is accessed by end-users (like a mobile or web app).
- Users sign up or log in via Cognito, which issues JWT tokens. Clients send these tokens in the
Authorizationheader of API requests. - API Gateway automatically validates the tokens, so you don’t have to build custom auth logic from scratch. You can also configure fine-grained permissions based on user groups.
Pro Tip
Layer multiple security methods for extra protection—for example, combine API keys with IP restrictions, or use Cognito plus a Lambda authorizer for additional validation checks. Also, enable CloudWatch logging for your API Gateway to monitor access attempts and spot suspicious activity early.
内容的提问来源于stack exchange,提问作者zegulas

