如何通过CloudFormation使用Access和Secret Keys保护AWS API Gateway?
Great question! Since you're using the AWS Serverless Application Model (SAM) template (with the AWS::Serverless-2016-10-31 Transform), there are two straightforward ways to enable SigV4 authentication (which leverages AWS Access and Secret Keys) for your API Gateway. Let's break them down:
1. Quick Method: Enable IAM Authentication Directly in the Function's API Event
The simplest approach is to add an Auth property to your existing API event configuration for the Lambda function. SigV4 is essentially AWS IAM authentication under the hood, so specifying Type: AWS_IAM will enforce that callers sign requests with valid AWS credentials.
Here's your modified CloudFormation/SAM template with this change:
{ "AWSTemplateFormatVersion": "2010-09-09", "Transform": "AWS::Serverless-2016-10-31", "Description": "An AWS Serverless Application.", "Resources": { "Get": { "Type": "AWS::Serverless::Function", "Properties": { "Handler": "AWSServerless::AWSServerless.Functions::Get", "Runtime": "dotnet6", // Updated from outdated dotnetcore2.0 for better support "CodeUri": "", "MemorySize": 256, "Timeout": 30, "Role": null, "Policies": [ "AWSLambdaBasicExecutionRole" ], "Events": { "GetResource": { // Renamed to match the GET method for clarity "Type": "Api", "Properties": { "Path": "/", "Method": "GET", "Auth": { "Type": "AWS_IAM" // This enables SigV4 authentication } } } } } } }, "Outputs": { "ApiURL": { "Description": "API endpoint URL for Prod environment", "Value": { "Fn::Sub": "https://${ServerlessRestApi}.execute-api.${AWS::Region}.amazonaws.com/Prod/" } } } }
2. Flexible Method: Define OpenAPI Security Rules (For Fine-Grained Control)
If you need more control—like applying security rules to specific paths, or defining multiple security schemes—you can explicitly create an AWS::Serverless::Api resource and embed OpenAPI configuration that includes the security: [{sigv4: []}] you referenced.
Here's how to adjust your template for this approach:
{ "AWSTemplateFormatVersion": "2010-09-09", "Transform": "AWS::Serverless-2016-10-31", "Description": "An AWS Serverless Application.", "Resources": { "MyProtectedApi": { "Type": "AWS::Serverless::Api", "Properties": { "StageName": "Prod", "DefinitionBody": { "openapi": "3.0.1", "info": { "title": "MyProtectedApi", "version": "1.0" }, "components": { "securitySchemes": { "sigv4": { "type": "apiKey", "name": "Authorization", "in": "header", "x-amazon-apigateway-authtype": "awsSigv4" } } }, "security": [ { "sigv4": [] // Enforces SigV4 authentication for all paths } ], "paths": { "/": { "get": { "x-amazon-apigateway-integration": { "uri": { "Fn::Sub": "arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${Get.Arn}/invocations" }, "httpMethod": "POST", "type": "aws_proxy" } } } } } } }, "Get": { "Type": "AWS::Serverless::Function", "Properties": { "Handler": "AWSServerless::AWSServerless.Functions::Get", "Runtime": "dotnet6", "CodeUri": "", "MemorySize": 256, "Timeout": 30, "Role": null, "Policies": [ "AWSLambdaBasicExecutionRole" ], "Events": { "GetResource": { "Type": "Api", "Properties": { "RestApiId": { "Ref": "MyProtectedApi" }, // Reference the custom API resource "Path": "/", "Method": "GET" } } } } } }, "Outputs": { "ApiURL": { "Description": "API endpoint URL for Prod environment", "Value": { "Fn::Sub": "https://${MyProtectedApi}.execute-api.${AWS::Region}.amazonaws.com/Prod/" } } } }
Key Post-Setup Notes:
- Calling the API: Clients must now sign requests using SigV4. AWS SDKs (like the .NET AWS SDK) handle this automatically, but you can also manually generate the SigV4 signature and include the
Authorizationheader in your requests. - IAM Permissions: Ensure the IAM user/role making the request has the
execute-api:Invokepermission for your API Gateway resource.
内容的提问来源于stack exchange,提问作者RredCat

