You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否将AppSync API端点限制为仅内网访问?含Cognito及自定义域名疑问

AppSync Private Access & Custom Domain Setup

Let's tackle your two key questions one by one, since they're both focused on restricting AppSync API access to non-public networks:

1. Can AppSync restrict public access like API Gateway's VPC endpoints?

Absolutely! AppSync supports VPC Private Endpoints—this is the equivalent of API Gateway's private VPC integration you referenced. Here's how it works:

  • Create a VPC Endpoint of type com.amazonaws.<your-region>.appsync-api in your VPC. Make sure to associate it with the appropriate subnets and security groups that only allow traffic from your internal resources.
  • In your AppSync API settings, navigate to the Security section and set the API access to Private. You'll then link it to the VPC endpoint you created.
  • Once configured, all public requests to your AppSync endpoint will be rejected. Only resources within your VPC (or connected via VPN/Direct Connect) can reach the API through the private endpoint.
  • Don't forget to update your VPC route tables to route AppSync traffic to the endpoint, and configure security group rules to permit inbound traffic from your allowed resources.

2. Is it possible to bind a non-public custom domain to AppSync?

Yes, but it requires combining a few AWS services to ensure the domain is only accessible internally:

  • First, set up a Route 53 Private Hosted Zone for your non-public domain (e.g., api.internal.yourcompany.com). This hosted zone will only resolve DNS queries from within your VPC.
  • Create a CNAME record in this private hosted zone pointing to your AppSync endpoint (or the VPC endpoint's DNS name if you're using private access).
  • To use the custom domain with AppSync, you'll need to configure AppSync's custom domain feature:
    • Use an AWS Certificate Manager (ACM) certificate for your custom domain. If it's a private internal domain, you can use ACM's private certificate authority (CA) to issue a trusted certificate for internal clients.
    • In the AppSync console, go to Custom Domains and add your domain, associating it with the ACM certificate.
  • With this setup, only resources inside your VPC will be able to resolve and access AppSync via your non-public custom domain—public users won't have DNS resolution for the domain, making it effectively inaccessible from the internet.

It's worth noting that combining both the private VPC endpoint and private custom domain gives you the strongest control over access to your AppSync API, ensuring it's completely isolated from public networks.

内容的提问来源于stack exchange,提问作者Slae

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 10:03:07