Review the exposure of an API Gateway REST API

Make internal APIs callable only from the networks that need them.

Description

EDGE and REGIONAL endpoints suit API Gateway REST APIs that need internet reachability. Providing an unnecessary public path to an internal API can expose it to external discovery and invocation attempts.

A public endpoint does not itself permit anonymous calls. PRIVATE limits network reachability; API authentication and authorization are still separate requirements.

Potential impact

  • Internal paths or features may become targets for external invocation attempts.
  • Missing authentication or permission checks can lead to data disclosure or feature abuse.

Remediation

For an internal REST API, use endpoint_type: PRIVATE and configure an interface VPC endpoint, DNS and connection paths, and the endpoint security group. Restrict the API resource policy to required VPCs or endpoints. Test approved client connectivity before migration, and retain appropriate authentication and authorization for APIs that need public access.

Examples

These deployment excerpts compare endpoint types. my_api.yml, VPC endpoint configuration and resource policies are omitted. For an existing API, check supported conversion paths and effects on client connectivity.

Before

yaml
- name: Setup AWS API Gateway
  community.aws.aws_api_gateway:
    swagger_file: my_api.yml
    stage: production
    endpoint_type: EDGE
    state: present

This deploys an EDGE endpoint. It can suit an intentionally internet-facing API; reassess its scope for an internal API.

After

yaml
- name: Setup AWS API Gateway
  community.aws.aws_api_gateway:
    swagger_file: my_api.yml
    stage: production
    endpoint_type: PRIVATE
    state: present

This deploys a PRIVATE endpoint. Clients still need the required VPC connection path and resource policy to invoke it.

References