Description
EDGE and REGIONAL endpoints suit API Gateway REST APIs that need internet reachability. Providing an unnecessary public path to an internal API can expose it to external discovery and invocation attempts.
A public endpoint does not itself permit anonymous calls. PRIVATE limits network reachability; API authentication and authorization are still separate requirements.
Potential impact
- Internal paths or features may become targets for external invocation attempts.
- Missing authentication or permission checks can lead to data disclosure or feature abuse.
Remediation
For an internal REST API, use endpoint_type: PRIVATE and configure an interface VPC endpoint, DNS and connection paths, and the endpoint security group. Restrict the API resource policy to required VPCs or endpoints. Test approved client connectivity before migration, and retain appropriate authentication and authorization for APIs that need public access.
Examples
These deployment excerpts compare endpoint types. my_api.yml, VPC endpoint configuration and resource policies are omitted. For an existing API, check supported conversion paths and effects on client connectivity.
Before
- name: Setup AWS API Gateway
community.aws.aws_api_gateway:
swagger_file: my_api.yml
stage: production
endpoint_type: EDGE
state: present
This deploys an EDGE endpoint. It can suit an intentionally internet-facing API; reassess its scope for an internal API.
After
- name: Setup AWS API Gateway
community.aws.aws_api_gateway:
swagger_file: my_api.yml
stage: production
endpoint_type: PRIVATE
state: present
This deploys a PRIVATE endpoint. Clients still need the required VPC connection path and resource policy to invoke it.