Description
Without required AWS WAF protection on an API Gateway REST API stage, opportunities to filter known attack patterns or excessive requests through shared rules may be lost. Actual protection depends on the associated web ACL’s rules and actions.
WAF does not replace authentication, authorization or application input validation. Select managed, custom and rate-based rules according to the API’s exposure and the data it handles.
Potential impact
- Malicious requests may reach the application and exploit vulnerabilities.
- Excessive requests can increase processing costs or reduce service availability.
Remediation
Associate the protected REST API stage with a REGIONAL web ACL in the same Region. Configure required rules and test their effect on legitimate requests before applying blocking actions. Monitor WAF logs and metrics while maintaining API authentication, authorization and input validation.
Examples
The first task deploys an API; the second separately associates WAF protection. The second does not replace API deployment. Prepare the string03 web ACL and its rules, and replace the Region, API ID and stage with actual values.
Before
- name: Setup AWS API Gateway
community.aws.aws_api_gateway:
swagger_file: my_api.yml
stage: production
endpoint_type: EDGE
state: present
This deploys the production stage. The excerpt contains no WAF association task; also check protection configured elsewhere.
After
- name: Associate API Gateway stage with WAF
community.aws.wafv2_resources:
name: string03
scope: REGIONAL
state: present
arn: "arn:aws:apigateway:region::/restapis/api-id/stages/production"
This associates the specified REST API stage with a REGIONAL web ACL. Its rules and actions determine how requests are actually handled.