Review WAF protection for an API Gateway REST API

Apply web request filtering that fits the API’s exposure and requirements.

Description

Without required AWS WAF protection on an API Gateway REST API stage, opportunities to filter known attack patterns or excessive requests through shared rules may be lost. Actual protection depends on the associated web ACL’s rules and actions.

WAF does not replace authentication, authorization or application input validation. Select managed, custom and rate-based rules according to the API’s exposure and the data it handles.

Potential impact

  • Malicious requests may reach the application and exploit vulnerabilities.
  • Excessive requests can increase processing costs or reduce service availability.

Remediation

Associate the protected REST API stage with a REGIONAL web ACL in the same Region. Configure required rules and test their effect on legitimate requests before applying blocking actions. Monitor WAF logs and metrics while maintaining API authentication, authorization and input validation.

Examples

The first task deploys an API; the second separately associates WAF protection. The second does not replace API deployment. Prepare the string03 web ACL and its rules, and replace the Region, API ID and stage with actual values.

Before

yaml
- name: Setup AWS API Gateway
  community.aws.aws_api_gateway:
    swagger_file: my_api.yml
    stage: production
    endpoint_type: EDGE
    state: present

This deploys the production stage. The excerpt contains no WAF association task; also check protection configured elsewhere.

After

yaml
- name: Associate API Gateway stage with WAF
  community.aws.wafv2_resources:
    name: string03
    scope: REGIONAL
    state: present
    arn: "arn:aws:apigateway:region::/restapis/api-id/stages/production"

This associates the specified REST API stage with a REGIONAL web ACL. Its rules and actions determine how requests are actually handled.

References