API Gateway cache cluster not configured

Configure response caching for REST APIs that can use it safely.

Description

An API Gateway REST API cache cluster can reuse responses to repeated requests and reduce backend load. Absence of caching is not itself a vulnerability; first consider freshness and separation of user-specific data.

Potential impact

Repeatedly processing cacheable requests can increase backend load and response latency.

Remediation

When caching is appropriate, set CacheClusterEnabled: true and CachingEnabled: true for the intended methods. Choose cache keys and expiry to suit the responses.

Examples

The examples enable caching for GET responses. API and deployment resources and any required cache-key settings are omitted.

Before

yaml
Resources:
  ProdStage:
    Type: AWS::ApiGateway::Stage
    Properties:
      StageName: Prod
      RestApiId: !Ref MyRestApi
      DeploymentId: !Ref MyDeployment
      TracingEnabled: true

After

yaml
Resources:
  ProdStage:
    Type: AWS::ApiGateway::Stage
    Properties:
      StageName: Prod
      RestApiId: !Ref MyRestApi
      DeploymentId: !Ref MyDeployment
      TracingEnabled: true
      CacheClusterEnabled: true
      MethodSettings:
        - ResourcePath: /*
          HttpMethod: GET
          CachingEnabled: true

References