API Gateway cache encryption is disabled

Encrypt sensitive responses cached by API Gateway, and review cache keys and access permissions alongside encryption.

Description

API Gateway REST API caching stores responses for repeated requests. Sensitive cached responses should be encrypted at rest. CloudFormation's StageDescription.CacheDataEncrypted: true requests encryption for cached responses.

Caching is active only after a cache cluster is provisioned. Stage defaults can differ from method-level overrides, so check the methods actually in use.

Potential impact

  • Sensitive cached responses may lack required encryption-at-rest protection.
  • Encryption does not correct inappropriate cache keys or excessive API permissions. Configure caching so one user's response is not reused for another user.

Remediation

  • Enable encryption for methods that need caching and inspect the deployed stage and method-level settings.
  • Decide whether sensitive responses should be cached at all. Configure cache keys, expiration and API authorization for the data involved.
  • Verify responses and cache behavior after the change. If existing cache entries need flushing, account for the temporary increase in load on the origin service.

Examples

Provide the ID of a REST API with existing methods and integrations as MyApi. Both examples explicitly provision a cache cluster, which incurs cache charges. Manage method overrides and access permissions separately.

Cache encryption disabled

yaml
Parameters:
  MyApi:
    Type: String
Resources:
  Deployment:
    Type: AWS::ApiGateway::Deployment
    Properties:
      RestApiId: !Ref MyApi
      Description: My deployment
      StageName: DummyStage
      StageDescription:
        CacheClusterEnabled: true
        CacheClusterSize: "0.5"
        CachingEnabled: true
        CacheDataEncrypted: false

Caching is enabled while encryption of stored responses is disabled.

Cache encryption enabled

yaml
Parameters:
  MyApi:
    Type: String
Resources:
  Deployment:
    Type: AWS::ApiGateway::Deployment
    Properties:
      RestApiId: !Ref MyApi
      Description: My deployment
      StageName: DummyStage
      StageDescription:
        CacheClusterEnabled: true
        CacheClusterSize: "0.5"
        CachingEnabled: true
        CacheDataEncrypted: true

This enables response encryption for the same cache configuration. Per-user data separation and authorization remain necessary.

References