Description
API Gateway REST API caching stores responses for repeated requests. Sensitive cached responses should be encrypted at rest. CloudFormation's StageDescription.CacheDataEncrypted: true requests encryption for cached responses.
Caching is active only after a cache cluster is provisioned. Stage defaults can differ from method-level overrides, so check the methods actually in use.
Potential impact
- Sensitive cached responses may lack required encryption-at-rest protection.
- Encryption does not correct inappropriate cache keys or excessive API permissions. Configure caching so one user's response is not reused for another user.
Remediation
- Enable encryption for methods that need caching and inspect the deployed stage and method-level settings.
- Decide whether sensitive responses should be cached at all. Configure cache keys, expiration and API authorization for the data involved.
- Verify responses and cache behavior after the change. If existing cache entries need flushing, account for the temporary increase in load on the origin service.
Examples
Provide the ID of a REST API with existing methods and integrations as MyApi. Both examples explicitly provision a cache cluster, which incurs cache charges. Manage method overrides and access permissions separately.
Cache encryption disabled
Parameters:
MyApi:
Type: String
Resources:
Deployment:
Type: AWS::ApiGateway::Deployment
Properties:
RestApiId: !Ref MyApi
Description: My deployment
StageName: DummyStage
StageDescription:
CacheClusterEnabled: true
CacheClusterSize: "0.5"
CachingEnabled: true
CacheDataEncrypted: false
Caching is enabled while encryption of stored responses is disabled.
Cache encryption enabled
Parameters:
MyApi:
Type: String
Resources:
Deployment:
Type: AWS::ApiGateway::Deployment
Properties:
RestApiId: !Ref MyApi
Description: My deployment
StageName: DummyStage
StageDescription:
CacheClusterEnabled: true
CacheClusterSize: "0.5"
CachingEnabled: true
CacheDataEncrypted: true
This enables response encryption for the same cache configuration. Per-user data separation and authorization remain necessary.