Description
A public endpoint for an internal API exposes an invocation path beyond the intended network. A public endpoint does not itself permit anonymous calls, and EDGE or REGIONAL endpoints are legitimate for public services.
A PRIVATE REST API requires preparation such as an interface VPC endpoint and a resource policy. Reducing network exposure does not replace method authentication or application permission checks.
Potential impact
- Insufficient authentication or access policies can expose internal functions to unintended callers.
- Changing the endpoint before preparing private connectivity can interrupt legitimate calls.
Remediation
Confirm whether the API needs public exposure. For an internal REST API, prepare an interface VPC endpoint, security groups, DNS and a resource policy restricting allowed VPCs or endpoints before applying PRIVATE configuration. Test connectivity and authentication for required callers, and retain appropriate authentication and access restrictions for public APIs.
Examples
These excerpts compare the endpoint type of the same REST API. The VPC endpoint, resource policy, methods and authentication settings needed for a PRIVATE API are omitted.
Before
Resources:
InternalApi:
Type: AWS::ApiGateway::RestApi
Properties:
Name: internal-api
EndpointConfiguration:
Types:
- EDGE
EDGE configures a public API endpoint. This setting alone does not establish method authentication or actual data permissions.
After
Resources:
InternalApi:
Type: AWS::ApiGateway::RestApi
Properties:
Name: internal-api
EndpointConfiguration:
Types:
- PRIVATE
This sets the endpoint type to PRIVATE. Configure the required private path and resource policy as well to make the API usable.