Review the API Gateway compression threshold

Use a valid byte threshold when compression is needed.

Description

A REST API’s MinimumCompressionSize sets the minimum payload size for compression, from 0 through 10485760 bytes inclusive. Omitting it can disable compression. Compression controls transfer efficiency and does not replace encryption.

Potential impact

Out-of-range values can cause API configuration to fail, while an unsuitable threshold can increase transfer or processing costs.

Remediation

Choose a valid value for the responses and verify it after deployment with a supported Accept-Encoding request. Omit the setting when compression is not needed.

Examples

The examples replace invalid -1 with 0. Zero permits compression at any payload size, but actual compression also depends on content-encoding conditions.

Before

yaml
Resources:
  RestApi:
    Type: AWS::ApiGateway::RestApi
    Properties:
      Name: myApi
      MinimumCompressionSize: -1

After

yaml
Resources:
  RestApi:
    Type: AWS::ApiGateway::RestApi
    Properties:
      Name: myApi
      MinimumCompressionSize: 0

References