Description
A public SAM REST API endpoint can receive requests from the internet. For an internal-only API, set Type under EndpointConfiguration to PRIVATE and use access through a VPC endpoint.
Potential impact
An internal API can be exposed to unintended external call attempts. A public endpoint does not itself imply unauthenticated access.
Remediation
Set EndpointConfiguration.Type: PRIVATE and restrict access with a VPC endpoint and API resource policy. Associating VPCEndpointIds creates invocation DNS aliases; it does not replace an allow-list.
Examples
The examples use SAM’s singular Type property. The API resource policy and VPC endpoint are omitted and must be configured for deployment. APIs intended for public services can use a suitable public endpoint.
Before
Resources:
ApiGatewayApi:
Type: AWS::Serverless::Api
Properties:
StageName: prod
EndpointConfiguration:
Type: EDGE
After
Resources:
ApiGatewayApi:
Type: AWS::Serverless::Api
Properties:
StageName: prod
EndpointConfiguration:
Type: PRIVATE