Public endpoint for an internal SAM API

Configure a private endpoint and access policy for an internal REST API.

Description

A public SAM REST API endpoint can receive requests from the internet. For an internal-only API, set Type under EndpointConfiguration to PRIVATE and use access through a VPC endpoint.

Potential impact

An internal API can be exposed to unintended external call attempts. A public endpoint does not itself imply unauthenticated access.

Remediation

Set EndpointConfiguration.Type: PRIVATE and restrict access with a VPC endpoint and API resource policy. Associating VPCEndpointIds creates invocation DNS aliases; it does not replace an allow-list.

Examples

The examples use SAM’s singular Type property. The API resource policy and VPC endpoint are omitted and must be configured for deployment. APIs intended for public services can use a suitable public endpoint.

Before

yaml
Resources:
  ApiGatewayApi:
    Type: AWS::Serverless::Api
    Properties:
      StageName: prod
      EndpointConfiguration:
        Type: EDGE

After

yaml
Resources:
  ApiGatewayApi:
    Type: AWS::Serverless::Api
    Properties:
      StageName: prod
      EndpointConfiguration:
        Type: PRIVATE

References