Review SAM API compression settings

Choose a minimum size suitable for responses that benefit from compression.

Description

MinimumCompressionSize on AWS::Serverless::Api sets the response-compression threshold. Omitting it disables compression; valid values range from 0 through 10485760 bytes inclusive. Compression is neither encryption nor a mandatory security control.

Potential impact

Skipping useful compression can increase transfer volume and latency, while compressing small responses can add processing cost.

Remediation

Choose a valid threshold for the responses and compare sizes and latency after deployment. Check that clients send a supported Accept-Encoding value.

Examples

The threshold of 114 is illustrative. Supply the actual log-group ARN and a compression threshold appropriate for the service.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31
Resources:
  ApiGatewayApi:
    Type: AWS::Serverless::Api
    Properties:
      StageName: prod
      TracingEnabled: true
      CacheClusterEnabled: true
      AccessLogSetting:
        DestinationArn: arn:aws:logs:us-east-1:123456789012:log-group:my-log-group
        Format: '{"requestId":"$context.requestId"}'

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31
Resources:
  ApiGatewayApi:
    Type: AWS::Serverless::Api
    Properties:
      StageName: prod
      TracingEnabled: true
      CacheClusterEnabled: true
      AccessLogSetting:
        DestinationArn: arn:aws:logs:us-east-1:123456789012:log-group:my-log-group
        Format: '{"requestId":"$context.requestId"}'
      MinimumCompressionSize: 114

References