Public endpoint for an internal Serverless Framework API

Use a private endpoint and access policies for an internal REST API.

Description

A Serverless Framework REST API using a public endpoint can receive requests from the internet. For an internal-only API, configure provider.endpointType: PRIVATE and access it through a VPC endpoint.

Potential impact

An internal API may receive unnecessary external call attempts. Endpoint exposure and caller authentication and authorization require separate controls.

Remediation

Set provider.endpointType: PRIVATE for an internal-only API and restrict access through API resource and VPC endpoint policies. vpcEndpointIds associates invocation DNS aliases; it does not replace an allow-list.

Examples

Replace the endpoint IDs in the excerpts with actual IDs. Resource policies and function handler definitions are omitted. APIs intended for public use do not need to be changed indiscriminately to private endpoints.

Before

yaml
provider:
  name: aws
functions:
  hello:
    events:
      - http:
          path: user/create
          method: get

After

yaml
provider:
  name: aws
  endpointType: PRIVATE
  vpcEndpointIds:
    - vpce-123
    - vpce-456
functions:
  hello:
    events:
      - http:
          path: user/create
          method: get

References