Description
aws_api_gateway_deployment is a snapshot of a REST API configuration. Access logging for actual requests is configured on the aws_api_gateway_stage that references the deployment. A deployment description does not enable access logs.
A deployed API without the required access logging may lack request records, making it harder to connect operational problems to deployments.
Potential impact
- Records of calls to the deployed API may be unavailable.
- Relating deployment changes to stage behavior can take longer.
- Failures or abuse can be harder to investigate.
Remediation
- Configure
access_log_settingson the servingaws_api_gateway_stage. - Check the stage’s deployment reference, log destination and format, and configure delivery permissions and retention.
- Include logging configuration in deployment templates and verify delivery after deployment.
Examples
These excerpts use a separate stage with the current provider. The REST API, methods, integrations, deployment dependencies, log group and delivery permissions are omitted.
Before
hcl
resource "aws_api_gateway_deployment" "example" {
rest_api_id = aws_api_gateway_rest_api.example.id
}
resource "aws_api_gateway_stage" "example" {
deployment_id = aws_api_gateway_deployment.example.id
rest_api_id = aws_api_gateway_rest_api.example.id
stage_name = "example"
}
After
hcl
resource "aws_api_gateway_deployment" "example" {
rest_api_id = aws_api_gateway_rest_api.example.id
}
resource "aws_api_gateway_stage" "example" {
deployment_id = aws_api_gateway_deployment.example.id
rest_api_id = aws_api_gateway_rest_api.example.id
stage_name = "example"
access_log_settings {
destination_arn = aws_cloudwatch_log_group.example.arn
format = jsonencode({ requestId = "$context.requestId", status = "$context.status" })
}
}
Explanation:
- Before: The deployment and stage are connected, but this stage has no access log delivery configuration. Check other logging separately.
- After: The stage has access logging configured. Verify that actual request records arrive in the log group after deployment.