Review access logging on an API Gateway deployment stage

Configure access logging on the stage that serves an API Gateway deployment.

Description

aws_api_gateway_deployment is a snapshot of a REST API configuration. Access logging for actual requests is configured on the aws_api_gateway_stage that references the deployment. A deployment description does not enable access logs.

A deployed API without the required access logging may lack request records, making it harder to connect operational problems to deployments.

Potential impact

  • Records of calls to the deployed API may be unavailable.
  • Relating deployment changes to stage behavior can take longer.
  • Failures or abuse can be harder to investigate.

Remediation

  • Configure access_log_settings on the serving aws_api_gateway_stage.
  • Check the stage’s deployment reference, log destination and format, and configure delivery permissions and retention.
  • Include logging configuration in deployment templates and verify delivery after deployment.

Examples

These excerpts use a separate stage with the current provider. The REST API, methods, integrations, deployment dependencies, log group and delivery permissions are omitted.

Before

hcl
resource "aws_api_gateway_deployment" "example" {
  rest_api_id = aws_api_gateway_rest_api.example.id
}

resource "aws_api_gateway_stage" "example" {
  deployment_id = aws_api_gateway_deployment.example.id
  rest_api_id   = aws_api_gateway_rest_api.example.id
  stage_name    = "example"
}

After

hcl
resource "aws_api_gateway_deployment" "example" {
  rest_api_id = aws_api_gateway_rest_api.example.id
}

resource "aws_api_gateway_stage" "example" {
  deployment_id = aws_api_gateway_deployment.example.id
  rest_api_id   = aws_api_gateway_rest_api.example.id
  stage_name    = "example"

  access_log_settings {
    destination_arn = aws_cloudwatch_log_group.example.arn
    format = jsonencode({ requestId = "$context.requestId", status = "$context.status" })
  }
}

Explanation:

  • Before: The deployment and stage are connected, but this stage has no access log delivery configuration. Check other logging separately.
  • After: The stage has access logging configured. Verify that actual request records arrive in the log group after deployment.

References