Review API Gateway endpoint exposure

Use a PRIVATE endpoint when a REST API is intended only for internal access.

Description

A public API Gateway REST API endpoint provides an invocation path over the internet. A public endpoint does not itself allow anonymous calls; authentication and resource policies also determine access.

Not every API needs to be private, but public endpoints unnecessarily expose internal-only APIs. Unintended exposure can attract discovery traffic and attempts to bypass authentication.

Potential impact

  • An internal API may be discoverable over the internet.
  • Scanning, authentication attempts and abusive requests can reach its public entry point.
  • Access control may depend on public-endpoint policies rather than the intended VPC boundary.

Remediation

  • For an internal-only API, set endpoint_configuration.types = ["PRIVATE"].
  • Separate public and internal APIs and apply the appropriate access policies.
  • Prepare an interface VPC endpoint, security groups and DNS. Restrict invocation through resource and VPC endpoint policies, and test authentication and legitimate calls.

Examples

These excerpts compare endpoint types for the same REST API. The VPC endpoint, resource policy, methods and authentication required for a PRIVATE API are omitted.

Before

hcl
resource "aws_api_gateway_rest_api" "example" {
  name = "regional-example"

  endpoint_configuration {
    types = ["REGIONAL"]
  }
}

After

hcl
resource "aws_api_gateway_rest_api" "example" {
  name = "regional-example"

  endpoint_configuration {
    types = ["PRIVATE"]
  }
}

Explanation:

  • Before: REGIONAL provides a public network invocation path.
  • After: PRIVATE uses a path through a VPC endpoint. Required connectivity and resource policies must be configured; this does not replace caller authentication.

References