Description
A public API Gateway REST API endpoint provides an invocation path over the internet. A public endpoint does not itself allow anonymous calls; authentication and resource policies also determine access.
Not every API needs to be private, but public endpoints unnecessarily expose internal-only APIs. Unintended exposure can attract discovery traffic and attempts to bypass authentication.
Potential impact
- An internal API may be discoverable over the internet.
- Scanning, authentication attempts and abusive requests can reach its public entry point.
- Access control may depend on public-endpoint policies rather than the intended VPC boundary.
Remediation
- For an internal-only API, set
endpoint_configuration.types = ["PRIVATE"]. - Separate public and internal APIs and apply the appropriate access policies.
- Prepare an interface VPC endpoint, security groups and DNS. Restrict invocation through resource and VPC endpoint policies, and test authentication and legitimate calls.
Examples
These excerpts compare endpoint types for the same REST API. The VPC endpoint, resource policy, methods and authentication required for a PRIVATE API are omitted.
Before
hcl
resource "aws_api_gateway_rest_api" "example" {
name = "regional-example"
endpoint_configuration {
types = ["REGIONAL"]
}
}
After
hcl
resource "aws_api_gateway_rest_api" "example" {
name = "regional-example"
endpoint_configuration {
types = ["PRIVATE"]
}
}
Explanation:
- Before:
REGIONALprovides a public network invocation path. - After:
PRIVATEuses a path through a VPC endpoint. Required connectivity and resource policies must be configured; this does not replace caller authentication.