API Gateway cache without encryption

Enable cache-data encryption when using API Gateway caching.

Description

API response caches can store query results and related data. Without cache encryption, stored responses lack encryption-at-rest protection. This is especially relevant for APIs that handle user information or internal responses.

Configure data protection as well as performance when using a cache. Encryption does not prevent an incorrect cache key or access policy from returning another user’s response.

Potential impact

  • Unauthorized access to cache storage can increase the risk of exposing sensitive response data.
  • Organizational API-cache encryption requirements may not be met.

Remediation

  • Explicitly set cache_data_encrypted = true for methods that use caching.
  • Cache only the methods that need it, and review sensitive data, cache keys and permissions.
  • After applying the change, verify the stage cache and method encryption settings, and test normal response handling.

Examples

These excerpts reference a separately defined REST API and stage. The stage’s cache cluster must also be enabled for caching to operate.

Before

hcl
resource "aws_api_gateway_method_settings" "cached_method" {
  rest_api_id = aws_api_gateway_rest_api.example.id
  stage_name  = aws_api_gateway_stage.example.stage_name
  method_path = "path1/GET"

  settings {
    metrics_enabled       = true
    logging_level         = "INFO"
    caching_enabled       = true
    cache_data_encrypted  = false
  }
}

Method caching is enabled, but cache-data encryption is disabled.

After

hcl
resource "aws_api_gateway_method_settings" "cached_method" {
  rest_api_id = aws_api_gateway_rest_api.example.id
  stage_name  = aws_api_gateway_stage.example.stage_name
  method_path = "path1/GET"

  settings {
    metrics_enabled       = true
    logging_level         = "INFO"
    caching_enabled       = true
    cache_data_encrypted  = true
  }
}

This keeps caching enabled and adds encryption. Review which responses may be shared and the applicable permissions separately.

References