Review API Gateway response compression

Choose response compression and its minimum size to suit the API payloads.

Description

API Gateway response compression affects bandwidth use and processing latency. Disabling it is a valid choice, and compression itself does not encrypt data or restrict access. Compressing small responses can increase their size or processing overhead.

Potential impact

  • Sending large responses without compression can increase transfer volume.
  • A threshold unsuited to the payloads can increase processing costs or latency.

Remediation

When compression is needed, set minimum_compression_size to a suitable threshold from 0 to 10485760 bytes; use -1 to disable it. Test actual response sizes and client Accept-Encoding support, then deploy the API. Configure HTTPS separately for transport protection.

Examples

These excerpts configure REST API compression. Configure actual methods and integrations separately. Omitting this value for a new API in Terraform leaves compression disabled.

Before

hcl
resource "aws_api_gateway_rest_api" "example" {
  name = "regional-example"

  endpoint_configuration {
    types = ["REGIONAL"]
  }

  minimum_compression_size = -1
}

After

hcl
resource "aws_api_gateway_rest_api" "example" {
  name = "regional-example"

  endpoint_configuration {
    types = ["REGIONAL"]
  }

  minimum_compression_size = 0
}

The first example uses the valid disabling value -1. The second uses 0, allowing eligible responses of any size to be compressed; conditions such as supported client encodings still apply. Zero is not the right threshold for every API.

References