API Gateway X-Ray tracing disabled

Disabled X-Ray tracing on a REST API can make request-path and latency analysis harder.

Description

When X-Ray tracing is disabled on an API Gateway REST API stage, locating request latency or errors can be harder. Distributed traces connect calls across services, but sampling means they do not replace an audit log of every request.

Potential impact

  • Identifying the source of latency and errors across services can take longer.
  • Incident response and performance analysis may lack useful request-path information.

Remediation

Set xray_tracing_enabled = true on REST API stages that need tracing. Check the required X-Ray permissions and sampling settings, use traces alongside logs and metrics, and verify actual trace collection after deployment.

Examples

These are REST API stage excerpts. Configure the referenced API and deployment separately.

Before

hcl
resource "aws_api_gateway_stage" "example" {
  stage_name           = "prod"
  rest_api_id          = aws_api_gateway_rest_api.test.id
  deployment_id        = aws_api_gateway_deployment.test.id
  xray_tracing_enabled = false
}

After

hcl
resource "aws_api_gateway_stage" "example" {
  stage_name           = "prod"
  rest_api_id          = aws_api_gateway_rest_api.test.id
  deployment_id        = aws_api_gateway_deployment.test.id
  xray_tracing_enabled = true
}

The revision enables X-Ray tracing for the stage. Check tracing in integrated services as well to observe the backend flow.

References