설명
Serverless Framework에서 provider.logs.restApi.accessLogging을 끄면 API Gateway REST API의 액세스 로그가 생성되지 않습니다. 애플리케이션 로그만으로는 API Gateway에서 처리한 요청을 모두 파악하기 어려울 수 있습니다.
잠재적 영향
장애나 의심스러운 호출을 조사할 때 요청별 기록이 부족할 수 있습니다.
해결 방법
provider.logs.restApi.accessLogging: true로 설정하고 요청 ID를 포함한 로그 포맷, 전달 권한과 보존 기간을 구성하세요. 로그에는 비밀값이나 불필요한 요청 본문을 남기지 마세요.
예시
예시는 Framework가 생성한 REST API에 적용됩니다. 외부 API를 provider.apiGateway.restApiId로 가져왔다면 해당 API의 로그를 별도로 설정해야 합니다.
변경 전
yaml
provider:
name: aws
logs:
restApi:
accessLogging: false
format: 'requestId: $context.requestId'
변경 후
yaml
provider:
name: aws
logs:
restApi:
accessLogging: true
format: 'requestId: $context.requestId'