Specify which account/user can invoke the API using SAM and API GatewayHow to control access to AWS API Gateway EndpointHow to control access of resources in amazon api gateway through API KeysAWS::Serverless::Api Resource Policy with Cloudformation SAMPermission to invoke all Lambda functions from API GatewayAWS API Gateway privateTerraform - how to attach IAM role to invoke Lambda to API GatewayAWS SAM cloudformation: API Gateway can't invoke lambda (AWS::Serverless::Function )AWS API Gateway Custom Authorizer not invokedVersioning an API deployed with SAMAPI Gateway HTTP Proxy integration with aws-sam (NOT Lambda Proxy)

How to patch glass cuts in a bicycle tire?

What could a self-sustaining lunar colony slowly lose that would ultimately prove fatal?

Why were helmets and other body armour not commonplace in the 1800s?

What is a Centaur Thief's climbing speed?

Can the Levitate spell be used to cause damage by slamming a creature?

Why did David Cameron offer a referendum on the European Union?

What to do when you've set the wrong ISO for your film?

What are these arcade games in Ghostbusters 1984?

How did these characters "suit up" so quickly?

I unknowingly submitted plagarised work

Popcorn is the only acceptable snack to consume while watching a movie

When the Torah was almost lost and one (or several) Rabbis saved it?

What to keep in mind when telling an aunt how wrong her actions are, without creating further family conflict?

Can I tell a prospective employee that everyone in the team is leaving?

Make 24 using exactly three 3s

Why didn't Thanos use the Time Stone to stop the Avengers' plan?

Have 1.5% of all nuclear reactors ever built melted down?

Who will lead the country until there is a new Tory leader?

How should I introduce map drawing to my players?

Why aren't space telescopes put in GEO?

USPS Back Room - Trespassing?

Do photons bend spacetime or not?

Is the Indo-European language family made up?

Count Even Digits In Number



Specify which account/user can invoke the API using SAM and API Gateway


How to control access to AWS API Gateway EndpointHow to control access of resources in amazon api gateway through API KeysAWS::Serverless::Api Resource Policy with Cloudformation SAMPermission to invoke all Lambda functions from API GatewayAWS API Gateway privateTerraform - how to attach IAM role to invoke Lambda to API GatewayAWS SAM cloudformation: API Gateway can't invoke lambda (AWS::Serverless::Function )AWS API Gateway Custom Authorizer not invokedVersioning an API deployed with SAMAPI Gateway HTTP Proxy integration with aws-sam (NOT Lambda Proxy)






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








1















I'm trying to create an API Gateway which invokes a Lambda function using SAM. I want to restrict access to the API in such a way that only certain IAM accounts/users can access the API. How should I do that? I couldn't find a proper way to attach a resource access policy to an API endpoint in SAM.










share|improve this question






















  • I think what you want is in your AWS::Serverless::Function resource, you want to assign a Role, which will be an IAM user with the proper permissions. github.com/awslabs/serverless-application-model/blob/master/…

    – HolyMoly
    Mar 19 at 22:29


















1















I'm trying to create an API Gateway which invokes a Lambda function using SAM. I want to restrict access to the API in such a way that only certain IAM accounts/users can access the API. How should I do that? I couldn't find a proper way to attach a resource access policy to an API endpoint in SAM.










share|improve this question






















  • I think what you want is in your AWS::Serverless::Function resource, you want to assign a Role, which will be an IAM user with the proper permissions. github.com/awslabs/serverless-application-model/blob/master/…

    – HolyMoly
    Mar 19 at 22:29














1












1








1








I'm trying to create an API Gateway which invokes a Lambda function using SAM. I want to restrict access to the API in such a way that only certain IAM accounts/users can access the API. How should I do that? I couldn't find a proper way to attach a resource access policy to an API endpoint in SAM.










share|improve this question














I'm trying to create an API Gateway which invokes a Lambda function using SAM. I want to restrict access to the API in such a way that only certain IAM accounts/users can access the API. How should I do that? I couldn't find a proper way to attach a resource access policy to an API endpoint in SAM.







amazon-web-services aws-lambda aws-api-gateway aws-sam






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Mar 14 at 0:09









FarzadFarzad

183




183












  • I think what you want is in your AWS::Serverless::Function resource, you want to assign a Role, which will be an IAM user with the proper permissions. github.com/awslabs/serverless-application-model/blob/master/…

    – HolyMoly
    Mar 19 at 22:29


















  • I think what you want is in your AWS::Serverless::Function resource, you want to assign a Role, which will be an IAM user with the proper permissions. github.com/awslabs/serverless-application-model/blob/master/…

    – HolyMoly
    Mar 19 at 22:29

















I think what you want is in your AWS::Serverless::Function resource, you want to assign a Role, which will be an IAM user with the proper permissions. github.com/awslabs/serverless-application-model/blob/master/…

– HolyMoly
Mar 19 at 22:29






I think what you want is in your AWS::Serverless::Function resource, you want to assign a Role, which will be an IAM user with the proper permissions. github.com/awslabs/serverless-application-model/blob/master/…

– HolyMoly
Mar 19 at 22:29













1 Answer
1






active

oldest

votes


















0














Generally, you can limit the access to your APIs using IAM roles.



However, SAM supports only a limited number of resource types, so you have to use the IAM Policy type of CloudFormation instead.



Since SAM is only a higher-level abstraction of CloudFormation, it is no problem to use native CloudFormation resource types in your SAM template: https://docs.aws.amazon.com/serverless-application-model/latest/developerguide/appendix-appendix-sam-templates-and-cf-templates.html






share|improve this answer























    Your Answer






    StackExchange.ifUsing("editor", function ()
    StackExchange.using("externalEditor", function ()
    StackExchange.using("snippets", function ()
    StackExchange.snippets.init();
    );
    );
    , "code-snippets");

    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "1"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55152993%2fspecify-which-account-user-can-invoke-the-api-using-sam-and-api-gateway%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    0














    Generally, you can limit the access to your APIs using IAM roles.



    However, SAM supports only a limited number of resource types, so you have to use the IAM Policy type of CloudFormation instead.



    Since SAM is only a higher-level abstraction of CloudFormation, it is no problem to use native CloudFormation resource types in your SAM template: https://docs.aws.amazon.com/serverless-application-model/latest/developerguide/appendix-appendix-sam-templates-and-cf-templates.html






    share|improve this answer



























      0














      Generally, you can limit the access to your APIs using IAM roles.



      However, SAM supports only a limited number of resource types, so you have to use the IAM Policy type of CloudFormation instead.



      Since SAM is only a higher-level abstraction of CloudFormation, it is no problem to use native CloudFormation resource types in your SAM template: https://docs.aws.amazon.com/serverless-application-model/latest/developerguide/appendix-appendix-sam-templates-and-cf-templates.html






      share|improve this answer

























        0












        0








        0







        Generally, you can limit the access to your APIs using IAM roles.



        However, SAM supports only a limited number of resource types, so you have to use the IAM Policy type of CloudFormation instead.



        Since SAM is only a higher-level abstraction of CloudFormation, it is no problem to use native CloudFormation resource types in your SAM template: https://docs.aws.amazon.com/serverless-application-model/latest/developerguide/appendix-appendix-sam-templates-and-cf-templates.html






        share|improve this answer













        Generally, you can limit the access to your APIs using IAM roles.



        However, SAM supports only a limited number of resource types, so you have to use the IAM Policy type of CloudFormation instead.



        Since SAM is only a higher-level abstraction of CloudFormation, it is no problem to use native CloudFormation resource types in your SAM template: https://docs.aws.amazon.com/serverless-application-model/latest/developerguide/appendix-appendix-sam-templates-and-cf-templates.html







        share|improve this answer












        share|improve this answer



        share|improve this answer










        answered Mar 24 at 3:29









        margulmargul

        9219




        9219





























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Stack Overflow!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55152993%2fspecify-which-account-user-can-invoke-the-api-using-sam-and-api-gateway%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            SQL error code 1064 with creating Laravel foreign keysForeign key constraints: When to use ON UPDATE and ON DELETEDropping column with foreign key Laravel error: General error: 1025 Error on renameLaravel SQL Can't create tableLaravel Migration foreign key errorLaravel php artisan migrate:refresh giving a syntax errorSQLSTATE[42S01]: Base table or view already exists or Base table or view already exists: 1050 Tableerror in migrating laravel file to xampp serverSyntax error or access violation: 1064:syntax to use near 'unsigned not null, modelName varchar(191) not null, title varchar(191) not nLaravel cannot create new table field in mysqlLaravel 5.7:Last migration creates table but is not registered in the migration table

            용인 삼성생명 블루밍스 목차 통계 역대 감독 선수단 응원단 경기장 같이 보기 외부 링크 둘러보기 메뉴samsungblueminx.comeh선수 명단용인 삼성생명 블루밍스용인 삼성생명 블루밍스ehsamsungblueminx.comeheheheh

            155 수학 과학 기타 둘러보기 메뉴eh추가해eh문서를 완성해