API Gateway REST API must have an endpoint configuration
Medium
AWS
General
aws-apigateway-restapi-api-gateway-rest-api
Applies to
AWS::ApiGateway::RestApi
What CGPulse checks
A resource passes this rule when endpointConfiguration must be set true. Anything else is reported as a finding with the evaluated property value attached as evidence.
How to fix it
Configure the API Gateway REST API endpoint type (EDGE, REGIONAL, or PRIVATE) to match your security requirements. In AWS Console: API Gateway > APIs > select API > Settings > Endpoint Type. See: https://docs.aws.amazon.com/apigateway/latest/developerguide/api-gateway-api-endpoint-types.html
Terraform
resource "aws_api_gateway_rest_api" "{name}" {
endpoint_configuration {
types = ["REGIONAL"]
}
}
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related AWS rules
- ACM certificate must be eligible for renewal
- ACM certificate must be in issued status
- Amplify app should have basic auth disabled for production
- API Gateway V2 API must be properly configured
- App Runner service must have encryption enabled
- AppSync API must have logging configured
- AppSync API must have X-Ray tracing enabled
- Athena workgroup must enforce workgroup configuration