AWS API Gateway

· 1 min read · AWS

Amazon API Gateway is a fully managed service that makes it easy to publish APIs at any scale. It is the "front door" that receives the HTTP requests of clients and sends them to a backend: Lambda functions, HTTP services behind a load balancer, or other AWS services.

API types #

  • HTTP APIs: the simpler and cheaper option, with low latency, JWT authorizers and Lambda or HTTP integrations.
  • REST APIs: more features: API keys and usage plans, request validation and transformation, caching, WAF integration and private endpoints.
  • WebSocket APIs: two-way communication for chat, dashboards and games.

Key concepts #

  • Routes/resources and methods, integrations to the backend and stages (dev, prod) with their own settings and variables.
  • Authorization: IAM, Amazon Cognito, JWT and custom Lambda authorizers.
  • Throttling and quotas protect the backends; a custom domain name with a certificate from ACM and a record in Route 53 gives the API its own URL.
  • Protection: attach AWS WAF to a REST API; the endpoint can be Regional, edge-optimized (through CloudFront) or private inside a VPC.
  • Monitoring: access logs and metrics in CloudWatch.

Pricing #

Per million API calls (and per message and connection minute for WebSocket), plus optional cache and data transfer. HTTP APIs cost less than REST APIs. See the API Gateway pricing.

With Terraform #

The resources are aws_apigatewayv2_api (HTTP and WebSocket APIs) and aws_api_gateway_rest_api with its resources, methods, integrations, deployments and stages.

#AWS #Serverless