0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

API Gateway特定IP利用制限

0
Posted at

API Gateway REST API のリソースポリシーで「特定の IP アドレスのみ許可」する方法は以下のとおりです。


基本方針

  • aws:SourceIp 条件を使って
    👉 許可したい グローバル IP / CIDR のみ Allow
  • それ以外は 暗黙的に Deny(明示 Deny でも可)

例:特定 IP のみ許可するリソースポリシー

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "AllowSpecificIPs",
      "Effect": "Allow",
      "Principal": "*",
      "Action": "execute-api:Invoke",
      "Resource": "arn:aws:execute-api:ap-northeast-1:123456789012:abcd1234/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": [
            "203.0.113.10/32",
            "198.51.100.0/24"
          ]
        }
      }
    }
  ]
}

設定ポイント

項目 説明
aws:SourceIp クライアントの送信元IP
/32 単一IP指定
/24 IPレンジ指定
Resource API Gateway の ARN(/* で全ステージ・全メソッド)

明示的に Deny を書くパターン(推奨)

セキュリティを明確にしたい場合はこちら👇

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "DenyOtherIPs",
      "Effect": "Deny",
      "Principal": "*",
      "Action": "execute-api:Invoke",
      "Resource": "arn:aws:execute-api:ap-northeast-1:123456789012:abcd1234/*",
      "Condition": {
        "NotIpAddress": {
          "aws:SourceIp": [
            "203.0.113.10/32"
          ]
        }
      }
    },
    {
      "Sid": "AllowSpecificIPs",
      "Effect": "Allow",
      "Principal": "*",
      "Action": "execute-api:Invoke",
      "Resource": "arn:aws:execute-api:ap-northeast-1:123456789012:abcd1234/*"
    }
  ]
}

👉 Deny は Allow より優先されるため、安全に制御できます。


よくある注意点(重要)

① プライベート API では使い方が違う

  • Private API + VPC Endpoint の場合
    👉 aws:SourceVpce を使うのが一般的
    👉 SourceIp 制限は意味を持たないケースあり

② CloudFront 経由の場合

  • Source IP は CloudFront のIP になる

  • 対策:

    • CloudFront の マネージドプレフィックスリストを許可
    • または WAF でIP制限

③ ALB / NLB 経由では不可

  • API Gateway は直接 IP 制限可能
  • ALB の SG のような考え方は不可

IP制限 + α のベストプラクティス

レイヤ 推奨
API Gateway リソースポリシー(IP制限)
WAF IP / Geo / Rate Limit
認証 IAM / Cognito / Lambda Authorizer

まとめ(超要点)

  • ✅ REST API はリソースポリシーでIP制限可能
  • ✅ aws:SourceIp を使う
  • ✅ 明示 Deny + Allow が安全
  • ⚠ CloudFront / Private API では注意
0
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?