Skip to content

MI-331: Add optional IP allowlist to SecureRestApi - #1767

Open
toddhainsworth wants to merge 1 commit into
mainfrom
feature/MI-331_secure_rest_api_ip_allowlist
Open

toddhainsworth wants to merge 1 commit into
mainfrom
feature/MI-331_secure_rest_api_ip_allowlist

Conversation

@toddhainsworth

Copy link
Copy Markdown
Member

Summary

  • Add optional allowedIps prop to SecureRestApi (IPv4/IPv6 addresses or CIDR ranges)
  • Enforced with an API Gateway resource policy: Allow execute-api:Invoke, Deny when aws:SourceIp is not in the list
  • Entries are validated at synth with node:net; an empty array or any malformed entry throws, naming every bad value
  • Omitting the prop leaves behaviour unchanged (no resource policy)

Notes

  • The Deny applies to CORS preflight (OPTIONS) too, documented in the README
  • 0.0.0.0/0 and ::/0 are accepted but disable the restriction
  • Chose a prop over an aspect: it configures a single construct. A shared policy helper could back an aspect later if we want to enforce this across all RestApis
  • A test confirms changing the list changes the Deployment logical ID, so the policy is redeployed

Changeset

@aligent/cdk-secure-rest-api: minor

@crispy101 crispy101 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants