An API Group Whose ACL Is Attached and Whose APIs Name Their Auth Type
An API Gateway group, the APIs in it, and an access control list created WITH its attachment, since an unattached list looks exactly like protection in the console. auth_type ANONYMOUS means anybody with the URL calls the backend and has to be taken per API; force_nonce_check is on for every app-authenticated API, because without it a captured signed request can be replayed.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-15 · how we verify
Use it from the registry
terraform · opentofumodule "api_gateway" {
source = "www.iac-bazaar.com/iac-bazaar/alicloud-api-gateway/alicloud"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
alicloud-api-gateway
A managed API gateway on Alibaba Cloud API Gateway. Works with Terraform and OpenTofu
(>= 1.6), alicloud provider >= 1.0, < 2.0.
auth_type ANONYMOUS is an open API - anybody with the URL calls the backend. Every API names its auth type and ANONYMOUS has to be taken per API.
An access control list that is not attached does nothing, and an unattached list looks exactly like protection in the console. This module creates both or neither.
force_nonce_check is what stops a replay, and it is on for every APP-authenticated API here; without it a captured signed request can be sent again.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
tencent-api-gateway
An API Gateway service with net_type INNER rather than OUTER, https rather than the http that stays plaintext to the gateway, and QPS ceilings required - without a limit one caller can spend the whole backend's capacity. auth_type NONE and CORS are both named per API, since either turns an endpoint into an open one.
oci-api-gateway
Managed API gateway with route deployments, JWT/auth policies, rate limiting, CORS and custom-domain TLS.
gcp-api-gateway
A serverless API Gateway fronting an OpenAPI 2.0 spec - API, immutable config and managed gateway - with a dedicated least-privilege backend service account and a built-in default spec.
aws-apigateway-http
HTTP API with routes, Lambda/ALB integrations, custom domain, JWT authorizers, and access logs.
aws-apigateway-rest
A REST API wired end to end - resource tree built from route paths, deny-by-default IAM authorization, MOCK/Lambda/HTTP integrations, deployment + stage with throttling and JSON access logs.
azure-api-management
An API Management gateway tuned for the serverless Consumption tier - scale-to-zero, billed per call - with a system-assigned managed identity, TLS hardening, and HTTP/2 enabled.