IaC Bazaar
AWSLive-tested

API Gateway HTTP API

HTTP API with routes, Lambda/ALB integrations, custom domain, JWT authorizers, and access logs.

terraformAWS#aws
aws-apigateway-httpterraform v1.7

Verification

Live-tested

Really deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan test superseded by live test

Provenance

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-06-11 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o aws-apigateway-http-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/aws-apigateway-http/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle aws-apigateway-http-1.0.0.sigstore.json \
  aws-apigateway-http-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "e4af8581fc75d04976c6efea6494b552baae0a4a8f052270f9f3658af4f41449  aws-apigateway-http-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "apigateway_http" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-apigateway-http/aws"
  version = "1.0.0"
}

Paid module — needs a purchase (or a subscription that covers it) plus a registry token from /account/tokens. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract — every input name, type, default and description, plus every output — is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every Free module. This one is Professional, so its contract unlocks when you buy it.

Documentation

aws-apigateway-http — API Gateway HTTP API

An HTTP API (API Gateway v2) wired end to end: typed integrations (Lambda-proxy or any HTTP/ALB backend, including private VPC-Link upstreams), JWT and Lambda authorizers, routes that bind methods/paths to those backends, a stage with throttling and structured JSON access logs, and an optional regional custom domain (ACM-backed, TLS 1.2 floor, optional mutual TLS). Works with Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.

Status: static-validated, live-test pending. Ships under live-test quarantine — validated with tofu fmt, tofu validate, and tflint. Real apply → curl the invoke URL → destroy against an AWS account is pending a cloud sandbox. HTTP APIs are cheap and fast to test (no minimum charge, the invoke URL is the verify target), so this is first in line for the live lane.

Secure / sane defaults

  • Deny-by-default authorization. Routes that name no authorizer inherit default_authorization_type, which is AWS_IAM — unauthenticated callers are rejected unless a route is explicitly opened with authorization_type = NONE. Flip the default to NONE only for a genuinely public API.
  • CORS off by default. No CORS headers are emitted (same-origin only) until you opt in; the module refuses the allow_credentials + "*" origin combination that AWS rejects.
  • Access logs on by default, streamed as a structured JSON record (request id, source IP, route, status, latency, integration error) to a module-managed CloudWatch log group with 30-day retention (KMS optional).
  • TLS 1.2 floor on the custom domain, regional endpoint type, optional mutual-TLS client authentication via an S3 truststore.
  • Throttling on by default (burst/rate caps in default_route_settings) so a single client cannot exhaust the account-wide soft limits.
  • integration_method is dropped automatically for AWS_PROXY, and connection_id only applies to VPC_LINK integrations — invalid AWS combos are pruned for you.

Requirements

  • Terraform or OpenTofu >= 1.6
  • hashicorp/aws >= 6.0, < 7.0

License

Commercial — LicenseRef-IaCBazaar-Commercial. © IaC Bazaar. Original work (not derived from a third-party module).

Usage code & full reference unlock after purchase

The complete copy-paste usage, the full input/output reference, and operational notes ship with your licence - shown here and bundled in the download.

  • Usage
  • Inputs (key)
  • Outputs
  • Notes

Related modules