An API Gateway Where No API Is Open or Unthrottled by Default
A Huawei Cloud APIG dedicated instance, group, environment and published APIs. The provider defaults an API to no authentication; this module defaults to signed app requests and takes open or plaintext APIs one at a time. Every published API gets the required rate limit, the gateway stays off the internet unless asked, and the debug hostname stays off.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- No applicable security policies for this provider
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-16 · how we verify
Use it from the registry
terraform · opentofumodule "api_gateway" {
source = "www.iac-bazaar.com/iac-bazaar/huawei-api-gateway/huaweicloud"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
huawei-api-gateway
An API gateway on Huawei Cloud API Gateway (dedicated). Works with Terraform and OpenTofu
(>= 1.6), huaweicloud provider >= 1.60, < 2.0.
An API with no authentication is an open endpoint, and that is the provider's default. Every API here defaults to APP (signed requests); NONE is taken per API with accept_no_auth.
HTTP and BOTH keep a plaintext listener open. HTTPS is the default; anything else is taken per API with accept_plaintext.
Nothing is limited until a policy is bound to a published API. The module publishes every API and binds the required rate_limit to all of them, so none is left unthrottled by omission. The optional IP access list is bound the same way.
The instance has no public ingress unless asked. public_ingress_mbit = null keeps the gateway on the VPC; the Huawei-issued debug hostname stays off unless debug_domain_access is set.
A dedicated instance bills from the moment it exists, whether or not an API is published on it.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
tencent-api-gateway
An API Gateway service with net_type INNER rather than OUTER, https rather than the http that stays plaintext to the gateway, and QPS ceilings required - without a limit one caller can spend the whole backend's capacity. auth_type NONE and CORS are both named per API, since either turns an endpoint into an open one.
oci-api-gateway
Managed API gateway with route deployments, JWT/auth policies, rate limiting, CORS and custom-domain TLS.
gcp-api-gateway
A serverless API Gateway fronting an OpenAPI 2.0 spec - API, immutable config and managed gateway - with a dedicated least-privilege backend service account and a built-in default spec.
aws-apigateway-http
HTTP API with routes, Lambda/ALB integrations, custom domain, JWT authorizers, and access logs.
aws-apigateway-rest
A REST API wired end to end - resource tree built from route paths, deny-by-default IAM authorization, MOCK/Lambda/HTTP integrations, deployment + stage with throttling and JSON access logs.
azure-api-management
An API Management gateway tuned for the serverless Consumption tier - scale-to-zero, billed per call - with a system-assigned managed identity, TLS hardening, and HTTP/2 enabled.