AWS HTTP API Gateway as a proxy to private S3 bucket

Viewed 761

I have a private S3 bucket with lots of small files. I'd like to expose the contents of the bucket (only read-only access) using AWS API Gateway as a proxy. Both S3 bucket and AWS API Gateway belong to the same AWS account and are in the same VPC and Availability Zone.

AWS API Gateway comes in two types: HTTP API, REST API. The configuration options of REST API are more advanced, additionally, REST API supports much more AWS services integrations than the HTTP API. In fact, the use case I described above is fully covered in one of the documentation tabs of REST API. However, REST API has one huge disadvantage - it's about 70% more expensive than the HTTP API, the price comes with more configuration options but as for now, I need only one - integration with the S3 service that's why I believe this type of service is not well suited for my use case. I started searching if HTTP API can be integrated with S3, and so far I haven't found any way to achieve it.

I tried creating/editing service-linked roles associated with the HTTP API Gateway instance, but those roles can't be edited (only read-only access). As for now, I don't have any idea where I should search next, or if my goal is even achievable using HTTP API.

1 Answers

I am a fan of AWSs HTTP APIs. I work daily with an API that serves a very similar purpose. The way I have done it is by using AWS Lambda functions integrated with the APIs paths.

What works for me is this:

Define your API paths, and integrate them with AWS Lambda functions.

Have your integrated Lambda function return a signed URL for any objects you want to provide access to through API calls.

There are several different ways to pass the name of the object(s) you want to the Lambda function servicing the API call.

This is the short answer. I plan to give a longer answer at a later time. But this has worked for me.

Related