함수 프록시 통합으로 REST API 만들기
함수 프록시 통합으로 REST API 만들기 (Create a rest API with function proxy integration)
다음 코드 예제는 다음을 수행하는 방법을 보여줍니다:
- Lambda 실행용 IAM 역할 만들기
- Lambda 함수 만들기 및 배포
- REST API 만들기
- Lambda 프록시 통합 구성
- API 배포 및 테스트
- 리소스 정리
본문
Bash
AWS CLI with Bash script
참고
GitHub에서 더 많은 내용을 볼 수 있습니다. 전체 예제와 설정·실행 방법은 Sample developer tutorials 리포지토리에서 확인하세요.
#!/bin/bash
set -euo pipefail
# Simple API Gateway Lambda Integration Script
# This script creates a REST API with Lambda proxy integration
# Generate random identifiers
FUNCTION_NAME="GetStartedLambdaProxyIntegration-$(openssl rand -hex 4)"
ROLE_NAME="GetStartedLambdaBasicExecutionRole-$(openssl rand -hex 4)"
API_NAME="LambdaProxyAPI-$(openssl rand -hex 4)"
# Get AWS account info
ACCOUNT_ID=$(aws sts get-caller-identity --query Account --output text)
REGION=$(aws configure get region || echo "us-east-1")
# Validate inputs
if [[ -z "$ACCOUNT_ID" ]] || [[ -z "$REGION" ]]; then
echo "Error: Failed to retrieve AWS account information" >&2
exit 1
fi
echo "Creating Lambda function code..."
# Create Lambda function code with input validation
cat > lambda_function.py <<'EOF'
import json
def lambda_handler(event, context):
# Extract data from the request
query_params = event.get('queryStringParameters') or {}
headers = event.get('headers') or {}
body = event.get('body')
# Try to parse JSON body if present
body_data = {}
if body:
try:
body_data = json.loads(body)
except json.JSONDecodeError:
return {
'statusCode': 400,
'body': json.dumps({'error': 'Invalid JSON'})
}
# Build response with data from query, header, and body
response_data = {
'message': 'Hello from Lambda!',
'queryParameter': query_params.get('greeter', 'No query parameter'),
'headerValue': headers.get('greeter', 'No header'),
'bodyValue': body_data.get('greeter', 'No body')
}
return {
'statusCode': 200,
'headers': {'Content-Type': 'application/json'},
'body': json.dumps(response_data)
}
EOF
# Create deployment package
zip function.zip lambda_function.py || {
echo "Error: Failed to create deployment package" >&2
exit 1
}
echo "Creating IAM role..."
# Create IAM trust policy
cat > trust-policy.json <<'EOF'
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Service": "lambda.amazonaws.com"
},
"Action": "sts:AssumeRole"
}
]
}
EOF
aws iam create-role \
--role-name "$ROLE_NAME" \
--assume-role-policy-document file://trust-policy.json >/dev/null || {
echo "Error: Failed to create IAM role" >&2
exit 1
}
aws iam tag-role --role-name "$ROLE_NAME" --tags Key=project,Value=doc-smith Key=tutorial,Value=apigateway-lambda-integration
# Attach execution policy
aws iam attach-role-policy \
--role-name "$ROLE_NAME" \
--policy-arn "arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole" || {
echo "Error: Failed to attach IAM policy" >&2
exit 1
}
# Wait for role propagation
sleep 15
echo "Creating Lambda function..."
# Create Lambda function with Python 3.11 (more recent runtime)
aws lambda create-function \
--function-name "$FUNCTION_NAME" \
--runtime python3.11 \
--role "arn:aws:iam::$ACCOUNT_ID:role/$ROLE_NAME" \
--handler lambda_function.lambda_handler \
--zip-file fileb://function.zip \
--timeout 30 \
--memory-size 128 \
--environment "Variables={LOG_LEVEL=INFO}" \
--tags project=doc-smith,tutorial=apigateway-lambda-integration || {
echo "Error: Failed to create Lambda function" >&2
exit 1
}
echo "Creating API Gateway..."
# Create REST API with minimum logging
API_RESPONSE=$(aws apigateway create-rest-api \
--name "$API_NAME" \
--endpoint-configuration types=REGIONAL \
--description "API for Lambda proxy integration tutorial" \
--tags project=doc-smith,tutorial=apigateway-lambda-integration \
--output json)
API_ID=$(echo "$API_RESPONSE" | grep -o '"id": "[^"]*"' | head -1 | cut -d'"' -f4)
if [[ -z "$API_ID" ]]; then
echo "Error: Failed to create API Gateway" >&2
exit 1
fi
# Get root resource ID
ROOT_RESOURCE_ID=$(aws apigateway get-resources --rest-api-id "$API_ID" --query 'items[?path==`/`].id' --output text)
# Create helloworld resource
aws apigateway create-resource \
--rest-api-id "$API_ID" \
--parent-id "$ROOT_RESOURCE_ID" \
--path-part helloworld || {
echo "Error: Failed to create resource" >&2
exit 1
}
# Get resource ID
RESOURCE_ID=$(aws apigateway get-resources --rest-api-id "$API_ID" --query "items[?pathPart=='helloworld'].id" --output text)
# Create ANY method with no authorization (intentional for tutorial)
aws apigateway put-method \
--rest-api-id "$API_ID" \
--resource-id "$RESOURCE_ID" \
--http-method ANY \
--authorization-type NONE || {
echo "Error: Failed to create method" >&2
exit 1
}
# Set up Lambda proxy integration
LAMBDA_URI="arn:aws:apigateway:$REGION:lambda:path/2015-03-31/functions/arn:aws:lambda:$REGION:$ACCOUNT_ID:function:$FUNCTION_NAME/invocations"
aws apigateway put-integration \
--rest-api-id "$API_ID" \
--resource-id "$RESOURCE_ID" \
--http-method ANY \
--type AWS_PROXY \
--integration-http-method POST \
--uri "$LAMBDA_URI" || {
echo "Error: Failed to create integration" >&2
exit 1
}
# Grant API Gateway permission to invoke Lambda
STATEMENT_ID="apigateway-invoke-$(openssl rand -hex 4)"
SOURCE_ARN="arn:aws:execute-api:$REGION:$ACCOUNT_ID:$API_ID/*/*"
aws lambda add-permission \
--function-name "$FUNCTION_NAME" \
--statement-id "$STATEMENT_ID" \
--action lambda:InvokeFunction \
--principal apigateway.amazonaws.com \
--source-arn "$SOURCE_ARN" || {
echo "Error: Failed to add Lambda permission" >&2
exit 1
}
# Deploy API
aws apigateway create-deployment \
--rest-api-id "$API_ID" \
--stage-name test \
--description "Test deployment" || {
echo "Error: Failed to deploy API" >&2
exit 1
}
echo "Testing API..."
# Test the API
INVOKE_URL="https://$API_ID.execute-api.$REGION.amazonaws.com/test/helloworld"
echo "API URL: $INVOKE_URL"
# Test with query parameter (with proper URL encoding)
echo "Testing with query parameter:"
curl -s -X GET "$INVOKE_URL?greeter=John" | jq . 2>/dev/null || curl -s -X GET "$INVOKE_URL?greeter=John"
echo ""
# Test with header
echo "Testing with header:"
curl -s -X GET "$INVOKE_URL" \
-H 'content-type: application/json' \
-H 'greeter: John' | jq . 2>/dev/null || curl -s -X GET "$INVOKE_URL" \
-H 'content-type: application/json' \
-H 'greeter: John'
echo ""
# Test with body
echo "Testing with POST body:"
curl -s -X POST "$INVOKE_URL" \
-H 'content-type: application/json' \
-d '{"greeter": "John"}' | jq . 2>/dev/null || curl -s -X POST "$INVOKE_URL" \
-H 'content-type: application/json' \
-d '{"greeter": "John"}'
echo ""
echo "Tutorial completed! API is available at: $INVOKE_URL"
# Cleanup
echo "Cleaning up resources..."
# Delete API
aws apigateway delete-rest-api --rest-api-id "$API_ID" || echo "Warning: Failed to delete API" >&2
# Delete Lambda function
aws lambda delete-function --function-name "$FUNCTION_NAME" || echo "Warning: Failed to delete Lambda function" >&2
# Detach policy and delete role
aws iam detach-role-policy \
--role-name "$ROLE_NAME" \
--policy-arn "arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole" || echo "Warning: Failed to detach policy" >&2
aws iam delete-role --role-name "$ROLE_NAME" || echo "Warning: Failed to delete role" >&2
# Clean up local files securely
rm -f lambda_function.py function.zip trust-policy.json
echo "Cleanup completed!"
API 세부 정보는 AWS CLI 명령 참조의 다음 항목을 참조하세요:
AddPermissionAttachRolePolicyCreateDeploymentCreateFunctionCreateResourceCreateRestApiCreateRoleDeleteFunctionDeleteRestApiDeleteRoleDetachRolePolicyGetCallerIdentityGetResourcesGetRestApisPutIntegrationPutMethod
AWS SDK 개발자 안내서와 코드 예제의 전체 목록은 AWS SDK와 함께 Lambda 사용을 참조하세요. 이 주제에는 시작하기와 이전 SDK 버전에 대한 자세한 내용도 포함되어 있습니다.
더 알아보기 (Learn more)
- API Gateway에서 Lambda 사용
- Lambda 프록시 통합
- API Gateway로 Lambda 함수 호출