Skip to content

fix(aws-apigatewayv2): deployments, validation, tags, pagination and quick-create - #1374

Merged
NitinKumar004 merged 3 commits into
developmentfrom
fix/aws-apigatewayv2-a7a
Sep 27, 2026
Merged

NitinKumar004 merged 3 commits into
developmentfrom
fix/aws-apigatewayv2-a7a

Conversation

@NitinKumar004

@NitinKumar004 NitinKumar004 commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

API Gateway v2 had CRUD only. This PR adds deployments, input validation, tagging, pagination and quick create for HTTP and WebSocket APIs. All of it lives in the provider (providers/aws/apigatewayv2), and the wire handler only maps it to restJson1.

Deployments

  • CreateDeployment, GetDeployment(s), UpdateDeployment and DeleteDeployment under /v2/apis/{apiId}/deployments.
  • Each deployment freezes a copy of the API's routes and integrations. The A7b data plane will serve a non-autoDeploy stage from that copy.
  • deploymentStatus is DEPLOYED. An API with no routes returns Unable to deploy API because no routes exist in this API.
  • With stageName, the stage moves to the new deployment, and lastDeploymentStatusMessage records the move.
  • A stage with autoDeploy gets a new automatic deployment (autoDeployed: true, the real description text) when it is created or switched on. It also gets one whenever a route or integration changes.
  • A stage deploymentId must name an existing deployment. A deployment that a stage still points at cannot be deleted.

Validation (BadRequestException / ConflictException)

  • RouteKey on HTTP APIs must be $default or METHOD /path, and a duplicate key returns ConflictException.
  • A route target must name an existing integration.
  • UpdateRoute now applies authorizationScopes and validates authorizationType for the API's protocol.
  • Integration type is checked against the protocol: HTTP APIs take only AWS_PROXY and HTTP_PROXY.
  • payloadFormatVersion: 2.0 only on AWS_PROXY, and WebSocket APIs take 1.0 only. The timeout must be within 50 to 30000 (29000 for WebSocket).
  • WebSocket APIs require routeSelectionExpression. HTTP APIs accept only the method and path expression, in the bare or the braced ${request.method} ${request.path} form that CDK sends. The API key expression accepts both forms too.
  • CORS configuration is rejected on WebSocket APIs. UpdateStage rejects a deploymentId while autoDeploy is on.
  • Integrations now store and echo requestTemplates, templateSelectionExpression and passthroughBehavior, so WebSocket MOCK integrations plan clean.
  • Stage names must match ^[a-zA-Z0-9_-]+$ or be $default.
  • A WebSocket API's apiEndpoint now uses wss://.

Tags

  • TagResource, UntagResource and GetTags at /v2/tags/{resource-arn}. Before this, the request fell through to S3.
  • API and stage ARNs work. CreateStage accepts tags, and GetApi, GetApis and GetStage always render tags.
  • Domain name and VPC link ARNs return NotFoundException until those resources exist (A11, A12a).
  • Tag limits (50 tags, keys up to 128 and values up to 256 characters, aws: prefix reserved) are enforced.

Pagination

  • maxResults (a string in the query, any positive integer) and nextToken on GetApis, GetRoutes, GetIntegrations, GetStages and GetDeployments.
  • An out-of-range or non-numeric value, or a bad token, returns BadRequestException.

Quick create

  • CreateApi with target builds a managed integration: AWS_PROXY with payload 2.0 for a Lambda ARN, or HTTP_PROXY with ANY and 1.0 for a URL. It also builds a route for routeKey (default $default) and a managed $default stage with autoDeploy.
  • credentialsArn goes on the integration.
  • UpdateApi's target, routeKey and credentialsArn update the managed resources.
  • Managed stages cannot be updated or deleted, a managed integration cannot be deleted, and a managed route keeps its key except through UpdateApi.

Persist covers the new state: deployments with their frozen routes and integrations, stage tags and the managed flags.

The execute-api host still answers 403 Missing Authentication Token for a v2 id. The v2 data plane is A7b, and the §3.4 pin test in server/aws/apigateway still passes.

Testing

  • New wire tests for each area and provider tests for deployments, managed rules, tags and snapshot round-trips. All of them failed on the old code.
  • go build ./..., then scoped go vet and go test -race on the touched packages plus server/aws/apigateway. The server/aws dispatch-ordering and persist completeness tests pass.
  • golangci-lint --new-from-rev=origin/development reports 0 issues. docs/coverage is regenerated.
  • AWS CLI against cloudemu serve covered quick create with a Lambda target, a route, an integration and an autoDeploy stage, a manual deployment, tag and untag on API and stage ARNs, and --page-size and --max-items paging. It also ran every error case above and the execute-api host.
  • Terraform (aws provider 6.66.0) covered aws_apigatewayv2_api (quick create and full with CORS), _integration, _route, _stage (auto_deploy and a named stage) and _deployment with triggers and create_before_destroy. The run went apply, clean plan, update, clean plan, destroy.

@NitinKumar004
NitinKumar004 marked this pull request as ready for review September 27, 2026 13:23
@NitinKumar004
NitinKumar004 merged commit 98681a2 into development Sep 27, 2026
23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant