feat(aws-apigateway): client certificates, documentation parts and versions, account settings - #1379
Merged
Merged
Conversation
…rsions, account settings
…teway-a12b # Conflicts: # docs/coverage/aws/README.md # server/aws/apigateway/handler.go
NitinKumar004
marked this pull request as ready for review
September 27, 2026 18:11
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A12b from the API Gateway build-out plan. Adds the REST API (v1) resources that sit next to the API tree: client certificates, documentation parts and versions, and the account settings. Behaviour lives in the provider; the wire handler only maps routes and shapes.
Client certificates
POST /clientcertificates,GET /clientcertificates(position/limit paging, default 25, max 500),GET|PATCH|DELETE /clientcertificates/{id}.pemEncodedCertificateis a real self-signed RSA-2048 certificate with a 365-day validity.expirationDatematches its NotAfter. Only the public certificate is kept./descriptiononly. Any other path is a BadRequest.PUT|GET|DELETE /tags/{arn}for client certificate and REST API ARNs. Other API Gateway ARNs (the v2/apistree) and other services' ARNs still fall through to their own handlers./clientCertificateIdmust name an existing certificate (404 otherwise). Deleting a certificate that a stage still uses returns a BadRequest that names the stages.Documentation parts
PUT .../documentation/parts?mode=merge|overwrite&failonwarnings=).nameor a badstatusCode. Defaults are filled on read (path/,methodandstatusCode*), so an omitted field and its explicit default are the same location.Documentation part already exists for the specified location: type 'API'.).type,path(exact),name(substring),locationStatus(DOCUMENTED means non-empty properties).x-amazon-apigateway-documentationfrom a JSON or YAML OpenAPI body. Merge keeps the part id at a location it already has; overwrite replaces all parts. Invalid entries come back as warnings, or fail the whole import underfailonwarnings.Documentation versions
stageNameit also sets that stage'sdocumentationVersion. Get, List (paged), Update (/description) and Delete are included.documentationVersion(CreateStage or/documentationVersionpatch) must name an existing version. Deleting a version that a stage uses is a BadRequest.Account
GET /accountdefaults: throttle 10000 rps and burst 5000, features[UsagePlans], apiKeyVersion4.PATCH /accountaccepts/cloudwatchRoleArn(replace or remove, must be a role ARN) and/features(add or remove UsagePlans). Throttle settings and apiKeyVersion are read-only in AWS, so patching them is a BadRequest.Other
Testing
go build ./..., then vet andgo test -raceon the touched packages and persist.golangci-lint --new-from-rev=origin/developmentreports 0 issues.serve: generated a cert, attached it to a stage, got the in-use delete error, created parts, got the duplicate and invalid-location errors, ran a merge import with a warning and a failOnWarnings import, created a doc version on the stage, updated the account, and hit the bad-role and read-only-path errors. After detaching, all deletes succeeded.aws_api_gateway_client_certificate,aws_api_gateway_documentation_part,aws_api_gateway_documentation_version,aws_api_gateway_account, and a stage usingclient_certificate_idanddocumentation_version: apply, plan clean, update every mutable field, plan clean, destroy.Notes
I couldn't confirm two behaviours from the AWS docs: whether deleting an in-use client certificate, or a documentation version tied to a stage, is blocked, and which error it returns. Both are blocked with a BadRequest for now. Stage tags are left for a later change.