aws-cloudformation / aws-cloudformation/cloudformation-coverage-roadmap

[AWS::ApiGatewayV2::DomainName] - [Coverage] - DomainNameConfiguration EndpointAccessMode

Open
#2,520 0 comments 2 reactions 0 assignees View on GitHub
Coverage
Dominant language
No language data
Stars
1.1k
Forks
62
PR merge metrics
No merged PRs in 30d

Description

### Name of the resource

AWS::ApiGatewayV2::DomainName

### Resource name

_No response_

### Description

AWS::ApiGatewayV2::DomainName DomainNameConfiguration supports [SecurityPolicy](https://docs.aws.amazon.com/AWSCloudFormation/latest/TemplateReference/aws-properties-apigatewayv2-domainname-domainnameconfiguration.html#cfn-apigatewayv2-domainname-domainnameconfiguration-securitypolicy) however when you use an enhanced security policy (SecurityPolicy_*), you must also specify an endpoint access mode. [source](https://aws.amazon.com/blogs/compute/enhancing-api-security-with-amazon-api-gateway-tls-security-policies/).
The property EndpointAccessMode is not supported.
In contrast AWS::ApiGateway::RestApi has received support for this property.

For PQ compliance the EndpointAccessMode is needed to enable PQ ciphers in the enhanced security policy.

### Other Details

_No response_

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the AWS::ApiGatewayV2::DomainName coverage and comparing it with the existing AWS::ApiGateway::RestApi support for EndpointAccessMode. Read the linked CloudFormation reference and AWS security-policy article to confirm the property behavior. Done means DomainNameConfiguration supports EndpointAccessMode for enhanced security policies and the coverage is represented.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws
Domain
api, cloud
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
65/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.