aws-cloudformation / aws-cloudformation/cloudformation-coverage-roadmap
[AWS::ApiGatewayV2::DomainName] - [Coverage] - DomainNameConfiguration EndpointAccessMode
- Dominant language
- No language data
- Stars
- 1.1k
- Forks
- 62
- PR merge metrics
- No merged PRs in 30d
Description
### Name of the resource
AWS::ApiGatewayV2::DomainName
### Resource name
_No response_
### Description
AWS::ApiGatewayV2::DomainName DomainNameConfiguration supports [SecurityPolicy](https://docs.aws.amazon.com/AWSCloudFormation/latest/TemplateReference/aws-properties-apigatewayv2-domainname-domainnameconfiguration.html#cfn-apigatewayv2-domainname-domainnameconfiguration-securitypolicy) however when you use an enhanced security policy (SecurityPolicy_*), you must also specify an endpoint access mode. [source](https://aws.amazon.com/blogs/compute/enhancing-api-security-with-amazon-api-gateway-tls-security-policies/).
The property EndpointAccessMode is not supported.
In contrast AWS::ApiGateway::RestApi has received support for this property.
For PQ compliance the EndpointAccessMode is needed to enable PQ ciphers in the enhanced security policy.
### Other Details
_No response_
Contributor guide
Research direction
Start by reviewing the AWS::ApiGatewayV2::DomainName coverage and comparing it with the existing AWS::ApiGateway::RestApi support for EndpointAccessMode. Read the linked CloudFormation reference and AWS security-policy article to confirm the property behavior. Done means DomainNameConfiguration supports EndpointAccessMode for enhanced security policies and the coverage is represented.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws
- Domain
- api, cloud
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 65/100