{APIGateway}HTTP API のログ記録の設定

https://docs.aws.amazon.com/ja_jp/apigateway/latest/developerguide/http-api-logging.html


-- 1. コマンド等のインストール

-- 1.1 aws cli version 2 インストール

curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip"
unzip awscliv2.zip
sudo ./aws/install

aws --version

-- 1.2 jqインストール
sudo yum -y install jq


-- 2. IAMロール作成
vim role01.json

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "Service": "lambda.amazonaws.com"
      },
      "Action": "sts:AssumeRole"
    }
  ]
}

aws iam create-role \
--role-name role01 \
--assume-role-policy-document file://role01.json


-- 3. ポリシーをロールにアタッチ
aws iam attach-role-policy \
--policy-arn arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole \
--role-name role01

-- 4. Lambda関数作成

vim test.js

exports.handler = async (event) => {
    const response = {
        statusCode: 200,
        body: JSON.stringify('Hello from Lambda!'),
    };
    return response;
};


chmod 755 test.js
zip test.zip test.js

aws lambda create-function \
--function-name func01 \
--zip-file fileb://test.zip \
--handler test.handler  \
--runtime nodejs14.x  \
--role arn:aws:iam::999999999999:role/role01


aws lambda list-functions | grep func01

aws lambda get-function --function-name func01

 


-- 5. HTTP API を作成する

aws apigatewayv2 create-api \
--name api01 \
--protocol-type HTTP \
--target arn:aws:lambda:ap-northeast-1:999999999999:function:func01

 

aws apigatewayv2 get-apis
aws apigatewayv2 get-apis| jq -r .Items.ApiId


aws apigatewayv2 get-api \
--api-id 1111111111


aws apigatewayv2 get-integrations \
--api-id 1111111111

aws apigatewayv2 get-integrations \
--api-id 1111111111| jq -r .Items.IntegrationId


aws apigatewayv2 create-route \
--api-id 1111111111 \
--route-key 'ANY /func01' \
--target integrations/2222222


aws apigatewayv2 get-routes \
--api-id 1111111111

 


aws apigatewayv2 get-deployments \
--api-id 1111111111


aws apigatewayv2 get-stages \
--api-id 1111111111

 

 

-- 6. Lambda関数に権限を追加する

aws lambda add-permission \
--function-name func01 \
--statement-id apigw \
--action lambda:InvokeFunction \
--principal apigateway.amazonaws.com \
--source-arn "arn:aws:execute-api:ap-northeast-1:999999999999:1111111111/*/*/func01"

 

aws lambda get-policy \
--function-name func01 | jq -r .Policy  | jq .


-- 7. API をテストする

curl https://1111111111.execute-api.ap-northeast-1.amazonaws.com/func01

 

-- 8. ロググループの作成

aws logs create-log-group --log-group-name lg01

aws logs describe-log-groups --log-group-name-prefix lg01


-- 9. ステージのログ記録の有効化

aws apigatewayv2 update-stage \
--api-id 1111111111 \
--stage-name '$default' \
--access-log-settings '{"DestinationArn": "arn:aws:logs:ap-northeast-1:999999999999:log-group:lg01:*","Format": "$context.identity.sourceIp - - [$context.requestTime] \"$context.httpMethod $context.routeKey $context.protocol\" $context.status $context.responseLength $context.requestId"}'

 

 

-- 10. クリーンアップ

-- ロググループの削除

aws logs describe-log-groups --log-group-name-prefix lg01
aws logs delete-log-group --log-group-name lg01

 

 

-- HTTP APIの削除
aws apigatewayv2 get-apis

aws apigatewayv2 delete-api \
--api-id 1111111111

 

-- Lambda関数の削除
aws lambda get-function --function-name func01
aws lambda delete-function --function-name func01


-- ロールの削除
aws iam list-roles | grep role01

aws iam detach-role-policy \
--role-name role01 \
--policy-arn arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole

aws iam delete-role --role-name role01