Help Center/ Config/ User Guide/ Resource Compliance/ Built-In Policies/ API Gateway/ Dedicated API Gateway Bound to a Specified VPC
Updated on 2025-08-25 GMT+08:00

Dedicated API Gateway Bound to a Specified VPC

Rule Details

Table 1 Rule details

Parameter

Description

Rule Name

apig-instances-in-vpc

Identifier

Dedicated API Gateway Bound to a Specified VPC

Description

If a dedicated API gateway instance is not bound to a specified VPC, this instance is non-compliant.

Tag

apig

Trigger Type

Configuration change

Filter Type

apig.instances

Rule Parameters

authorizedVpcIds: VPC IDs used by dedicated API gateway instances

Application Scenarios

VPC allows you to create custom virtual networks in your logically isolated AZ. These networks are dedicated zones that are logically isolated for your ECS instances. You can define security groups, virtual private networks (VPNs), IP address segments, and bandwidth for a VPC. This facilitates internal network configuration and management and allows you to change your network in a secure and convenient manner. You can also customize the ECS access rules within a security group or between security groups to improve ECS security.

For more information about VPC, see VPC Service Overview.

Solution

Create a dedicated gateway in a specified VPC.

Rule Logic

  • If a dedicated API gateway instance is not in any of the specified VPCs, this instance is non-compliant.
  • If a dedicated API gateway instance is in any of the specified VPCs, this instance is compliant.