fix(integration-tests): make MyFirstApiKey value stack-scoped - #3997
Merged
licjun merged 1 commit intoSep 25, 2026
Merged
Conversation
The api_with_authorizer_apikey template hardcodes both the API Key's
Value and the Lambda authorizer's usageIdentifierKey to the literal
"needatleast20characters". AWS API Gateway enforces an undocumented
uniqueness constraint on the API Key value across account+region
(returns 409 ConflictException with HandlerErrorCode: AlreadyExists
on collision). Any orphaned resource from a previous run - for
example, a test runner that timed out before its cleanup could
complete - will hold the value and block every subsequent run of
this test until the orphan is deleted externally.
Scope the API Key value to ${AWS::StackName} so it is unique per
CFN stack, while still matching the authorizer's usageIdentifierKey.
Substituted length stays within API Gateway's [20, 128]-character
bounds (empirically verified: min=20 with "API Key value should be
at least 20 characters", max=128 with "API Key value exceeds
maximum size of 128 characters"). Verified end-to-end by deploying
the fixed template as two concurrent stacks in a dev account -
both created cleanly with distinct stack-scoped values, and the
runtime authorizer flow returned 200 for allow / 403 for deny.
vicheey
approved these changes
Sep 24, 2026
reedham-aws
approved these changes
Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The
api_with_authorizer_apikeyintegration test template hardcodes both theAWS::ApiGateway::ApiKey.Valueand the Lambda authorizer'susageIdentifierKeyto the literal"needatleast20characters".AWS API Gateway enforces an undocumented uniqueness constraint on
valueacross account + region (returns409 ConflictException/HandlerErrorCode: AlreadyExistson collision). Any leftover key from a previous run — for example, a test runner that timed out before cleanup could complete — will collide with the next run's stack creation, and the stack rolls back toROLLBACK_COMPLETE. Both the first attempt and any--rerunsretry hit the same collision (same hardcoded literal), so the test fails deterministically until the orphaned key is deleted externally.Fix
Substitute
${AWS::StackName}into bothValueand the authorizer'susageIdentifierKey. Because${AWS::StackName}is unique per CFN stack (which is unique per run), the API Key value is unique per run, and the authorizer + key still resolve to the same string at runtime.Length bounds (empirically verified)
CreateApiKey.valuemin = 20 characters ("API Key value should be at least 20 characters")CreateApiKey.valuemax = 128 characters ("API Key value exceeds maximum size of 128 characters")19 (prefix "needatleast20chars-") + len(stackName). For representative integration-test stack names (~60–70 characters), the result is well within[20, 128].Testing
Verified end-to-end in a dev account:
fix-test-stack-alphaandfix-test-stack-beta) — bothCREATE_COMPLETE, noAlreadyExistscollision (previously, one of the two would fail with this signature).needatleast20chars-<stackName>(i.e.,${AWS::StackName}is correctly substituted at deploy time).GET /lambda-token-api-keywithAuthorization: allowreturns 200 (authorizer'susageIdentifierKeymatches the API Key value → usage plan matches), andAuthorization: denyreturns 403.integration/combination/test_api_with_authorizer_apikey.py) reads the API Key value from AWS at runtime (get_api_key(..., includeValue=True)) and does not depend on any specific literal, so no test-code changes are needed.