Q: You are deploying an API Gateway mapped to a custom domain name natively in the `eu-west-1` (Ireland) region. You request a free ACM (AWS Certificate Manager) SSL certificate in `eu-west-1`, but API Gateway absolutely refuses to let you select it from the dropdown. Why?
This happens because you selected an Edge-Optimized API Gateway endpoint.
#AWS #Cost & Architecture #L2 #Cloud #Infrastructure
🎙️ Candidate Opening & Architectural Context
""In a previous role, our monitoring paged me for a similar incident across our AWS VPC infrastructure. The interviewer is testing: Edge-optimized APIs vs Regional APIs, ACM region constraints.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Production Solution & Architecture
This happens because you selected an Edge-Optimized API Gateway endpoint. Edge-optimized endpoints are actually deployed globally onto the CloudFront Content Delivery Network (CDN) edge locations. CloudFront strictly mandates that all ACM SSL certificates must reside exclusively in the us-east-1 (N. Virginia) region, regardless of where the underlying API Gateway actually lives. *Fix:* Either request a new ACM certificate in us-east-1 and attach it, or change the API Gateway endpoint type from "Edge-Optimized" to "Regional", which will natively accept the existing eu-west-1 certificate.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: This happens because you selected an Edge-Optimized API Gateway endpoint.."
⚡ 60-Second Elevator Pitch Talking Points
- Immediate Triage: This happens because you selected an Edge-Optimized API Gateway endpoint.
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement