Description
CloudFront caching and delivery optimization can improve web content delivery. A service designed to use a CDN loses those benefits when its distribution is disabled or its origin configuration is incorrect. Not every service needs a CDN, and enabling one does not by itself block direct origin access.
Potential impact
- Missing caching and delivery optimization can increase latency or origin load.
- Direct origin access can bypass access controls or security policies applied at CloudFront.
Remediation
- For services that need a CDN, configure
originsanddefault_cache_behavior, and setenabled: true. Verify DNS and the actual service path. - Separately configure direct-origin restrictions, HTTPS on the client and origin connections, authentication and required edge security policies. Ensure caching does not share private responses between users, and test log delivery.
Examples
These excerpts require a real origin, logging bucket and permissions. The before example lacks the required origin and is not a complete distribution-creation example.
Before
- name: CloudFront 배포 생성
community.aws.cloudfront_distribution:
state: present
caller_reference: unique test distribution ID
default_cache_behavior:
target_origin_id: "my test origin-000111"
forwarded_values:
query_string: true
cookies:
forward: all
headers:
- "*"
viewer_protocol_policy: allow-all
smooth_streaming: true
compress: true
allowed_methods:
items:
- GET
- HEAD
cached_methods:
- GET
- HEAD
enabled: false
logging:
enabled: true
include_cookies: false
bucket: mylogbucket.s3.amazonaws.com
prefix: myprefix/
The origin is undefined and the distribution is disabled, so it cannot serve the intended content.
After
- name: CloudFront 배포 생성
community.aws.cloudfront_distribution:
state: present
caller_reference: unique test distribution ID
origins:
- id: "my test origin-000111"
domain_name: www.example.com
origin_path: /production
custom_origin_config:
http_port: 80
https_port: 443
origin_protocol_policy: https-only
origin_ssl_protocols:
- TLSv1.2
default_cache_behavior:
target_origin_id: "my test origin-000111"
forwarded_values:
query_string: true
cookies:
forward: all
headers:
- "*"
viewer_protocol_policy: allow-all
compress: true
allowed_methods:
items:
- GET
- HEAD
cached_methods:
- GET
- HEAD
logging:
enabled: true
include_cookies: false
bucket: mylogbucket.s3.amazonaws.com
prefix: myprefix/
enabled: true
This connects a custom origin that supports HTTPS and enables the distribution. viewer_protocol_policy: allow-all still permits client HTTP, so the example does not enforce HTTPS along the entire path.