Review CloudFront distribution configuration

Configure origins and the actual delivery path for services that need a CDN.

Description

CloudFront caching and delivery optimization can improve web content delivery. A service designed to use a CDN loses those benefits when its distribution is disabled or its origin configuration is incorrect. Not every service needs a CDN, and enabling one does not by itself block direct origin access.

Potential impact

  • Missing caching and delivery optimization can increase latency or origin load.
  • Direct origin access can bypass access controls or security policies applied at CloudFront.

Remediation

  • For services that need a CDN, configure origins and default_cache_behavior, and set enabled: true. Verify DNS and the actual service path.
  • Separately configure direct-origin restrictions, HTTPS on the client and origin connections, authentication and required edge security policies. Ensure caching does not share private responses between users, and test log delivery.

Examples

These excerpts require a real origin, logging bucket and permissions. The before example lacks the required origin and is not a complete distribution-creation example.

Before

yaml
- name: CloudFront 배포 생성
  community.aws.cloudfront_distribution:
    state: present
    caller_reference: unique test distribution ID
    default_cache_behavior:
      target_origin_id: "my test origin-000111"
      forwarded_values:
        query_string: true
        cookies:
          forward: all
        headers:
          - "*"
      viewer_protocol_policy: allow-all
      smooth_streaming: true
      compress: true
      allowed_methods:
        items:
          - GET
          - HEAD
        cached_methods:
          - GET
          - HEAD
    enabled: false
    logging:
      enabled: true
      include_cookies: false
      bucket: mylogbucket.s3.amazonaws.com
      prefix: myprefix/

The origin is undefined and the distribution is disabled, so it cannot serve the intended content.

After

yaml
- name: CloudFront 배포 생성
  community.aws.cloudfront_distribution:
    state: present
    caller_reference: unique test distribution ID
    origins:
      - id: "my test origin-000111"
        domain_name: www.example.com
        origin_path: /production
        custom_origin_config:
          http_port: 80
          https_port: 443
          origin_protocol_policy: https-only
          origin_ssl_protocols:
            - TLSv1.2
    default_cache_behavior:
      target_origin_id: "my test origin-000111"
      forwarded_values:
        query_string: true
        cookies:
          forward: all
        headers:
          - "*"
      viewer_protocol_policy: allow-all
      compress: true
      allowed_methods:
        items:
          - GET
          - HEAD
        cached_methods:
          - GET
          - HEAD
    logging:
      enabled: true
      include_cookies: false
      bucket: mylogbucket.s3.amazonaws.com
      prefix: myprefix/
    enabled: true

This connects a custom origin that supports HTTPS and enables the distribution. viewer_protocol_policy: allow-all still permits client HTTP, so the example does not enforce HTTPS along the entire path.

References