CloudFront logging settings need review

Without CloudFront access logs, request tracing and investigation of unusual traffic can be harder.

Description

CloudFront access logs record details such as request paths, response status and processing time. Without suitable request logs, unusual traffic and errors at the CDN layer can be harder to investigate. Logging does not itself block attacks.

Potential impact

  • Unusual requests and high-volume access patterns may be discovered late.
  • Incident investigations and troubleshooting may lack the necessary request history.

Remediation

  • Configure standard or real-time logging for the distribution. For the S3 delivery method below, set logging.enabled: true, a log bucket and a prefix.
  • Configure delivery permissions, access restrictions and retention for the chosen logging method, and confirm that logs arrive.
  • Standard logs are delivered on a best-effort basis; do not assume they account for every request.

Examples

These excerpts compare logging settings; required cache behavior and other settings are omitted. Both retain enabled: false, so the distribution is not enabled to serve content.

Before

yaml
- name: create a CloudFront distribution
  community.aws.cloudfront_distribution:
    state: present
    caller_reference: unique test distribution ID
    origins:
      - id: my test origin-000111
        domain_name: www.example.com
    enabled: false

This configuration has no log delivery settings. Also check any logging configured separately for the deployed distribution.

After

yaml
- name: create a CloudFront distribution
  community.aws.cloudfront_distribution:
    state: present
    caller_reference: unique test distribution ID
    origins:
      - id: my test origin-000111
        domain_name: www.example.com
    logging:
      enabled: true
      include_cookies: false
      bucket: mylogbucket.s3.amazonaws.com
      prefix: myprefix/
    enabled: false

This enables S3 log delivery. Substitute the actual bucket and prefix and provide the permissions required by that logging method.

References