CloudFront WAF association needs review

Without required WAF rules, CloudFront has fewer controls for filtering web attacks and automated abuse at the edge.

Description

Associating an AWS WAF web ACL with CloudFront allows HTTP and HTTPS requests to be inspected or blocked according to its rules. When a service needs this protection, omitting the association leaves that request filtering unavailable at CloudFront. A web ACL does not stop every attack; application authentication and vulnerability fixes remain necessary.

Potential impact

  • Requests that exploit application weaknesses may reach the origin.
  • Missing request filters or rate limits can increase service load.

Remediation

  • Configure the required web ACL and associate it through web_acl_id. For AWS WAFv2, use the ARN of a web ACL intended for CloudFront.
  • Review managed and service-specific rules and test that legitimate requests remain allowed.
  • Monitor WAF logs and metrics, and restrict direct access to the origin as needed.

Examples

These excerpts compare web ACL association. Replace the origin address and supply an existing CloudFront WAFv2 web ACL ARN through cloudfront_web_acl_arn.

Before

yaml
- name: create a basic distribution with defaults and tags
  community.aws.cloudfront_distribution:
    state: present
    default_origin_domain_name: www.my-cloudfront-origin.com

No web ACL is associated in this example. Check whether other configuration provides the web request protection the service needs.

After

yaml
- name: create a basic distribution with defaults and tags
  community.aws.cloudfront_distribution:
    state: present
    default_origin_domain_name: www.my-cloudfront-origin.com
    web_acl_id: "{{ cloudfront_web_acl_arn }}"

This associates a web ACL with the distribution. Actual blocking depends on its rules and default action.

References