Description
Associating an AWS WAF web ACL with CloudFront allows HTTP and HTTPS requests to be inspected or blocked according to its rules. When a service needs this protection, omitting the association leaves that request filtering unavailable at CloudFront. A web ACL does not stop every attack; application authentication and vulnerability fixes remain necessary.
Potential impact
- Requests that exploit application weaknesses may reach the origin.
- Missing request filters or rate limits can increase service load.
Remediation
- Configure the required web ACL and associate it through
web_acl_id. For AWS WAFv2, use the ARN of a web ACL intended for CloudFront. - Review managed and service-specific rules and test that legitimate requests remain allowed.
- Monitor WAF logs and metrics, and restrict direct access to the origin as needed.
Examples
These excerpts compare web ACL association. Replace the origin address and supply an existing CloudFront WAFv2 web ACL ARN through cloudfront_web_acl_arn.
Before
- name: create a basic distribution with defaults and tags
community.aws.cloudfront_distribution:
state: present
default_origin_domain_name: www.my-cloudfront-origin.com
No web ACL is associated in this example. Check whether other configuration provides the web request protection the service needs.
After
- name: create a basic distribution with defaults and tags
community.aws.cloudfront_distribution:
state: present
default_origin_domain_name: www.my-cloudfront-origin.com
web_acl_id: "{{ cloudfront_web_acl_arn }}"
This associates a web ACL with the distribution. Actual blocking depends on its rules and default action.