Review CloudFront distribution and origin configuration

Review the CloudFront distribution and origins needed by the service, and manage origin access, HTTPS and application security separately.

Description

If a service is designed to use CloudFront, a disabled distribution or missing origin configuration can prevent content from being delivered through the intended path. A CDN is not required for every external service, and its absence alone does not make a service vulnerable.

Enabling CloudFront does not by itself block direct access to the origin or application attacks. Review availability requirements together with the origin access policy.

Potential impact

  • A distribution that is needed but unavailable can interrupt content delivery or concentrate load on the origin.
  • Direct origin access can bypass access controls or filtering applied at CloudFront.

Remediation

  1. Determine whether the service needs a CDN, then configure Enabled, Origins and cache behaviors for the required distribution.
  2. Configure suitable origin access restrictions and HTTPS. Review viewer connections, authentication and any required WAF policies separately.
  3. Verify deployment status and the actual request path, and monitor errors and origin load.

Examples

These are distribution excerpts. A complete deployment also needs required settings such as a default cache behavior and a valid origin.

Before

yaml
Resources:
  MyDistribution:
    Type: AWS::CloudFront::Distribution
    Properties:
      DistributionConfig:
        Enabled: false
        DefaultRootObject: index.html

The distribution is disabled and has no origin.

After

yaml
Resources:
  MyDistribution:
    Type: AWS::CloudFront::Distribution
    Properties:
      DistributionConfig:
        Enabled: true
        DefaultRootObject: index.html
        Origins:
          - DomainName: www.example.com
            Id: origin1
            CustomOriginConfig:
              HTTPPort: 80
              HTTPSPort: 443
              OriginProtocolPolicy: https-only

This enables the distribution and specifies a custom origin reached over HTTPS. The excerpt does not configure viewer HTTPS or restrictions on direct origin access.

References