Review CloudFront content delivery configuration

Configure the CloudFront distribution and origin needed by the service.

Description

A CloudFront distribution must be enabled and have an origin configured to serve content. An intentionally disabled distribution, such as one for a retired service, does not need to be re-enabled.

Potential impact

A disabled distribution or missing origin can interrupt content delivery for a service that relies on CloudFront.

Remediation

Set enabled = true and the correct origin for the distribution the service needs. Configure cache behaviors and origin access, then test actual content requests.

Examples

These excerpts show only enablement and origin settings, using an existing S3 origin access identity. A complete distribution also needs cache behaviors and other required settings.

Before

hcl
resource "aws_cloudfront_distribution" "example" {
  enabled = false
}

After

hcl
resource "aws_cloudfront_distribution" "example" {
  origin {
    domain_name = aws_s3_bucket.b.bucket_regional_domain_name
    origin_id   = local.s3_origin_id

    s3_origin_config {
      origin_access_identity = "origin-access-identity/cloudfront/ABCDEFG1234567"
    }
  }

  enabled = true
}

References