Description
A CloudFront distribution must be enabled and have an origin configured to serve content. An intentionally disabled distribution, such as one for a retired service, does not need to be re-enabled.
Potential impact
A disabled distribution or missing origin can interrupt content delivery for a service that relies on CloudFront.
Remediation
Set enabled = true and the correct origin for the distribution the service needs. Configure cache behaviors and origin access, then test actual content requests.
Examples
These excerpts show only enablement and origin settings, using an existing S3 origin access identity. A complete distribution also needs cache behaviors and other required settings.
Before
hcl
resource "aws_cloudfront_distribution" "example" {
enabled = false
}
After
hcl
resource "aws_cloudfront_distribution" "example" {
origin {
domain_name = aws_s3_bucket.b.bucket_regional_domain_name
origin_id = local.s3_origin_id
s3_origin_config {
origin_access_identity = "origin-access-identity/cloudfront/ABCDEFG1234567"
}
}
enabled = true
}