Review the CloudFront WAF association

Apply WAF rules suited to the application’s risks.

Description

Without an AWS WAF web ACL associated with a CloudFront distribution, WAF rules cannot inspect and restrict web requests at that layer.

Potential impact

Malicious requests or excessive traffic may reach the origin application. The actual protection depends on the application and its other defenses.

Remediation

Configure the WAF rules the service needs and set web_acl_id to the ARN of a web ACL for CloudFront. Check the effect on legitimate requests before enabling blocking.

Examples

These excerpts show only the WAF association. Create the web ACL in us-east-1 with CLOUDFRONT scope and supply its actual ARN through the variable.

Before

hcl
resource "aws_cloudfront_distribution" "example" {
  enabled         = true
  is_ipv6_enabled = true
  comment         = var.site_domain

  aliases = [var.site_domain]
}

After

hcl
resource "aws_cloudfront_distribution" "example" {
  enabled         = true
  is_ipv6_enabled = true
  comment         = var.site_domain
  web_acl_id      = var.cloudfront_web_acl_arn

  aliases = [var.site_domain]
}

References