Description
Without an AWS WAF web ACL associated with a CloudFront distribution, WAF rules cannot inspect and restrict web requests at that layer.
Potential impact
Malicious requests or excessive traffic may reach the origin application. The actual protection depends on the application and its other defenses.
Remediation
Configure the WAF rules the service needs and set web_acl_id to the ARN of a web ACL for CloudFront. Check the effect on legitimate requests before enabling blocking.
Examples
These excerpts show only the WAF association. Create the web ACL in us-east-1 with CLOUDFRONT scope and supply its actual ARN through the variable.
Before
hcl
resource "aws_cloudfront_distribution" "example" {
enabled = true
is_ipv6_enabled = true
comment = var.site_domain
aliases = [var.site_domain]
}
After
hcl
resource "aws_cloudfront_distribution" "example" {
enabled = true
is_ipv6_enabled = true
comment = var.site_domain
web_acl_id = var.cloudfront_web_acl_arn
aliases = [var.site_domain]
}