설명
CloudFront의 캐싱과 전송 최적화는 웹 콘텐츠 전달을 개선할 수 있습니다. CDN을 사용하도록 설계한 서비스에서 배포가 꺼져 있거나 원본 구성이 잘못되면 이러한 기능을 이용하지 못합니다. 모든 서비스에 CDN이 필요한 것은 아니며, CDN을 켜는 것만으로 원본 직접 접근이 차단되지는 않습니다.
잠재적 영향
- 캐시와 전송 최적화를 활용하지 못해 응답 속도나 원본 부하가 나빠질 수 있습니다.
- 사용자가 원본에 직접 접근하면 CloudFront에 적용한 접근 통제나 보안 정책을 우회할 수 있습니다.
해결 방법
- CDN이 필요한 서비스에서는
origins와default_cache_behavior를 구성하고enabled: true로 활성화하세요. DNS와 실제 서비스 경로도 확인하세요. - 원본 직접 접근 제한, 클라이언트·원본 구간의 HTTPS, 인증과 필요한 엣지 보안 정책을 별도로 구성하세요. 캐시가 사용자별 비공개 응답을 공유하지 않는지 확인하고 로그 전달을 시험하세요.
예시
실제 원본, 로그 버킷과 접근 권한을 준비해야 하는 발췌입니다. 변경 전에는 필수 원본이 없어 신규 배포 생성 예제로 완전하지 않습니다.
변경 전
yaml
- name: CloudFront 배포 생성
community.aws.cloudfront_distribution:
state: present
caller_reference: unique test distribution ID
default_cache_behavior:
target_origin_id: "my test origin-000111"
forwarded_values:
query_string: true
cookies:
forward: all
headers:
- "*"
viewer_protocol_policy: allow-all
smooth_streaming: true
compress: true
allowed_methods:
items:
- GET
- HEAD
cached_methods:
- GET
- HEAD
enabled: false
logging:
enabled: true
include_cookies: false
bucket: mylogbucket.s3.amazonaws.com
prefix: myprefix/
원본 정의가 없고 배포도 비활성화되어 있어 의도한 콘텐츠를 제공할 수 없습니다.
변경 후
yaml
- name: CloudFront 배포 생성
community.aws.cloudfront_distribution:
state: present
caller_reference: unique test distribution ID
origins:
- id: "my test origin-000111"
domain_name: www.example.com
origin_path: /production
custom_origin_config:
http_port: 80
https_port: 443
origin_protocol_policy: https-only
origin_ssl_protocols:
- TLSv1.2
default_cache_behavior:
target_origin_id: "my test origin-000111"
forwarded_values:
query_string: true
cookies:
forward: all
headers:
- "*"
viewer_protocol_policy: allow-all
compress: true
allowed_methods:
items:
- GET
- HEAD
cached_methods:
- GET
- HEAD
logging:
enabled: true
include_cookies: false
bucket: mylogbucket.s3.amazonaws.com
prefix: myprefix/
enabled: true
HTTPS를 지원하는 사용자 지정 원본을 연결하고 배포를 켭니다. viewer_protocol_policy: allow-all은 클라이언트의 HTTP도 허용하므로 이 예시가 전체 경로의 HTTPS를 강제하지는 않습니다.