CloudFront 요청 로그 설정 점검

CloudFront 요청 로그를 수집해 장애와 비정상 트래픽을 분석하세요.

설명

CloudFront 요청 로그가 없으면 사용자 요청과 엣지 응답을 분석할 근거가 줄어듭니다. 필요한 요청 정보를 수집하도록 로깅을 구성하세요.

잠재적 영향

비정상 트래픽이나 캐시 문제의 원인을 찾는 데 시간이 더 걸릴 수 있습니다.

해결 방법

사용하는 로그 전달 방식에 맞게 저장 대상과 권한을 구성하세요. 기존 S3 표준 로그는 logging_config로 설정하며, 실제 로그 전달과 보존 기간을 확인하세요.

예시

예시는 기존 S3 표준 로그를 추가하는 배포 설정의 일부입니다. 캐시 동작과 인증서 등 나머지 필수 설정은 생략했습니다.

변경 전

hcl
resource "aws_cloudfront_distribution" "example" {
  origin {
    domain_name = aws_s3_bucket.b.bucket_regional_domain_name
    origin_id   = local.s3_origin_id

    s3_origin_config {
      origin_access_identity = "origin-access-identity/cloudfront/ABCDEFG1234567"
    }
  }

  enabled             = true
  is_ipv6_enabled     = true
  comment             = "Some comment"
  default_root_object = "index.html"
}

변경 후

hcl
resource "aws_cloudfront_distribution" "example" {
  origin {
    domain_name = aws_s3_bucket.b.bucket_regional_domain_name
    origin_id   = local.s3_origin_id

    s3_origin_config {
      origin_access_identity = "origin-access-identity/cloudfront/ABCDEFG1234567"
    }
  }

  enabled             = true
  is_ipv6_enabled     = true
  comment             = "Some comment"
  default_root_object = "index.html"

  logging_config {
    include_cookies = false
    bucket          = "mylogs.s3.amazonaws.com"
    prefix          = "myprefix"
  }
}

참조