Aws Cloudfront Cdn

by aj-geddes3f5182cfd739No license355 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 7 months ago

Distribute content globally using CloudFront with caching, security headers, WAF integration, and origin configuration. Use for low-latency content delivery.

Includes scriptsDevOps & Cloud
AI-generated overview

Configure AWS CloudFront CDN distributions with caching, security headers, WAF and origin settings.

What it does
Provides guidance and reference material for creating and configuring Amazon CloudFront distributions, covering caching behavior, security headers, WAF integration and origin setup. It includes AWS CLI and Terraform configuration references, a starter YAML template and a validation script for checking configuration. The deliverable is working CloudFront distribution configuration.
When to use it
Use when setting up or tuning a CloudFront CDN for static sites, APIs, media streaming, large downloads or DDoS protection. Also useful when writing CloudFront infrastructure as code with Terraform or the AWS CLI.
Requirements
AWS account and credentials with CloudFront permissions, the AWS CLI, and Terraform for the Terraform reference. Ships an executable validation script and a YAML config template.

AWS CloudFront CDN

Table of Contents

Overview

Amazon CloudFront is a fast, globally distributed content delivery network (CDN). Cache content at edge locations worldwide to reduce latency, improve performance, and provide high availability with DDoS protection.

When to Use

  • Static website hosting and assets
  • API acceleration and dynamic content
  • Video and media streaming
  • Mobile application content
  • Large file downloads
  • Real-time data distribution
  • DDoS protection for origins
  • Origin isolation and security

Quick Start

Minimal working example:

bash
# Create distribution for S3 originaws cloudfront create-distribution \  --distribution-config '{    "CallerReference": "myapp-'$(date +%s)'",    "Enabled": true,    "Comment": "My application distribution",    "Origins": {      "Quantity": 1,      "Items": [{        "Id": "myS3Origin",        "DomainName": "mybucket.s3.us-east-1.amazonaws.com",        "S3OriginConfig": {          "OriginAccessIdentity": "origin-access-identity/cloudfront/ABCDEFG1234567"        }      }]    },    "DefaultCacheBehavior": {      "AllowedMethods": {        "Quantity": 3,        "Items": ["GET", "HEAD", "OPTIONS"]      },      "ViewerProtocolPolicy": "redirect-to-https",      "TargetOriginId": "myS3Origin",      "ForwardedValues": {        "QueryString": false,// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
CloudFront Distribution with AWS CLI [blocked]CloudFront Distribution with AWS CLI
Terraform CloudFront Configuration [blocked]Terraform CloudFront Configuration
Custom Headers and Security Configuration [blocked]Custom Headers and Security Configuration

Best Practices

✅ DO

  • Use Origin Access Identity (OAI) for S3
  • Enable HTTPS only for viewers
  • Compress content at CloudFront
  • Set appropriate cache TTLs
  • Use cache invalidation cautiously
  • Enable WAF for protection
  • Monitor CloudWatch metrics
  • Use multiple origins for redundancy

❌ DON'T

  • Make S3 buckets public
  • Cache sensitive data
  • Use HTTP for production
  • Ignore cache headers
  • Create excessive invalidations
  • Skip WAF protection

Source and attribution

Source:aj-geddes/useful-ai-promptsinskills/aws-cloudfront-cdnat commit3f5182c

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal