Cloudfront

aws/agent-toolkit-for-aws/skills/specialized-skills/networking-and-content-delivery-skills/cloudfront

作者 aws188af2f810ce無授權條款2.8K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Configures Amazon CloudFront content delivery across six workflows: when to use CloudFront and how it fits with AWS WAF, Shield, CloudFront Functions, Lambda@Edge, Route 53, and origins (creating a distribution, caching, and Flat Rate Pricing (FRP) versus pay-as-you-go pricing); managing custom-domain TLS certificates (ACM in us-east-1); configuring multi-tenant distributions; protecting origins with origin access control (OAC), VPC origins, and origin mutual TLS (mTLS); securing content with signed URLs and cookies, geographic restrictions, viewer mutual TLS, and edge token validation; and observing traffic with standard and real-time logs. Applicable when the customer wants to put CloudFront in front of content, choose pricing, lock an origin, restrict who can view content, or analyze logs. Not applicable for the Route 53 DNS side of a CloudFront custom domain or failover between distributions (see the route53-cloudfront skill), or for pure-Route 53 DNS work (see the route53 skill).

AI 產生的概覽

將 Amazon CloudFront 設定工作路由到涵蓋發佈、憑證、來源、內容安全與日誌的參考程序。

功能
此技能扮演 Amazon CloudFront 內容傳遞設定工作的路由器。它會把客戶目標對應到六個參考檔案之一,每個檔案都自成一體,包含決策表、限制、程序與疑難排解。涵蓋範圍包括何時使用 CloudFront 與定價、自訂網域 TLS 憑證、多租戶發佈、來源保護、內容安全以及流量可觀測性。它產出的是設定指引與步驟,而不是檔案或程式碼。
適用情境
適用於將 CloudFront 放在內容前面、在固定費率定價與依用量計費之間選擇、鎖定來源、限制可檢視內容的使用者,或分析 CloudFront 日誌的情境。不適用於自訂網域的 Route 53 DNS 部分或發佈之間的容錯移轉,這些屬於個別的 Route 53 技能。
執行需求
需要存取 CloudFront 與 AWS Certificate Manager 的 AWS 權限,最好透過已連線的 AWS MCP 伺服器,並以 AWS CLI 作為備援。CloudFront API 呼叫與 ACM 憑證均在 us-east-1 處理。不附帶指令碼,僅為說明與參考文件。

Amazon CloudFront

Overview

Domain expertise for configuring Amazon CloudFront content delivery: deciding when to use CloudFront and how it fits the wider architecture, managing custom-domain certificates and multi-tenant distributions, protecting origins, securing content, and observing traffic.

This skill is a router. Each customer task maps to a procedure file under references/. Read the matching reference in full before acting, then follow its constraints and steps. The reference files are self-contained: each carries its own decision tables, constraints, procedure, and troubleshooting.

Execute commands using the AWS MCP server when connected (sandboxed execution, audit logging, observability). Fall back to the AWS CLI otherwise. CloudFront is a global service; its API calls and the AWS Certificate Manager (ACM) certificates it uses are made in us-east-1 regardless of where the customer's application runs.

Which CloudFront task do you need?

GoalReference
Decide whether CloudFront is the right layer, see how it integrates, create a distribution, tune caching, or choose pricingwhen to use CloudFront [blocked]
Serve a custom domain over HTTPS, manage ACM certificates, or run many domains with a certificate per tenantmanaging certificates with CloudFront [blocked]
Make CloudFront the only way to reach the origin (S3 OAC, VPC origins, origin mutual TLS, security groups)protecting your origins [blocked]
Limit who can view content by identity, location, client certificate, or auth tokensecuring your content [blocked]
Get visibility into traffic with standard and real-time logs, and analyze themCloudFront observability [blocked]
Serve multiple domains through shared configuration with per-tenant customization (SaaS, platform)multi-tenant distributions [blocked]

Routing notes

  • Choosing the layer and creating a distribution vs the rest. Whether CloudFront is the right entry layer, what it integrates with, creating a distribution, caching, and pricing live in the when-to-use reference. The other references assume a distribution exists and configure one aspect of it.
  • Protecting origins vs securing content. Locking the origin so it is reachable only through CloudFront (OAC, VPC origins, origin mTLS) is the protecting-your-origins reference. Restricting which viewers can see content (signed URLs and cookies, geographic restrictions, viewer mTLS, edge token validation) is the securing-your-content reference. They are paired: a content control only holds when the origin is also locked.
  • Viewer mTLS vs origin mTLS. Authenticating the client to CloudFront (viewer mTLS) is content security. Authenticating CloudFront to the origin (origin mTLS) is origin protection. Different controls, different references.
  • Custom domain certificate vs Route 53 DNS cutover. Requesting and validating the ACM certificate and adding the alternate domain name is the managing-certificates reference here. Pointing the domain's DNS at the distribution, including the zone apex alias and any failover, is Route 53 work owned by the separate route53-cloudfront skill.

Cross-service work

Pointing a custom domain's DNS at a CloudFront distribution, or failing over between distributions with Route 53 records, is cross-service work owned by the separate route53-cloudfront skill. Use this skill for the CloudFront-side configuration only.

Additional Resources

來源與署名

來源:aws/agent-toolkit-for-aws位於skills/specialized-skills/networking-and-content-delivery-skills/cloudfront提交188af2f

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架