Files
acdl/modules/l1/cloudfront/README.md
T
Jon Chery 2682719f24
acdl-ci / Lint (push) Successful in 7s
acdl-ci / Test (push) Successful in 26s
acdl-ci / Platform check-only (offline) (push) Successful in 8s
docs(P47): presentation slide updates + HIPAA removal from all docs
Presentation changes (both Marp decks + source markdown):
1. Title slide: deck title as H1 (slightly bigger), 'Agentic Cloud Delivery
   Platform' as H3 subtitle — cleaner title hierarchy
2. DX deck: removed Local Reproducibility slide (not beneficial for DX)
3. DX deck: Safe Promotion Path slide redesigned with side-by-side layout
   for Approaches A and B (HTML table, two columns)
4. DX deck: 'an agent' → 'an AI agent' (slide 2 + Citizen Developer slide)
5. DX deck: What a Developer Does — diagram floated to the right side
6. Header simplified to just the deck name (subtitle now on title slide)

HIPAA removal (25 files):
- Completely removed all HIPAA references from all markdown documentation,
  presentation source files, module READMEs, and rendered HTML
- Removed HIPAA from compliance milestone lists (GDPR, SOX, SOC2, DORA remain)
- Removed HIPAA section references (§164.xxx) from compliance annotations
- Cleaned up empty parentheses and broken commas left by removal
- Re-rendered both HTML decks from updated Marp source

---ci---
phase: 47
milestone: v1.9
status: complete
requirements:
  covered: []
  partial: []
---/ci---
2026-07-23 14:08:40 +00:00

118 lines
4.0 KiB
Markdown

# cloudfront — CloudFront distribution
> **Module kind:** primitive | **Version:** 1.0.0
A CloudFront distribution with an S3 origin via Origin Access Control
(OAC). The distribution serves the bucket's static content from the
global edge network with HTTPS redirection by default. An optional WAF
web ACL can be associated to filter traffic before it reaches the
origin.
## Resources
| Resource | Type | Purpose |
|----------|------|---------|
| `oac` | `aws_cloudfront_origin_access_control` | Origin Access Control signing the S3 origin |
| `distribution` | `aws_cloudfront_distribution` | The CloudFront distribution with an S3 origin via OAC |
## Inputs
| Name | Type | Required | Default | Description |
|------|------|----------|---------|-------------|
| `bucket_regional_domain_name` | string | yes | — | The S3 bucket regional domain name (ref to s3 origin) |
| `price_class` | string | no | `PriceClass_100` | CloudFront price class |
| `viewer_protocol_policy` | string | no | `redirect-to-https` | Viewer protocol policy |
| `default_ttl` | number | no | 3600 | Default TTL in seconds |
| `max_ttl` | number | no | 86400 | Max TTL in seconds |
| `waf_web_acl_arn` | string | no | — | WAF web ACL ARN to associate (ref to waf) |
| `region` | string | yes | — | AWS region (CloudFront is global but the provider region is used for the OAC) |
## Outputs
| Name | Type | Description |
|------|------|-------------|
| `distribution_arn` | arn | The CloudFront distribution ARN |
| `distribution_domain_name` | string | The CloudFront distribution domain name (e.g. d111111abcdef8.cloudfront.net) |
| `oac_id` | string | The Origin Access Control ID |
## Usage
```json
{
"id": "cloudfront",
"type": "aws:cloudfront:distribution",
"module": "cloudfront@1.0.0",
"inputs": {
"bucket_regional_domain_name": "ref:s3.bucket_regional_domain_name",
"price_class": "PriceClass_100",
"viewer_protocol_policy": "redirect-to-https",
"default_ttl": 3600,
"max_ttl": 86400,
"waf_web_acl_arn": "ref:waf.web_acl_arn",
"region": "us-east-1"
}
}
```
The `bucket_regional_domain_name` and `waf_web_acl_arn` inputs are
typically wired as `ref:` expressions from the `s3` and `waf` primitives
inside a module composition (see `modules/l2/static-assets`).
## Compliance extension points
- **TLS/HTTPS** — viewer protocol policy defaults to `redirect-to-https`;
a custom ACM certificate + `viewer_certificate` block can pin TLS to a
customer domain (SOC2 CC6.1, GDPR Art.32).
- **Geo restriction** — the `restrictions.geo_restriction` block can
whitelist/blacklist countries for data-residency compliance (GDPR
Art.44, SOC2 CC6.1).
- **Logging** — CloudFront access logs to an S3 bucket for auditability
(SOC2 CC7.2, DORA audit trail).
- **Field-level encryption** — add field-level encryption for PII fields
in POST bodies (GDPR Art.32).
## Examples
Validated example contracts are in [`examples/`](examples/). The platform-test
pipeline validates them against `schemas/contract.schema.json`.
### Simple
A minimal deployment:
[`examples/simple.yaml`](examples/simple.yaml)
```yaml
# Simple CloudFront distribution (S3 origin, no WAF)
uses: acdl/pipelines/deploy.yaml@v1.6
module: cloudfront
environment: dev
inputs:
bucket_regional_domain_name: my-bucket.s3.us-east-1.amazonaws.com
region: us-east-1
```
### Complex
A production deployment with optional inputs:
[`examples/complex.yaml`](examples/complex.yaml)
```yaml
# Complex CloudFront with WAF + custom TTL + viewer protocol redirect
uses: acdl/pipelines/deploy.yaml@v1.6
module: cloudfront
environment: dev
inputs:
bucket_regional_domain_name: my-bucket.s3.us-east-1.amazonaws.com
price_class: PriceClass_100
viewer_protocol_policy: redirect-to-https
default_ttl: 3600
max_ttl: 86400
waf_web_acl_arn: arn:aws:wafv2:us-east-1:000000000000:webacl/my-waf
region: us-east-1
```
## Versioning
`1.0.0` — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.