94065a4fbc
Each module README (10 primitives + 2 patterns) now has a ## Examples section before ## Versioning, referencing and excerpting the validated simple.yaml + complex.yaml (+ mysql.yaml for RDS) example contracts. The RDS README includes a Multi-engine variation subsection (D-059). ---ci--- project: acdl phase: 27 milestone: v1.7 status: execute ---/ci---
118 lines
4.0 KiB
Markdown
118 lines
4.0 KiB
Markdown
# cloudfront — CloudFront distribution
|
|
|
|
> **Module kind:** primitive | **Version:** 1.0.0
|
|
|
|
A CloudFront distribution with an S3 origin via Origin Access Control
|
|
(OAC). The distribution serves the bucket's static content from the
|
|
global edge network with HTTPS redirection by default. An optional WAF
|
|
web ACL can be associated to filter traffic before it reaches the
|
|
origin.
|
|
|
|
## Resources
|
|
|
|
| Resource | Type | Purpose |
|
|
|----------|------|---------|
|
|
| `oac` | `aws_cloudfront_origin_access_control` | Origin Access Control signing the S3 origin |
|
|
| `distribution` | `aws_cloudfront_distribution` | The CloudFront distribution with an S3 origin via OAC |
|
|
|
|
## Inputs
|
|
|
|
| Name | Type | Required | Default | Description |
|
|
|------|------|----------|---------|-------------|
|
|
| `bucket_regional_domain_name` | string | yes | — | The S3 bucket regional domain name (ref to s3 origin) |
|
|
| `price_class` | string | no | `PriceClass_100` | CloudFront price class |
|
|
| `viewer_protocol_policy` | string | no | `redirect-to-https` | Viewer protocol policy |
|
|
| `default_ttl` | number | no | 3600 | Default TTL in seconds |
|
|
| `max_ttl` | number | no | 86400 | Max TTL in seconds |
|
|
| `waf_web_acl_arn` | string | no | — | WAF web ACL ARN to associate (ref to waf) |
|
|
| `region` | string | yes | — | AWS region (CloudFront is global but the provider region is used for the OAC) |
|
|
|
|
## Outputs
|
|
|
|
| Name | Type | Description |
|
|
|------|------|-------------|
|
|
| `distribution_arn` | arn | The CloudFront distribution ARN |
|
|
| `distribution_domain_name` | string | The CloudFront distribution domain name (e.g. d111111abcdef8.cloudfront.net) |
|
|
| `oac_id` | string | The Origin Access Control ID |
|
|
|
|
## Usage
|
|
|
|
```json
|
|
{
|
|
"id": "cloudfront",
|
|
"type": "aws:cloudfront:distribution",
|
|
"module": "cloudfront@1.0.0",
|
|
"inputs": {
|
|
"bucket_regional_domain_name": "ref:s3.bucket_regional_domain_name",
|
|
"price_class": "PriceClass_100",
|
|
"viewer_protocol_policy": "redirect-to-https",
|
|
"default_ttl": 3600,
|
|
"max_ttl": 86400,
|
|
"waf_web_acl_arn": "ref:waf.web_acl_arn",
|
|
"region": "us-east-1"
|
|
}
|
|
}
|
|
```
|
|
|
|
The `bucket_regional_domain_name` and `waf_web_acl_arn` inputs are
|
|
typically wired as `ref:` expressions from the `s3` and `waf` primitives
|
|
inside a module composition (see `modules/l2/static-assets`).
|
|
|
|
## Compliance extension points
|
|
|
|
- **TLS/HTTPS** — viewer protocol policy defaults to `redirect-to-https`;
|
|
a custom ACM certificate + `viewer_certificate` block can pin TLS to a
|
|
customer domain (SOC2 CC6.1, GDPR Art.32).
|
|
- **Geo restriction** — the `restrictions.geo_restriction` block can
|
|
whitelist/blacklist countries for data-residency compliance (GDPR
|
|
Art.44, SOC2 CC6.1).
|
|
- **Logging** — CloudFront access logs to an S3 bucket for auditability
|
|
(SOC2 CC7.2, DORA audit trail).
|
|
- **Field-level encryption** — add field-level encryption for PII fields
|
|
in POST bodies (HIPAA §164.312(a)(2)(iv), GDPR Art.32).
|
|
|
|
## Examples
|
|
|
|
Validated example contracts are in [`examples/`](examples/). The platform-test
|
|
pipeline validates them against `schemas/contract.schema.json`.
|
|
|
|
### Simple
|
|
|
|
A minimal deployment:
|
|
|
|
[`examples/simple.yaml`](examples/simple.yaml)
|
|
```yaml
|
|
# Simple CloudFront distribution (S3 origin, no WAF)
|
|
uses: acdl/pipelines/deploy.yaml@v1.6
|
|
module: cloudfront
|
|
environment: dev
|
|
inputs:
|
|
bucket_regional_domain_name: my-bucket.s3.us-east-1.amazonaws.com
|
|
region: us-east-1
|
|
```
|
|
|
|
### Complex
|
|
|
|
A production deployment with optional inputs:
|
|
|
|
[`examples/complex.yaml`](examples/complex.yaml)
|
|
```yaml
|
|
# Complex CloudFront with WAF + custom TTL + viewer protocol redirect
|
|
uses: acdl/pipelines/deploy.yaml@v1.6
|
|
module: cloudfront
|
|
environment: dev
|
|
inputs:
|
|
bucket_regional_domain_name: my-bucket.s3.us-east-1.amazonaws.com
|
|
price_class: PriceClass_100
|
|
viewer_protocol_policy: redirect-to-https
|
|
default_ttl: 3600
|
|
max_ttl: 86400
|
|
waf_web_acl_arn: arn:aws:wafv2:us-east-1:000000000000:webacl/my-waf
|
|
region: us-east-1
|
|
```
|
|
|
|
## Versioning
|
|
|
|
`1.0.0` — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
|
|
require a new registry entry (immutable publication); old entries enter
|
|
a 12-month deprecation window. |