Skip to main content

CDK Constructs for AWS Cloudfront to AWS S3 integration.

Project description

aws-cloudfront-s3 module

---

Stability: Stable


Reference Documentation: https://docs.aws.amazon.com/solutions/latest/constructs/
Language Package
Python Logo Python aws_solutions_constructs.aws_cloudfront_s3
Typescript Logo Typescript @aws-solutions-constructs/aws-cloudfront-s3
Java Logo Java software.amazon.awsconstructs.services.cloudfronts3

This AWS Solutions Construct implements an AWS CloudFront fronting an AWS S3 Bucket.

Here is a minimal deployable pattern definition in Typescript:

# Example automatically generated from non-compiling source. May contain errors.
from aws_solutions_constructs.aws_cloudfront_s3 import CloudFrontToS3

CloudFrontToS3(self, "test-cloudfront-s3")

Initializer

new CloudFrontToS3(scope: Construct, id: string, props: CloudFrontToS3Props);

Parameters

Pattern Construct Props

Name Type Description
existingBucketObj? s3.IBucket Existing instance of S3 Bucket object or interface. If this is provided, then also providing bucketProps will cause an error.
bucketProps? s3.BucketProps Optional user provided props to override the default props for the S3 Bucket.
cloudFrontDistributionProps? cloudfront.DistributionProps Optional user provided props to override the default props for CloudFront Distribution
insertHttpSecurityHeaders? boolean Optional user provided props to turn on/off the automatic injection of best practice HTTP security headers in all responses from CloudFront
originPath? string Optional user provided props to provide anoriginPath that CloudFront appends to the origin domain name when CloudFront requests content from the origin. The string should start with a /, for example: /production. Default value is '/'
loggingBucketProps? s3.BucketProps Optional user provided props to override the default props for the S3 Logging Bucket.
cloudFrontLoggingBucketProps? s3.BucketProps Optional user provided props to override the default props for the CloudFront Logging Bucket.
logS3AccessLogs? boolean Whether to turn on Access Logging for the S3 bucket. Creates an S3 bucket with associated storage costs for the logs. Enabling Access Logging is a best practice. default - true

Pattern Properties

Name Type Description
cloudFrontWebDistribution cloudfront.CloudFrontWebDistribution Returns an instance of cloudfront.CloudFrontWebDistribution created by the construct
cloudFrontFunction? cloudfront.Function Returns an instance of the Cloudfront function created by the pattern.
cloudFrontLoggingBucket s3.Bucket Returns an instance of the logging bucket for CloudFront WebDistribution.
s3BucketInterface s3.IBucket Returns an instance of s3.IBucket created by the construct
s3Bucket? s3.Bucket Returns an instance of s3.Bucket created by the construct. IMPORTANT: If existingBucketObj was provided in Pattern Construct Props, this property will be undefined
s3LoggingBucket? s3.Bucket Returns an instance of s3.Bucket created by the construct as the logging bucket for the primary bucket.

Default settings

Out of the box implementation of the Construct without any override will set the following defaults:

Amazon CloudFront

  • Configure Access logging for CloudFront WebDistribution
  • Enable automatic injection of best practice HTTP security headers in all responses from CloudFront WebDistribution
  • CloudFront originPath set to '/'

Amazon S3 Bucket

  • Configure Access logging for S3 Bucket
  • Enable server-side encryption for S3 Bucket using AWS managed KMS Key
  • Enforce encryption of data in transit
  • Turn on the versioning for S3 Bucket
  • Don't allow public access for S3 Bucket
  • Retain the S3 Bucket when deleting the CloudFormation stack
  • Applies Lifecycle rule to move noncurrent object versions to Glacier storage after 90 days

Architecture

Architecture Diagram


© Copyright 2021 Amazon.com, Inc. or its affiliates. All Rights Reserved.

Project details


Release history Release notifications | RSS feed

This version

2.0.0

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

File details

Details for the file aws-solutions-constructs.aws-cloudfront-s3-2.0.0.tar.gz.

File metadata

  • Download URL: aws-solutions-constructs.aws-cloudfront-s3-2.0.0.tar.gz
  • Upload date:
  • Size: 147.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.7.0 importlib_metadata/4.8.2 pkginfo/1.8.2 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.6.5

File hashes

Hashes for aws-solutions-constructs.aws-cloudfront-s3-2.0.0.tar.gz
Algorithm Hash digest
SHA256 6437d14f17cc2d3a890a79ff98d2b0eb6d25c02d5d7fa6cdb7b297171d9523f7
MD5 15144fc4922c433bc1e973d1b3c522ae
BLAKE2b-256 067838f376b080d7d31a72e4f6ab972b3f05f59db226b0c9afb5cef4f43bef3b

See more details on using hashes here.

File details

Details for the file aws_solutions_constructs.aws_cloudfront_s3-2.0.0-py3-none-any.whl.

File metadata

File hashes

Hashes for aws_solutions_constructs.aws_cloudfront_s3-2.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 609a7ca3548d167cb1fe998d5cefbe4bc2018c01f1961f77c4c7bd9393c5c5c1
MD5 23138195b606f9ad01836127d35694ed
BLAKE2b-256 75441679ffd46a5fb5804d46557598b0bc4edbfbfe3ec9ad1f4d3e1104d2c45e

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page