irongit
readfasterlabs-infra/cloudfront.tf
100 lines2.7 KB
1resource "aws_cloudfront_origin_access_control" "default" {
2 name = "default-oac"
3 origin_access_control_origin_type = "s3"
4 signing_behavior = "always"
5 signing_protocol = "sigv4"
6}
7
8resource "aws_cloudfront_distribution" "cdn" {
9 origin {
10 domain_name = aws_s3_bucket_website_configuration.frontend.website_endpoint
11 # origin_access_control_id = aws_cloudfront_origin_access_control.default.id
12 origin_id = local.s3_origin_id
13 custom_origin_config {
14 http_port = 80
15 https_port = 443
16 origin_protocol_policy = "http-only"
17 origin_ssl_protocols = ["TLSv1.2"]
18 }
19 }
20
21 origin {
22 domain_name = replace(aws_apigatewayv2_api.http_api.api_endpoint, "https://", "")
23 origin_id = "api-origin"
24
25 custom_origin_config {
26 origin_protocol_policy = "https-only"
27 http_port = 80
28 https_port = 443
29 origin_ssl_protocols = ["TLSv1.2"]
30 }
31 }
32
33 enabled = true
34 is_ipv6_enabled = true
35 comment = "ReadFasterLabs CDN"
36 default_root_object = "index.html"
37 aliases = ["readfasterlabs.com", "www.readfasterlabs.com"]
38
39 default_cache_behavior {
40 allowed_methods = ["DELETE", "GET", "HEAD", "OPTIONS", "PATCH", "POST", "PUT"]
41 cached_methods = ["GET", "HEAD"]
42 target_origin_id = local.s3_origin_id
43 viewer_protocol_policy = "redirect-to-https"
44
45 forwarded_values {
46 query_string = true
47 headers = ["Authorization"]
48
49 cookies {
50 forward = "none"
51 }
52 }
53
54 min_ttl = 0
55 default_ttl = 3600
56 max_ttl = 86400
57 }
58
59 # Cache behavior with precedence 0
60 ordered_cache_behavior {
61 path_pattern = "/api/*"
62 allowed_methods = ["GET", "HEAD", "OPTIONS", "POST", "PUT", "PATCH", "DELETE"]
63 cached_methods = ["GET", "HEAD"]
64 target_origin_id = "api-origin"
65
66 forwarded_values {
67 query_string = true
68 headers=["Authorization"]
69
70 cookies {
71 forward = "none"
72 }
73 }
74
75 min_ttl = 0
76 default_ttl = 3600
77 max_ttl = 86400
78 compress = true
79 viewer_protocol_policy = "redirect-to-https"
80 }
81
82 price_class = "PriceClass_200"
83
84 restrictions {
85 geo_restriction {
86 restriction_type = "whitelist"
87 locations = ["US", "CA", "GB", "DE"]
88 }
89 }
90
91 tags = {
92 Environment = "production"
93 }
94
95 viewer_certificate {
96 acm_certificate_arn = "arn:aws:acm:us-east-1:036487096349:certificate/dc4f8dcc-9809-4d6d-8258-362cf5e19244"
97 ssl_support_method = "sni-only"
98 minimum_protocol_version = "TLSv1.2_2021"
99 }
100}