配置CloudFront默认缓存行为时CDK报非法键错误,求解决方案
解决AWS CDK配置CloudFront DefaultCacheBehavior时的额外键错误
问题描述
尝试通过AWS CDK在CloudFormation栈中配置CloudFront的DefaultCacheBehaviorProperty,参考官方文档编写代码后,部署时CloudFormation提示所有配置的键(如minTtl、compress等)均为不允许的额外键。
代码示例
const defaultCacheBehaviour: CfnDistribution.DefaultCacheBehaviorProperty = { compress: true, viewerProtocolPolicy: "redirect-to-https", targetOriginId: "api-gw-origin", forwardedValues: { queryString: true }, lambdaFunctionAssociations: [ { eventType: LambdaEdgeEventType.VIEWER_REQUEST, lambdaFunctionArn: this.getLambdaEdgeArnString(CHECK_AUTH_LAMBDA_EDGE_ARN_PARAM_NAME) } ], defaultTtl: 0, minTtl: 0, maxTtl: 0 } cloudfrontDistribution.distribution.addPropertyOverride("DistributionConfig.DefaultCacheBehavior", defaultCacheBehaviour );
错误信息
Properties validation failed for resource CloudfrontDistributionECD with message: #/DistributionConfig/DefaultCacheBehavior: extraneous key [minTtl] is not permitted #/DistributionConfig/DefaultCacheBehavior: extraneous key [compress] is not permitted #/DistributionConfig/DefaultCacheBehavior: extraneous key [maxTtl] is not permitted #/DistributionConfig/DefaultCacheBehavior: extraneous key [viewerProtocolPolicy] is not permitted #/DistributionConfig/DefaultCacheBehavior: extraneous key [forwardedValues] is not permitted #/DistributionConfig/DefaultCacheBehavior: extraneous key [lambdaFunctionAssociations] is not permitted #/DistributionConfig/DefaultCacheBehavior: extraneous key [defaultTtl] is not permitted #/DistributionConfig/DefaultCacheBehavior: extraneous key [targetOriginId] is not permitted
问题原因
你使用了CDK TypeScript接口的小驼峰属性名(如defaultTtl),直接通过addPropertyOverride写入CloudFormation模板,但CloudFormation原生的CloudFront Distribution配置要求属性名为首字母大写的驼峰格式(如DefaultTTL),导致CloudFormation无法识别这些键,判定为额外键。
解决方法
方法一:使用CDK L2构造直接配置(推荐)
优先使用CDK的L2 Distribution构造配置默认缓存行为,CDK会自动处理属性名的格式转换,无需手动适配CloudFormation规则:
import * as cloudfront from 'aws-cdk-lib/aws-cloudfront'; import * as origins from 'aws-cdk-lib/aws-cloudfront-origins'; import * as cdk from 'aws-cdk-lib'; // 创建Distribution时直接配置默认行为 const distribution = new cloudfront.Distribution(this, 'CloudfrontDistributionECD', { defaultBehavior: { origin: new origins.HttpOrigin('your-origin-domain'), // 替换为你的实际源站域名 compress: true, viewerProtocolPolicy: cloudfront.ViewerProtocolPolicy.REDIRECT_TO_HTTPS, targetOriginId: 'api-gw-origin', forwardedValues: { queryString: true, }, lambdaFunctionAssociations: [{ lambdaFunction: cloudfront.experimental.EdgeFunction.fromEdgeFunctionArn( this, 'AuthLambdaEdge', this.getLambdaEdgeArnString(CHECK_AUTH_LAMBDA_EDGE_ARN_PARAM_NAME) ), eventType: cloudfront.LambdaEdgeEventType.VIEWER_REQUEST, }], cachePolicy: new cloudfront.CachePolicy(this, 'NoCachePolicy', { defaultTtl: cdk.Duration.seconds(0), minTtl: cdk.Duration.seconds(0), maxTtl: cdk.Duration.seconds(0), }), }, });
方法二:修改addPropertyOverride的属性格式
如果必须使用addPropertyOverride,需要将属性名改为CloudFormation原生的首字母大写驼峰格式,同时Lambda的事件类型要使用原生字符串值:
const defaultCacheBehaviour = { Compress: true, ViewerProtocolPolicy: "redirect-to-https", TargetOriginId: "api-gw-origin", ForwardedValues: { QueryString: true }, LambdaFunctionAssociations: [ { EventType: "viewer-request", // 使用CloudFormation原生事件类型字符串 LambdaFunctionARN: this.getLambdaEdgeArnString(CHECK_AUTH_LAMBDA_EDGE_ARN_PARAM_NAME) } ], DefaultTTL: 0, MinTTL: 0, MaxTTL: 0 } cloudfrontDistribution.distribution.addPropertyOverride( "DistributionConfig.DefaultCacheBehavior", defaultCacheBehaviour );
内容的提问来源于stack exchange,提问作者Debapratim Chakraborty
相关产品推荐
相关产品推荐

