CloudFront搭配Lambda@Edge触发器未触发问题求助
Let's break down the possible issues and fixes for your scenario where the Lambda@Edge trigger isn't activating as expected, and you're seeing a 403 error in CloudFront logs:
1. Verify CloudFront Behavior-Lambda Association
First, confirm the Lambda trigger is properly linked to your CloudFront distribution's behavior:
- Navigate to the CloudFront console, select your distribution (
F4CC9XIJS6USAF), and go to the Behaviors tab. - Locate the behavior with path pattern
/images/*—check that under Lambda Function Associations, the Viewer Request event type is mapped to your Lambda function's ARN. - Ensure the path pattern is exact (no typos, case sensitivity matters;
/Images/*won't match/images/*).
2. Confirm Lambda@Edge Deployment Region
Lambda@Edge requires the parent function to be deployed in the us-east-1 region (CloudFront replicates it to edge locations globally):
- If you specified a custom region via the
--regionflag when runningserverless deploy, this will break the Lambda@Edge setup. Re-deploy the function tous-east-1if needed. - Verify the function exists in the Lambda console's
us-east-1region with the correct code.
3. Investigate the 403 Error Root Cause
Your log shows the request URI was rewritten to .webp (e.g., /images/menu/majorGroup/led_troffer_t34.png became .webp), which means the Lambda did execute—the 403 is coming from the origin or CloudFront itself:
- If your origin is S3: Ensure the corresponding
.webpfile exists in the bucket, and the CloudFront origin access identity (OAI) has permission to read it. - If your origin is a web server: Confirm the server can serve
.webpfiles for the rewritten path, and there are no access restrictions (like auth rules) blocking the request. - Check for WAF rules attached to your CloudFront distribution that might be blocking the
.webprequest.
4. Validate Lambda Dependencies and Execution Logs
Missing dependencies or runtime errors could cause silent failures even if the function is deployed:
- Your function uses the
useragentnpm package—make sure this dependency was included in the deployment package. Serverless should bundle it by default, but if you usedserverless-offline, double-check thatnode_moduleswas included in the deployment zip. - Check Lambda execution logs: Go to the Lambda console (us-east-1 region), select your function, and look at the Monitor tab's logs. If the function ran but threw an error (e.g., missing
useragentmodule, invalid header manipulation), it will show up here.
5. Ensure CloudFront Configuration Has Deployed
CloudFront takes 5-15 minutes to propagate configuration changes to edge locations. If you just added the trigger, wait for the distribution's status to change from In Progress to Deployed before testing again.
内容的提问来源于stack exchange,提问作者rp346

