You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CloudFront分发在多区域架构中是否需要部署副本?

CloudFront多区域故障转移配置指南

核心结论

  • CloudFront是全局分布式服务,完全不需要部署多个分发副本。它的边缘节点遍布全球,核心控制平面本身采用多区域冗余架构,单个分发就能自动应对区域级故障。
  • 你真正需要做的是给CloudFront配置多源故障转移组,把主、备区域的S3存储桶关联起来,让CloudFront在主S3区域故障时自动切换到备桶。

基于你的CloudFormation模板的修改方案

1. 新增备区域S3源

在Origins列表中加入备区域的S3存储桶配置,注意使用对应区域的RegionalDomainName,并复用同一个CloudFront源访问身份(OAI):

2. 创建故障转移源组

在DistributionConfig中添加OriginGroups配置,指定主、备源的ID,以及触发故障转移的HTTP状态码(比如5xx系列错误):

3. 调整缓存行为指向源组

把DefaultCacheBehavior中的TargetOriginId从单个源ID改为故障转移组的ID。

修改后的完整模板片段如下:

IVRSpeechContentCFDistro:
    Type: AWS::CloudFront::Distribution
    Properties:
      DistributionConfig:
        Aliases:
          - !FindInMap [ EnvMappings, !Ref StageName, domain ]
        HttpVersion: http2
        ViewerCertificate:
          AcmCertificateArn: !FindInMap [ EnvMappings, !Ref StageName, ssl ]
          MinimumProtocolVersion: TLSv1.2_2021
          SslSupportMethod: sni-only
        Enabled: True
        DefaultCacheBehavior:
          CachePolicyId: xxxxxx
          AllowedMethods:
            - GET
            - HEAD
            - OPTIONS
          # 切换为故障转移组ID
          TargetOriginId: "S3-Failover-Group"
          ViewerProtocolPolicy: https-only
        # 新增故障转移源组配置
        OriginGroups:
          Quantity: 1
          Items:
            - Id: "S3-Failover-Group"
              FailoverCriteria:
                StatusCodes:
                  Items: [500, 502, 503, 504]
                  Quantity: 4
              Members:
                Quantity: 2
                Items:
                  - OriginId: !Sub "xxxxxxx" # 原主S3源ID
                  - OriginId: !Sub "xxxxxxx-secondary" # 新增备S3源ID
        Origins:
          # 原主S3源配置保留
          - Id: !Sub "xxxxxxx"
            DomainName: !GetAtt bucket.RegionalDomainName
            S3OriginConfig:
              OriginAccessIdentity: !Sub
                - "origin-access-identity/cloudfront/${ID}"
                - { ID: !Ref identity }
          # 新增备区域S3源
          - Id: !Sub "xxxxxxx-secondary"
            DomainName: !GetAtt bucketSecondary.RegionalDomainName
            S3OriginConfig:
              OriginAccessIdentity: !Sub
                - "origin-access-identity/cloudfront/${ID}"
                - { ID: !Ref identity }

额外注意事项

  • 备S3桶的内容要和主桶保持同步,建议开启S3跨区域复制(CRR)
  • CloudFront要求ACM证书必须部署在us-east-1区域,或者直接使用CloudFront提供的免费证书
  • 确保你用的CloudFront源访问身份(OAI)对两个S3桶都有读取权限

内容的提问来源于stack exchange,提问作者elena

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.24 16:54:52