You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

借助CloudFront整合外部站点与子目录服务的问题求助

解决方案:单CloudFront分发整合Wix站点、API Gateway和S3静态站点

一、解决Wix站点重定向与默认根对象冲突问题

核心原因

Wix子页面会自动生成指向自身域名的重定向,且CloudFront全局默认根对象设置会覆盖Wix根路径的正常访问逻辑。

具体方案(推荐CloudFront Functions,轻量低成本)

  1. 创建CloudFront函数(Viewer Request阶段),编写路径改写逻辑:
function handler(event) {
    const request = event.request;
    const uri = request.uri;

    // 排除API和Docs路径,只处理Wix相关请求
    if (!uri.startsWith('/api') && !uri.startsWith('/docs')) {
        // 根路径直接转发,子路径添加Wix站点前缀
        if (uri === '/') {
            request.uri = '/website'; // 匹配Wix源的路径前缀
        } else {
            request.uri = `/website${uri}`;
        }
    }

    return request;
}
  1. 在CloudFront的默认行为(*)上关联这个函数(Viewer Request事件)
  2. 额外处理Wix重定向:再创建一个CloudFront函数(Viewer Response阶段),拦截3xx重定向响应,替换Wix域名:
function handler(event) {
    const response = event.response;
    const headers = response.headers;

    if (headers.location) {
        const originalLocation = headers.location.value;
        // 替换Wix域名到自定义子域名
        const newLocation = originalLocation.replace('https://username.wix.com/website', 'https://sub.example.com');
        headers.location.value = newLocation;
    }

    return response;
}
  1. 将该函数关联到默认行为的Viewer Response事件
  2. 删除CloudFront全局默认根对象,避免干扰Wix根路径访问

二、解决S3静态站点Access Denied问题

核心原因

CloudFront的/docs*行为转发请求时,会携带/docs前缀到S3,而S3桶内的静态文件路径可能不匹配;同时全局默认根对象对/docs路径不生效。

具体方案

  1. 调整路径转发逻辑:
    • 如果S3桶内的静态文件直接存放在根目录:创建CloudFront函数(Viewer Request阶段),对/docs*路径改写,去掉前缀:
      function handler(event) {
          const request = event.request;
          const uri = request.uri;
      
          if (uri.startsWith('/docs')) {
              // 去掉/docs前缀,比如/docs/index.html → /index.html
              request.uri = uri.replace(/^\/docs/, '');
              // 处理/docs/根路径,自动指向index.html
              if (request.uri === '/') {
                  request.uri = '/index.html';
              }
          }
      
          return request;
      }
      
    • 如果S3桶内的文件存放在docs前缀下:直接在CloudFront的S3源设置中,将源路径填写为/docs,无需路径改写
  2. 验证OAI权限:确保S3桶策略允许CloudFront OAI访问所有对象,示例桶策略:
    {
        "Version": "2008-10-17",
        "Id": "PolicyForCloudFrontPrivateContent",
        "Statement": [
            {
                "Sid": "1",
                "Effect": "Allow",
                "Principal": {
                    "AWS": "arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity YOUR_OAI_ID"
                },
                "Action": "s3:GetObject",
                "Resource": "arn:aws:s3:::YOUR_BUCKET_NAME/*"
            }
        ]
    }
    
  3. 配置自定义错误响应:在/docs*行为中,添加自定义错误响应,将403状态码重定向到/docs/index.html,避免目录访问时出现权限错误

三、最终CloudFront行为优先级确认

确保行为优先级按以下顺序设置:

  • 优先级0:/docs* → 关联S3源和对应的路径改写函数
  • 优先级1:/api* → 关联API Gateway源
  • 优先级2:* → 关联Wix源和两个路径/重定向处理函数

内容的提问来源于stack exchange,提问作者Svencken

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 03:45:38