AWS CDK如何配置带viewerCertificate的CloudFrontWebDistribution
解决方案
你要实现的替换逻辑完全可行,具体操作如下:
1. 导入依赖包(适配CDK v1版本)
import { Certificate } from '@aws-cdk/aws-certificatemanager'; import { ViewerCertificate, SecurityPolicyProtocol, SSLMethod } from '@aws-cdk/aws-cloudfront';
2. 引入已有的ACM证书资源
直接通过证书ARN导入现有资源,无需在CDK中新建证书:
const existingAcmCert = Certificate.fromCertificateArn(this, 'ImportedAcmCert', awsConfig.acm_arn);
3. 替换弃用的aliasConfiguration配置
删除原有aliasConfiguration字段,新增顶层aliases和viewerCertificate字段即可,完整修改后的代码如下:
this.distribution = new CloudFrontWebDistribution(this, `${this.props.applicationName}Distribution`, { originConfigs: [ { s3OriginSource: { s3BucketSource: this.dashboardBucket, originAccessIdentity: dashboardIdentity }, behaviors: [{ isDefaultBehavior: true }], }, ], // 原aliasConfiguration中的域名配置移到此处 aliases: [url], // 新增证书配置 viewerCertificate: ViewerCertificate.fromAcmCertificate(existingAcmCert, { sslMethod: SSLMethod.SNI, securityPolicy: SecurityPolicyProtocol.TLS_V1_2_2021, }), errorConfigurations: [ { errorCode: 403, responseCode: 200, responsePagePath: '/' }, { errorCode: 404, responseCode: 200, responsePagePath: '/index.html' } ] });
注意事项
- CloudFront仅支持调用托管在
us-east-1区域的ACM证书,若你的证书存放在其他区域需要先迁移到us-east-1才能正常使用 - 示例中使用的
TLS_V1_2_2021是当前官方推荐的TLS安全策略,你可根据业务需求替换为其他兼容的策略版本
内容的提问来源于stack exchange,提问作者Mattijs
相关产品推荐
相关产品推荐

