如何配置仅允许Amazon CloudFront访问源站?
Alright, let's walk through how to lock down your origin so only CloudFront can access it—blocking any direct requests from users or other services. The steps vary a bit depending on what type of origin you're using, so I'll cover the two most common scenarios below.
Restricting Access for S3 Bucket Origins
If your origin is an S3 bucket, the cleanest way is to use Origin Access Control (OAC) (this replaces the older Origin Access Identity, so stick with OAC for modern setups):
Create an OAC and link it to your CloudFront distribution
- Head to the CloudFront console, open your distribution, and go to the "Origins" tab.
- Select your S3 origin, click "Edit".
- Under "Origin access", choose "Origin access control settings (recommended)".
- Click "Create control setting"—give it a descriptive name, leave the default options (sign requests, S3 bucket) and save.
Update your S3 bucket policy to allow only CloudFront via the OAC
Replace the placeholders (YOUR_BUCKET_NAME,YOUR_ACCOUNT_ID,YOUR_CLOUDFRONT_DIST_ID) in this policy and attach it to your S3 bucket:{ "Version": "2008-10-17", "Id": "PolicyForCloudFrontPrivateContent", "Statement": [ { "Sid": "AllowCloudFrontAccess", "Effect": "Allow", "Principal": { "Service": "cloudfront.amazonaws.com" }, "Action": "s3:GetObject", "Resource": "arn:aws:s3:::YOUR_BUCKET_NAME/*", "Condition": { "StringEquals": { "AWS:SourceArn": "arn:aws:cloudfront::YOUR_ACCOUNT_ID:distribution/YOUR_CLOUDFRONT_DIST_ID" } } } ] }Block public access to the S3 bucket
- Go to your S3 bucket's "Permissions" tab.
- Enable "Block all public access" and save. This ensures no direct public requests can reach the bucket, even if someone finds its URL.
Pro tip: If you were using S3 static website hosting, note that OAC doesn't work with that endpoint. You'll need to switch your CloudFront origin to use the S3 REST API endpoint (e.g., bucket-name.s3.amazonaws.com) instead.
Restricting Access for Custom Origins (EC2, Web Servers)
For custom origins like EC2 instances or your own web server, you'll need to combine IP whitelisting with request validation to prevent spoofing:
Whitelist CloudFront IP addresses
CloudFront publishes its IP ranges, but manually updating security groups/firewalls is a hassle. Instead, use AWS WAF to automate this:- Create a WAF web ACL, then add a rule that allows requests only from CloudFront's managed IP set.
- Associate this web ACL with your CloudFront distribution. This way, when CloudFront updates its IPs, your rules stay current automatically.
Validate custom request headers
To ensure requests are actually coming from CloudFront (not just someone using a CloudFront IP), add a secret custom header that your origin checks:- In CloudFront, edit your origin, scroll to "Origin custom headers", and add a header like
X-CloudFront-Verifywith a unique secret value (e.g.,MyUniqueSecret123!). - On your origin server, add a rule to block any requests that don't include this header with the correct value.
Example Nginx config snippet:
if ($http_x_cloudfront_verify != "MyUniqueSecret123!") { return 403; }Example Apache config snippet:
RewriteEngine On RewriteCond %{HTTP:X-CloudFront-Verify} !^MyUniqueSecret123!$ RewriteRule ^ - [F]- In CloudFront, edit your origin, scroll to "Origin custom headers", and add a header like
Final Checks
- Test direct access: Try visiting your origin's URL directly (e.g., S3 bucket URL or EC2 public IP) — you should get a
403 Forbiddenresponse. - Test CloudFront access: Visit your CloudFront distribution's domain to confirm content loads correctly.
- If you have multiple CloudFront distributions accessing the same origin, update your bucket policy or WAF rules to include all their ARNs/IP ranges.
内容的提问来源于stack exchange,提问作者Taz

