能否将AWS CloudFront关联S3桶并指定目录转发至EC2实例?
Can I Route CloudFront Traffic to S3 and Elastic Beanstalk/EC2 Based on Path?
Absolutely! This setup is totally feasible using CloudFront's Cache Behavior rules—let me break down exactly how to configure it for your use case:
Step 1: Prepare Your Origins
First, you'll need to add both your S3 bucket and Elastic Beanstalk (EB) environment as origins in your CloudFront distribution:
- Default Origin: Set this to your S3 static website bucket. Make sure to use CloudFront's Origin Access Control (OAC) instead of bucket policies for secure access—this prevents direct public access to S3, forcing all traffic through CloudFront.
- Second Origin: Add a new origin pointing to your EB environment's domain name (you can find this in the EB console under your environment's "Domain" section). For the origin type, select "Custom Origin" and enter the EB domain as the origin domain name.
Step 2: Configure Cache Behaviors
Cache behaviors let you route specific path patterns to different origins. Here's what to set up:
- Default Behavior (Path Pattern:
/*):- Assign this to your S3 origin.
- Set allowed HTTP methods to
GET, HEAD(since it's static content). - Choose a suitable cache policy (like the managed
CachingOptimizedpolicy) to leverage CloudFront's caching for your static assets.
- Custom Behavior for
/one_folder/*:- Click "Create Cache Behavior" and set the Path Pattern to
/one_folder/*. - Assign this to your EB origin.
- For HTTP methods, select
GET, HEAD, OPTIONS, PUT, POST, PATCH, DELETE(since PHP apps often need dynamic request methods). - Use the managed
CachingDisabledpolicy (or a custom policy with no caching) because dynamic PHP content shouldn't be cached. - Under "Cache Key and Origin Requests", make sure to forward any necessary headers, cookies, or query strings that your PHP app depends on (e.g.,
Cookie,Authorizationif your app uses authentication).
- Click "Create Cache Behavior" and set the Path Pattern to
Step 3: Critical Security & Access Checks
- S3 OAC Setup: Double-check that your S3 bucket's OAC is linked to your CloudFront distribution, and that the bucket policy restricts access to only CloudFront.
- EB Environment Access: Ensure your EB environment's security group allows incoming traffic from CloudFront's IP ranges. Alternatively, you can add a custom HTTP header (like
X-CloudFront-Access) in your CloudFront cache behavior, then configure a WAF rule or EB security group to only allow requests with that header—this adds an extra layer of security to prevent direct access to your EB instance. - SSL/TLS: If you're using a custom domain with CloudFront, make sure to attach an ACM certificate (from the us-east-1 region, even if your resources are elsewhere) to enable HTTPS for all traffic.
Final Result
Once everything is configured, CloudFront will automatically route:
- All requests to
http://<cloudfront_domain>/(and subpaths not under/one_folder/) to your S3 static bucket. - All requests to
http://<cloudfront_domain>/one_folder/(and its subpaths) to your Elastic Beanstalk/EC2 instance running PHP.
内容的提问来源于stack exchange,提问作者P. Johnson
相关产品推荐
相关产品推荐

