如何正确将Route 53指向CloudFront?现有S3与CloudFront已正常运行
Got it, let's break down exactly how to set up Route 53 to point to your working CloudFront distributions—since you've already confirmed both distros are accessible via their CNAMEs, most of the heavy lifting is already done. Here's the step-by-step process:
1. Double-Check CloudFront Prerequisites First
Before touching Route 53, make sure these critical CloudFront settings are locked in (you might have already done this, but it's worth verifying):
- Alternate Domain Names (CNAMEs): Each CloudFront distribution has the custom domain you want to use added to its CNAME list. For example, if you're pointing
www.mydomain.com.auto one distro, that domain must be listed in the distro's Alternate Domain Names. - SSL Certificate: You have a valid SSL certificate (from AWS Certificate Manager, preferably in the
us-east-1region, or an imported certificate) that covers all your custom domains. This ensures HTTPS works once Route 53 is pointing to CloudFront.
2. Create Route 53 Alias Records (The Right Way)
Route 53 Alias records are the best choice here—they're free, automatically track CloudFront's IP changes, and work with apex domains (like mydomain.com.au) where CNAMEs aren't allowed. Here's how to set them up:
- Open the Route 53 Console and navigate to your domain's hosted zone.
- Click Create record to start configuring:
- Record name: For your apex domain (
mydomain.com.au), leave this field blank. For a subdomain (e.g.,app.mydomain.com.au), enter just the subdomain part (app). - Record type: Choose either
A(for IPv4) orAAAA(for IPv6)—I recommend creating both for full compatibility. - Alias toggle: Turn on the "Alias" option.
- Alias to: Select CloudFront distribution from the dropdown, then pick the specific CloudFront distribution you want to point to from the list (you'll see the distro's unique domain like
d123xyz.cloudfront.netto confirm it's the right one). - TTL: Alias records don't require manual TTL settings—AWS handles this automatically, so leave it as is.
- Save the record, then repeat this process for your second CloudFront distribution (using its corresponding custom domain).
- Record name: For your apex domain (
3. Verify the Setup
Give it 1-5 minutes for Route 53's DNS changes to propagate (it can sometimes take longer, but usually not). Then:
- Visit your custom domain(s) in a browser to confirm they load the correct content via CloudFront.
- Use a tool like
digornslookupto check the DNS records:
You should see CloudFront's edge server IP addresses in the response.dig mydomain.com.au
Quick Notes to Avoid Headaches
- Don't use CNAMEs for apex domains: CNAME records override all other DNS records for that domain (like MX for email), so stick with Alias records for
mydomain.com.au. - Skip pointing directly to S3: Since you're using CloudFront, always route traffic through the distro—this ensures you get the benefits of caching, global CDN, and SSL termination.
- Confirm Default Root Object: Make sure each CloudFront distribution has a default root object set (e.g.,
index.html) so visiting the root domain doesn't throw a 403 error.
内容的提问来源于stack exchange,提问作者Michael Coxon

