You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为EC2实例配置CloudFront类CloudFlare CDN后无法访问,求排查

Troubleshooting Your CloudFront Distribution Setup

Let’s walk through the most likely issues that could be preventing your CloudFront distribution from serving your site, even after completing those initial steps:

1. Verify Your Origin Configuration

  • Double-check the Origin Domain Name: Ensure it's exactly secret.example.com and that CloudFront can resolve this domain. If your origin is an EC2 instance, make sure its security group allows inbound HTTP/HTTPS traffic from all IPs (CloudFront uses a large range of global IPs, so restricting to specific ranges can be tricky—test with 0.0.0.0/0 first to rule out firewall blocks).
  • Confirm the Origin Protocol Policy: If secret.example.com uses HTTPS, select "HTTPS Only" or "Match Viewer". If it's HTTP-only, choose "HTTP Only". Mismatched protocols will cause CloudFront to fail fetching content from your origin.
  • Leave Origin Path blank unless your site is hosted in a subdirectory (like /app) on your origin. A filled-in path when unnecessary will lead to 404 errors.

2. Check Cache Behavior & Viewer Settings

  • Viewer Protocol Policy: For modern sites, use "Redirect HTTP to HTTPS" or "HTTPS Only". If you force HTTP but try accessing CloudFront via HTTPS, you’ll get errors.
  • Allowed HTTP Methods: Ensure at least GET and HEAD are enabled (these are required for static content). If your site uses POST/PUT, add those too, but start with the basics for testing.
  • Cache Policy: Try using the default CachingOptimized policy first. Custom policies might accidentally cache error responses (like 404s) or override necessary settings.

3. Validate SSL Certificate & CNAME Setup

  • When adding www.example.com as a CNAME, you must attach a valid SSL certificate from AWS Certificate Manager (ACM). Critical note: this certificate must be issued in the us-east-1 (N. Virginia) region, regardless of where your origin or CloudFront distribution is hosted.
  • Make sure the certificate includes www.example.com and has been successfully validated (via DNS or email). Even if the CloudFront default domain works, a missing/invalid certificate will break your custom CNAME.

4. Wait for CloudFront Deployment

  • CloudFront takes 5-15 minutes to propagate configuration changes to all edge locations. Check the distribution’s status in the AWS Console—if it says "In Progress", you’ll need to wait until it switches to "Deployed" before testing. Early access will return inconsistent results.

5. Rule Out DNS & Local Caching Issues

  • Use nslookup www.example.com or dig www.example.com to confirm your DNS record is pointing to the CloudFront distribution domain. If it’s still resolving to an old IP, wait for DNS propagation (TTL settings can delay this—check your domain registrar’s TTL value).
  • Test in an incognito/private browser window to bypass local DNS and browser caching, which might be holding onto old records.

6. Check Origin Host Header Handling

  • Many web servers (Nginx, Apache) use the Host header to route requests. By default, CloudFront sends the origin’s domain (secret.example.com) as the Host header. If your origin’s web server is configured to only respond to a different Host value (e.g., www.example.com), this will cause errors.
  • To fix this, create a custom Origin Request Policy that sets the Host header to match your origin’s expected value, or update your web server config to accept secret.example.com as a valid Host.

7. Diagnose with Error Codes & CloudWatch

  • Look at the HTTP status code returned when accessing the CloudFront domain directly:
    • 502 Bad Gateway: CloudFront can’t connect to your origin—check security groups, origin uptime, and domain resolution.
    • 503 Service Unavailable: Your origin is refusing connections or overloaded.
    • 403 Forbidden: Permission issue (e.g., web server blocking CloudFront’s IPs, or incorrect origin access settings).
    • 404 Not Found: CloudFront is reaching your origin but the requested content doesn’t exist—check Origin Path and web server file paths.
  • You can also use CloudWatch metrics for your distribution to track error rates and narrow down the problem.

Quick Test Step

First, try accessing the raw CloudFront distribution domain (e.g., d1234567890abc.cloudfront.net) directly in your browser. If this fails, the issue is with the CloudFront-origin connection, not the CNAME/DNS. Use the error code from this test to prioritize the troubleshooting steps above.


内容的提问来源于stack exchange,提问作者Süha Boncukçu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:38:43