You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于CloudFront实现多域名SSL配置的问题咨询

Scaling Custom Domains on CloudFront: Fixing CNAME Limits & SSL Certificate Hassles

Nice question—this is a super common scaling headache when supporting custom domains at scale with CloudFront. Let’s walk through the most practical, scalable fixes for both your pain points:

1. Beat the 100-CNAME Limit: Use Wildcard CNAME + Host Header Routing

Instead of adding every user’s custom domain (like docs.theirsite.com) as a separate alternate CNAME on your CloudFront distribution, shift to a smarter routing pattern:

  • Ask users to CNAME their custom domain to a wildcard-enabled domain you control, e.g., custom.mywebapp.com.
  • Set your CloudFront distribution’s alternate CNAME to *.custom.mywebapp.com—this uses just 1 CNAME slot, so you’ll never hit the 100 limit no matter how many users you add.
  • Use CloudFront Functions (lightweight, cost-effective) or Lambda@Edge (for more complex logic) to inspect the request’s Host header, then route it to your app’s correct resources. This way, your app knows exactly which user’s custom domain is making the request, even though it’s routed through your wildcard domain.

2. Simplify SSL Certificate Management

Forget manually updating certificates every time a new domain is added—here’s how to streamline this:

  • If using the wildcard CNAME approach above: Request a wildcard SSL certificate in ACM for *.custom.mywebapp.com. This single certificate will cover every user’s domain that points to your wildcard entry, no extra work needed.
  • If users need to use their own domains directly: Use ACM’s multi-domain certificates, which let you add up to 100 domains (including wildcards) per certificate. Once you hit that limit, CloudFront supports certificate stacking—you can attach multiple ACM certificates to a single distribution, as long as they cover the incoming request’s domain.
  • Automate the whole process: Build a simple workflow (using Terraform, AWS CDK, or even a Lambda function) that triggers when a user submits a custom domain request. The workflow can automatically add the domain to an ACM certificate, handle validation (either via Route 53 auto-validation if they use AWS DNS, or generate a TXT record for them to add), and you won’t even need to touch your CloudFront distribution’s config afterward.

Bonus Pro Tip

Make sure to document clear steps for users:

  • For Route 53 users: Show them how to create the CNAME record and let your automation handle the rest.
  • For non-Route 53 users: Provide the exact TXT record they need to add to their DNS provider to validate the ACM certificate, plus the CNAME to point to your CloudFront wildcard domain.

This setup eliminates both your current pain points and scales seamlessly as you add more users.

内容的提问来源于stack exchange,提问作者patrick_corrigan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 08:17:18