Deploys an AWS CloudFront distribution in front of your environment's public domain (AWS only). CloudFront serves your public hostnames over HTTPS with a managed TLS certificate and forwards requests privately to the Ryvn-managed origin through a CloudFront VPC origin. Optionally add AWS WAF and require client certificates (mTLS) from callers.
This blueprint accepts 27 configurable inputs to customize the installation for your environment.
hostnamesarrayPublic hostnames to serve through CloudFront.
originReadTimeoutSecondsnumberHow long, in seconds, CloudFront waits for a response from the origin. Valid range: 1-120.
cachePoliciesstringDefine reusable cache policies as a YAML map. Behaviors reference each policy by its key. ```yaml static_assets: min_ttl: 0 default_ttl: 86400 max_ttl: 31536000 ``` Every policy includes `Host`. `enable_accept_encoding_gzip` and `enable_accept_encoding_brotli` default to `true`.
orderedCacheBehaviorsstringDefine path-based cache behaviors as a YAML list evaluated in order. ```yaml - path_pattern: "/_next/static/*" cache_policy_key: static_assets compress: true ``` `compress` defaults to `true` and enables CloudFront edge compression.
customErrorResponsesstringCloudFront custom error responses as a YAML list (`error_code`, optional `response_code`, `response_page_path`, and `error_caching_min_ttl`). Applies to the whole distribution.
enableViewerMtlsbooleanValidate client certificates from callers connecting to CloudFront.
viewerMtlsModestringRequired rejects callers without a valid certificate. Optional requests one but still allows callers without it.
viewerMtlsTrustedCaBundlemapPublic CA certificate bundle used to validate client certificates. Provide a PEM bundle under the ca.crt key; do not include private keys.
viewerMtlsAdvertiseTrustStoreCaNamesbooleanAdvertise the accepted CA names during the TLS handshake so callers can present a matching certificate.
viewerMtlsIgnoreCertificateExpirybooleanAccept expired client certificates, while still checking they were issued by a trusted CA.
ipAllowListarrayCIDR blocks allowed to reach CloudFront. Leave empty to allow all sources.
wafCommonRuleSetActionstringLooks for common web app attacks such as XSS, path traversal, oversized requests, and other OWASP-style issues.
wafKnownBadInputsActionstringLooks for request patterns linked to known exploits or attempts to find vulnerable apps.
wafAmazonIpReputationActionstringChecks whether the request comes from an IP AWS has linked to bots, DDoS, scanning, or other abuse.
wafAnonymousIpActionstringChecks whether the request comes through VPNs, proxies, Tor, or hosting providers that can hide who is calling.
webAclArnstringAttach an externally managed CloudFront-scoped AWS WAF WebACL by ARN instead of configuring rules here.
enableCloudFrontLoggingbooleanDeliver CloudFront standard access logs to an existing S3 bucket.
cloudFrontLogBucketArnstringExisting S3 bucket ARN for CloudFront standard access logs.
enableWafLoggingbooleanDeliver AWS WAF request logs to an existing S3 bucket.
wafLogBucketArnstringExisting same-account S3 bucket ARN for AWS WAF request logs. AWS requires the bucket name to start with `aws-waf-logs-`; see [AWS WAF S3 logging requirements](https://docs.aws.amazon.com/waf/latest/developerguide/logging-s3.html).
existingVpcOriginIdstringReuse an externally managed CloudFront VPC origin by ID. Leave empty to create one from the environment's Ryvn-managed internal load balancer.
vpcOriginEndpointLookupTagsstringAWS load balancer tags as a YAML map, used to find the VPC origin's load balancer. Leave empty to use the environment's Ryvn-managed internal load balancer.
vpcOriginNamestringName for the created VPC origin. Leave empty for a generated name. A short endpoint fingerprint suffix is always appended.
priceClassstringCloudFront price class.
enableMonitoringbooleanCollect CloudFront real-time metrics.
waitForDeploymentbooleanWait for CloudFront to finish deploying before this completes.
retainOnDeletebooleanDisable the distribution instead of deleting it when this blueprint is removed.
This blueprint exposes 7 outputs that other services can reference.
distributionIdstringCloudFront distribution ID.
distributionArnstringCloudFront distribution ARN.
distributionDomainNamestringCloudFront distribution DNS name.
vpcOriginIdstringCloudFront VPC origin ID. Reference it from another installation's Existing VPC Origin ID input to share one VPC origin across distributions.
webAclArnstringAWS WAFv2 WebACL ARN attached to the CloudFront distribution, when configured.
externalDnsTargetAnnotationstringExternal DNS annotation to add to a service installation networking ingress so DNS targets the CloudFront distribution.
requiredDnsRecordsstringDNS records to create yourself when this blueprint isn't managing Route53.