←Marketplace

CloudFront Edge

Description

Deploys an AWS CloudFront distribution in front of your environment's public domain (AWS only). CloudFront serves your public hostnames over HTTPS with a managed TLS certificate and forwards requests privately to the Ryvn-managed origin through a CloudFront VPC origin. Optionally add AWS WAF and require client certificates (mTLS) from callers.

Configuration Inputs

This blueprint accepts 27 configurable inputs to customize the installation for your environment.

hostnamesarray

Public hostnames to serve through CloudFront.

originReadTimeoutSecondsnumber

How long, in seconds, CloudFront waits for a response from the origin. Valid range: 1-120.

cachePoliciesstring

Define reusable cache policies as a YAML map. Behaviors reference each policy by its key. ```yaml static_assets: min_ttl: 0 default_ttl: 86400 max_ttl: 31536000 ``` Every policy includes `Host`. `enable_accept_encoding_gzip` and `enable_accept_encoding_brotli` default to `true`.

orderedCacheBehaviorsstring

Define path-based cache behaviors as a YAML list evaluated in order. ```yaml - path_pattern: "/_next/static/*" cache_policy_key: static_assets compress: true ``` `compress` defaults to `true` and enables CloudFront edge compression.

customErrorResponsesstring

CloudFront custom error responses as a YAML list (`error_code`, optional `response_code`, `response_page_path`, and `error_caching_min_ttl`). Applies to the whole distribution.

enableViewerMtlsboolean

Validate client certificates from callers connecting to CloudFront.

viewerMtlsModestring

Required rejects callers without a valid certificate. Optional requests one but still allows callers without it.

viewerMtlsTrustedCaBundlemap

Public CA certificate bundle used to validate client certificates. Provide a PEM bundle under the ca.crt key; do not include private keys.

viewerMtlsAdvertiseTrustStoreCaNamesboolean

Advertise the accepted CA names during the TLS handshake so callers can present a matching certificate.

viewerMtlsIgnoreCertificateExpiryboolean

Accept expired client certificates, while still checking they were issued by a trusted CA.

ipAllowListarray

CIDR blocks allowed to reach CloudFront. Leave empty to allow all sources.

wafCommonRuleSetActionstring

Looks for common web app attacks such as XSS, path traversal, oversized requests, and other OWASP-style issues.

wafKnownBadInputsActionstring

Looks for request patterns linked to known exploits or attempts to find vulnerable apps.

wafAmazonIpReputationActionstring

Checks whether the request comes from an IP AWS has linked to bots, DDoS, scanning, or other abuse.

wafAnonymousIpActionstring

Checks whether the request comes through VPNs, proxies, Tor, or hosting providers that can hide who is calling.

webAclArnstring

Attach an externally managed CloudFront-scoped AWS WAF WebACL by ARN instead of configuring rules here.

enableCloudFrontLoggingboolean

Deliver CloudFront standard access logs to an existing S3 bucket.

cloudFrontLogBucketArnstring

Existing S3 bucket ARN for CloudFront standard access logs.

enableWafLoggingboolean

Deliver AWS WAF request logs to an existing S3 bucket.

wafLogBucketArnstring

Existing same-account S3 bucket ARN for AWS WAF request logs. AWS requires the bucket name to start with `aws-waf-logs-`; see [AWS WAF S3 logging requirements](https://docs.aws.amazon.com/waf/latest/developerguide/logging-s3.html).

existingVpcOriginIdstring

Reuse an externally managed CloudFront VPC origin by ID. Leave empty to create one from the environment's Ryvn-managed internal load balancer.

vpcOriginEndpointLookupTagsstring

AWS load balancer tags as a YAML map, used to find the VPC origin's load balancer. Leave empty to use the environment's Ryvn-managed internal load balancer.

vpcOriginNamestring

Name for the created VPC origin. Leave empty for a generated name. A short endpoint fingerprint suffix is always appended.

priceClassstring

CloudFront price class.

enableMonitoringboolean

Collect CloudFront real-time metrics.

waitForDeploymentboolean

Wait for CloudFront to finish deploying before this completes.

retainOnDeleteboolean

Disable the distribution instead of deleting it when this blueprint is removed.

Outputs

This blueprint exposes 7 outputs that other services can reference.

distributionIdstring

CloudFront distribution ID.

distributionArnstring

CloudFront distribution ARN.

distributionDomainNamestring

CloudFront distribution DNS name.

vpcOriginIdstring

CloudFront VPC origin ID. Reference it from another installation's Existing VPC Origin ID input to share one VPC origin across distributions.

webAclArnstring

AWS WAFv2 WebACL ARN attached to the CloudFront distribution, when configured.

externalDnsTargetAnnotationstring

External DNS annotation to add to a service installation networking ingress so DNS targets the CloudFront distribution.

requiredDnsRecordsstring

DNS records to create yourself when this blueprint isn't managing Route53.