amazon-web-services - 配置 Cloudformation 以使用 Cloudfront 和 S3 对 GET /subdirectory 服务 /subdirectory/index.html 的请求
问题描述
我有一个 Cloudformation 模板,用于设置 AWS::CloudFront::Distribution 和 AWS::S3::Bucket。不幸的是,对 GET /subdirectory 的请求以 403 响应。如何配置 Cloudformation 模板以让 GET /subdirectory 服务 /subdirectory/index.html?
我的 Cloudfront 配置如下所示:
CloudFrontDistribution:
Type: 'AWS::CloudFront::Distribution'
Properties:
DistributionConfig:
Aliases:
- !FindInMap [Domain, !Ref Stage, Domain]
ViewerCertificate:
AcmCertificateArn: !Ref Cert
SslSupportMethod: sni-only
CustomErrorResponses:
- ErrorCode: 403 # not found
ResponseCode: 404
ResponsePagePath: !Ref ErrorPagePath
DefaultCacheBehavior:
AllowedMethods:
- GET
- HEAD
- OPTIONS
CachedMethods:
- GET
- HEAD
- OPTIONS
Compress: true
DefaultTTL: 3600 # in seconds
ForwardedValues:
Cookies:
Forward: none
QueryString: false
MaxTTL: 86400 # in seconds
MinTTL: 60 # in seconds
TargetOriginId: s3origin
ViewerProtocolPolicy: redirect-to-https
DefaultRootObject: !Ref DefaultRootObject
Enabled: true
HttpVersion: http2
Origins:
- DomainName: !GetAtt 'S3Bucket.DomainName'
Id: s3origin
S3OriginConfig:
OriginAccessIdentity: !Sub 'origin-access-identity/cloudfront/${CloudFrontOriginAccessIdentity}'
PriceClass: 'PriceClass_All'
除了对 GET /subdirectory 的请求之外,一切正常。
我也试过:
- DomainName: !GetAtt 'S3Bucket.RegionalDomainName'
Id: s3origin
S3OriginConfig:
OriginProtocolPolicy: http-only
但是我Property TemplateURL cannot be empty.
在AWS::CloudFormation::Stack
.
解决方案
'use strict';
const querystring = require('querystring');
exports.handler = (event, context, callback) => {
const request = event.Records[0].cf.request;
/**
* Reads query string to check if S3 origin should be used, and
* if true, sets S3 origin properties.
*/
const params = querystring.parse(request.querystring);
if (params['useS3Origin']) {
if (params['useS3Origin'] === 'true') {
const s3DomainName = 'my-bucket.s3.amazonaws.com';
/* Set S3 origin fields */
request.origin = {
s3: {
domainName: s3DomainName,
region: '',
authMethod: 'none',
path: '',
customHeaders: {}
}
};
request.headers['host'] = [{ key: 'host', value: s3DomainName}];
}
}
callback(null, request);
};
path
您可以使用请求中的查询字符串将其更改为正确指向。
选中此项以设置CloudFormation,有一个关于如何设置触发器的示例
Resources:
CFDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
Enabled: 'true'
Comment: !Sub '${Stage} - CI/CD for Lambda@Edge'
Aliases:
- !FindInMap [AliasMap, !Ref Stage, Alias]
Origins:
-
Id: MyOrigin
DomainName: aws.amazon.com
CustomOriginConfig:
HTTPPort: 80
OriginProtocolPolicy: match-viewer
DefaultCacheBehavior:
TargetOriginId: MyOrigin
LambdaFunctionAssociations:
-
EventType: origin-request
LambdaFunctionARN: !Ref LambdaEdgeFunctionSample.Version
推荐阅读
- python - 如何禁用 django 注册密码 help_text
- c# - 如何在函数中使用 Azure 门户调用 Azure Compute Rest API?
- python - 如何在 Python 2.7 中声明一个空字典的空字典?
- xml - 如何在 xsl:comment 中包含 xml 并保持缩进
- html - 如何在 node-red 中使用纯 json 创建网页
- python - Scipy Curve_fit:为什么我的拟合这么差,如何改进?
- gstreamer - Gstreamer filesink 适用于命令行但不适用于 Java 代码
- github - GitHub:是否可以查看特定分支而不是整个仓库?
- node.js - Loopback 3 / Where Filter / LIKE / MSSQL 连接器错误
- sql - 如何修复提供用户输入的 PL/SQL 函数,它将通过条件语句并输出正确的行