cloudfront

por aws

Configura la entrega de contenido de Amazon CloudFront en seis flujos de trabajo: cuándo usar CloudFront y cómo se integra con AWS WAF, Shield, CloudFront Functions,…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill cloudfront

Amazon CloudFront

Overview

Domain expertise for configuring Amazon CloudFront content delivery: deciding when to use CloudFront and how it fits the wider architecture, managing custom-domain certificates and multi-tenant distributions, protecting origins, securing content, and observing traffic.

This skill is a router. Each customer task maps to a procedure file under references/. Read the matching reference in full before acting, then follow its constraints and steps. The reference files are self-contained: each carries its own decision tables, constraints, procedure, and troubleshooting.

Execute commands using the AWS MCP server when connected (sandboxed execution, audit logging, observability). Fall back to the AWS CLI otherwise. CloudFront is a global service; its API calls and the AWS Certificate Manager (ACM) certificates it uses are made in us-east-1 regardless of where the customer's application runs.

Which CloudFront task do you need?

GoalReference
Decide whether CloudFront is the right layer, see how it integrates, create a distribution, tune caching, or choose pricingwhen to use CloudFront
Serve a custom domain over HTTPS, manage ACM certificates, or run many domains with a certificate per tenantmanaging certificates with CloudFront
Make CloudFront the only way to reach the origin (S3 OAC, VPC origins, origin mutual TLS, security groups)protecting your origins
Limit who can view content by identity, location, client certificate, or auth tokensecuring your content
Get visibility into traffic with standard and real-time logs, and analyze themCloudFront observability
Serve multiple domains through shared configuration with per-tenant customization (SaaS, platform)multi-tenant distributions

Routing notes

  • Choosing the layer and creating a distribution vs the rest. Whether CloudFront is the right entry layer, what it integrates with, creating a distribution, caching, and pricing live in the when-to-use reference. The other references assume a distribution exists and configure one aspect of it.
  • Protecting origins vs securing content. Locking the origin so it is reachable only through CloudFront (OAC, VPC origins, origin mTLS) is the protecting-your-origins reference. Restricting which viewers can see content (signed URLs and cookies, geographic restrictions, viewer mTLS, edge token validation) is the securing-your-content reference. They are paired: a content control only holds when the origin is also locked.
  • Viewer mTLS vs origin mTLS. Authenticating the client to CloudFront (viewer mTLS) is content security. Authenticating CloudFront to the origin (origin mTLS) is origin protection. Different controls, different references.
  • Custom domain certificate vs Route 53 DNS cutover. Requesting and validating the ACM certificate and adding the alternate domain name is the managing-certificates reference here. Pointing the domain's DNS at the distribution, including the zone apex alias and any failover, is Route 53 work owned by the separate route53-cloudfront skill.

Cross-service work

Pointing a custom domain's DNS at a CloudFront distribution, or failing over between distributions with Route 53 records, is cross-service work owned by the separate route53-cloudfront skill. Use this skill for the CloudFront-side configuration only.

Additional Resources

Más skills de aws

analyzing-release-readiness
aws
Activa una revisión de preparación para el lanzamiento previa a la fusión en un PR de GitHub, MR de GitLab o rama local. Úsalo cuando el usuario quiera analizar cambios de código para evaluar riesgo, corrección,…
scanning-with-aws-security-agent
aws
Ejecuta un escaneo del AWS Security Agent en el workspace: sube el código fuente a AWS, lo escanea con el servicio administrado Security Agent y devuelve resultados clasificados y verificados…
coordinating-multi-space-devops-agent
aws
Coordina el agente DevOps de AWS a través de múltiples AgentSpaces desde una sola sesión de Claude Code: enruta las preguntas al espacio correcto (prod vs staging vs knowledge),…
aws-security
aws
Cubre los servicios y flujos de trabajo de seguridad de AWS: hallazgos de Security Hub V2 (OCSF), conectores, agregadores, reglas de automatización y resúmenes de postura de seguridad;…
querying-aws-sagemaker-catalog
aws
Ejecuta análisis SQL sobre tablas de metadatos de activos de SageMaker Catalog exportadas como Apache Iceberg en S3 Tables. Cubre consultas de gobernanza, seguimiento del crecimiento de activos,…
agents-connect
aws
Úsalo al conectar tu agente a APIs, herramientas o servicios externos a través de Gateway, o al restringir el acceso a herramientas con políticas de Cedar. Gestiona la configuración de gateway, target…
aurora-dsql
aws
Aprovisiona y gestiona clústeres de Aurora DSQL, se conecta mediante psql o conectores DSQL, gestiona esquemas, ejecuta consultas, migra desde MySQL, diagnostica planes de consulta,…
transitgateway
aws
Configura AWS Transit Gateway: creación de un hub y conexión de VPCs, segmentación del tráfico con tablas de rutas, centralización de la salida y la inspección a través de un hub…