cloudfront

โดย aws

กำหนดค่าการจัดส่งเนื้อหา Amazon CloudFront ในหกขั้นตอนการทำงาน: เมื่อใดควรใช้ CloudFront และวิธีการทำงานร่วมกับ AWS WAF, Shield, CloudFront Functions,…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill cloudfront

Amazon CloudFront

Overview

Domain expertise for configuring Amazon CloudFront content delivery: deciding when to use CloudFront and how it fits the wider architecture, managing custom-domain certificates and multi-tenant distributions, protecting origins, securing content, and observing traffic.

This skill is a router. Each customer task maps to a procedure file under references/. Read the matching reference in full before acting, then follow its constraints and steps. The reference files are self-contained: each carries its own decision tables, constraints, procedure, and troubleshooting.

Execute commands using the AWS MCP server when connected (sandboxed execution, audit logging, observability). Fall back to the AWS CLI otherwise. CloudFront is a global service; its API calls and the AWS Certificate Manager (ACM) certificates it uses are made in us-east-1 regardless of where the customer's application runs.

Which CloudFront task do you need?

GoalReference
Decide whether CloudFront is the right layer, see how it integrates, create a distribution, tune caching, or choose pricingwhen to use CloudFront
Serve a custom domain over HTTPS, manage ACM certificates, or run many domains with a certificate per tenantmanaging certificates with CloudFront
Make CloudFront the only way to reach the origin (S3 OAC, VPC origins, origin mutual TLS, security groups)protecting your origins
Limit who can view content by identity, location, client certificate, or auth tokensecuring your content
Get visibility into traffic with standard and real-time logs, and analyze themCloudFront observability
Serve multiple domains through shared configuration with per-tenant customization (SaaS, platform)multi-tenant distributions

Routing notes

  • Choosing the layer and creating a distribution vs the rest. Whether CloudFront is the right entry layer, what it integrates with, creating a distribution, caching, and pricing live in the when-to-use reference. The other references assume a distribution exists and configure one aspect of it.
  • Protecting origins vs securing content. Locking the origin so it is reachable only through CloudFront (OAC, VPC origins, origin mTLS) is the protecting-your-origins reference. Restricting which viewers can see content (signed URLs and cookies, geographic restrictions, viewer mTLS, edge token validation) is the securing-your-content reference. They are paired: a content control only holds when the origin is also locked.
  • Viewer mTLS vs origin mTLS. Authenticating the client to CloudFront (viewer mTLS) is content security. Authenticating CloudFront to the origin (origin mTLS) is origin protection. Different controls, different references.
  • Custom domain certificate vs Route 53 DNS cutover. Requesting and validating the ACM certificate and adding the alternate domain name is the managing-certificates reference here. Pointing the domain's DNS at the distribution, including the zone apex alias and any failover, is Route 53 work owned by the separate route53-cloudfront skill.

Cross-service work

Pointing a custom domain's DNS at a CloudFront distribution, or failing over between distributions with Route 53 records, is cross-service work owned by the separate route53-cloudfront skill. Use this skill for the CloudFront-side configuration only.

Additional Resources

Skills เพิ่มเติมจาก aws

analyzing-release-readiness
aws
เรียกใช้การตรวจสอบความพร้อมก่อนการรวมโค้ด (pre-merge release readiness review) บน GitHub PR, GitLab MR หรือสาขาในเครื่อง (local branch) ใช้เมื่อผู้ใช้ต้องการวิเคราะห์การเปลี่ยนแปลงโค้ดเพื่อหาความเสี่ยง ความถูกต้อง…
scanning-with-aws-security-agent
aws
รันการสแกน AWS Security Agent บนเวิร์กสเปซ — อัปโหลดซอร์สไปยัง AWS สแกนด้วยบริการ Security Agent ที่มีการจัดการ และส่งคืนผลลัพธ์ที่จัดอันดับและตรวจสอบแล้ว…
coordinating-multi-space-devops-agent
aws
ประสานงาน AWS DevOps Agent ในหลาย AgentSpaces จากเซสชัน Claude Code เดียว — กำหนดเส้นทางคำถามไปยังพื้นที่ที่ถูกต้อง (prod vs staging vs knowledge),…
aws-security
aws
ครอบคลุมบริการและเวิร์กโฟลว์ด้านความปลอดภัยของ AWS — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules และสรุปสถานะความปลอดภัย;…
querying-aws-sagemaker-catalog
aws
รันการวิเคราะห์ SQL บนตารางเมตาดาต้าของสินทรัพย์ SageMaker Catalog ที่ส่งออกเป็น Apache Iceberg ใน S3 Tables ครอบคลุมการสอบถามด้านธรรมาภิบาล การติดตามการเติบโตของสินทรัพย์…
agents-connect
aws
ใช้เมื่อเชื่อมต่อเอเจนต์ของคุณกับ API เครื่องมือ หรือบริการภายนอกผ่าน Gateway หรือจำกัดการเข้าถึงเครื่องมือด้วยนโยบาย Cedar จัดการการตั้งค่า Gateway เป้าหมาย…
aurora-dsql
aws
จัดเตรียมและจัดการคลัสเตอร์ Aurora DSQL เชื่อมต่อผ่าน psql หรือ DSQL Connectors จัดการสคีมา รันคิวรี ย้ายข้อมูลจาก MySQL วินิจฉัยแผนคิวรี…
transitgateway
aws
กำหนดค่า AWS Transit Gateway: สร้างฮับและเชื่อมต่อ VPC แบ่งกลุ่มทราฟฟิกด้วยตารางเส้นทาง รวมศูนย์อีเกรสและการตรวจสอบผ่านฮับ…