Serverless Framework - AWS CloudFront distribution S3 bucket access configuration

Viewed 316

I'm deploying a AWS Cloudfront distribution with the serverless-api-cloudfront plugin.

This distribution has a S3 origin configured which works as expected.

Configuration:

plugins:
- serverless-api-cloudfront

mywebapp:
   component: "@sls-next/serverless-component@3.6.0"
   inputs:
      env:
         ...
      cloudfront:
         defaults: # options for lambda that handle SSR
            ...
         origins:
            - url: https://...
              S3OriginConfig:
                  OriginAccessIdentity:
              pathPatterns:
                  secure/exports/*:
                    minTTL: 10
                    maxTTL: 10
                    defaultTTL: 10
                    forward:
                      cookies: "none"
                      queryString: true
    ...

My problem is that When my distribution is depoyed, the S3 bucket access configuration of my S3 origin is always set to "Yes use OAI (bucket can restrict access to only CloudFront)" and I would like it to be "Don't use OAI (bucket must allow public access)".

https://imgur.com/6Aagn0T

Any idea on how to configure this?

1 Answers

Its a very bad idea to disable OAI as it allows you to make sure that your static assets are only accessible via CloudFront. This maybe the reason why this is not doable in serverless framework. Do try AWS CDK or CloudFormation if you really want to proceed with this approach.

Related