Skip to content

sec(iac): flip dev/staging/prod to AWS_IAM + enable CloudFront OAC (runtime cut-over for #424) #16

Description

@cristim

Context

PR LeanerCloud/cloud-commitments-cli#574 added the Terraform infrastructure for authorization_type = "AWS_IAM" on the Lambda Function URL:

  • aws_cloudfront_origin_access_control (type=lambda, sigv4) in the frontend module
  • aws_lambda_permission.function_url_cloudfront at the environment layer (scoped to the specific distribution ARN)
  • Module default changed to "AWS_IAM"

All three env tfvars retain "NONE" with a TODO(LeanerCloud/cloud-commitments-cli#424) comment because flipping to "AWS_IAM" without a CloudFront OAC in place would make the Function URL return HTTP 403 on all requests.

What this issue tracks

The runtime cut-over: deploying CloudFront in front of each Lambda environment and flipping the auth type.

Steps per environment

For each of dev, staging, prod (in that order):

  1. In the env's github-*.tfvars:
    • Set enable_cdn = true
    • Set lambda_function_url_auth_type = "AWS_IAM"
    • Update lambda_allowed_origins from the raw Lambda Function URL to the CloudFront domain (e.g. ["https://app.example.com"])
  2. Run terraform apply -- this creates the CloudFront distribution, the OAC, and the Lambda permission in a single apply.
  3. Verify: hit the CloudFront URL, confirm requests reach Lambda and return 200. Confirm a direct request to the Lambda Function URL returns 403.

Notes

  • The frontend client.ts is already OAC-ready (uses X-Authorization, sends x-amz-content-sha256 on mutating requests).
  • Staging and prod tfvars use .invalid placeholder origins -- update to real domains before applying.
  • The dev Lambda Function URL is https://33pz7pombdqwu3bdlxp4lqxyra0bsriy.lambda-url.us-east-1.on.aws (from the current github-dev.tfvars).

Closes LeanerCloud/cloud-commitments-cli#424

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions