Context
PR LeanerCloud/cloud-commitments-cli#574 added the Terraform infrastructure for authorization_type = "AWS_IAM" on the Lambda Function URL:
aws_cloudfront_origin_access_control (type=lambda, sigv4) in the frontend module
aws_lambda_permission.function_url_cloudfront at the environment layer (scoped to the specific distribution ARN)
- Module default changed to
"AWS_IAM"
All three env tfvars retain "NONE" with a TODO(LeanerCloud/cloud-commitments-cli#424) comment because flipping to "AWS_IAM" without a CloudFront OAC in place would make the Function URL return HTTP 403 on all requests.
What this issue tracks
The runtime cut-over: deploying CloudFront in front of each Lambda environment and flipping the auth type.
Steps per environment
For each of dev, staging, prod (in that order):
- In the env's
github-*.tfvars:
- Set
enable_cdn = true
- Set
lambda_function_url_auth_type = "AWS_IAM"
- Update
lambda_allowed_origins from the raw Lambda Function URL to the CloudFront domain (e.g. ["https://app.example.com"])
- Run
terraform apply -- this creates the CloudFront distribution, the OAC, and the Lambda permission in a single apply.
- Verify: hit the CloudFront URL, confirm requests reach Lambda and return 200. Confirm a direct request to the Lambda Function URL returns 403.
Notes
- The frontend
client.ts is already OAC-ready (uses X-Authorization, sends x-amz-content-sha256 on mutating requests).
- Staging and prod tfvars use
.invalid placeholder origins -- update to real domains before applying.
- The dev Lambda Function URL is
https://33pz7pombdqwu3bdlxp4lqxyra0bsriy.lambda-url.us-east-1.on.aws (from the current github-dev.tfvars).
Closes LeanerCloud/cloud-commitments-cli#424
Context
PR LeanerCloud/cloud-commitments-cli#574 added the Terraform infrastructure for
authorization_type = "AWS_IAM"on the Lambda Function URL:aws_cloudfront_origin_access_control(type=lambda, sigv4) in the frontend moduleaws_lambda_permission.function_url_cloudfrontat the environment layer (scoped to the specific distribution ARN)"AWS_IAM"All three env tfvars retain
"NONE"with aTODO(LeanerCloud/cloud-commitments-cli#424)comment because flipping to"AWS_IAM"without a CloudFront OAC in place would make the Function URL return HTTP 403 on all requests.What this issue tracks
The runtime cut-over: deploying CloudFront in front of each Lambda environment and flipping the auth type.
Steps per environment
For each of dev, staging, prod (in that order):
github-*.tfvars:enable_cdn = truelambda_function_url_auth_type = "AWS_IAM"lambda_allowed_originsfrom the raw Lambda Function URL to the CloudFront domain (e.g.["https://app.example.com"])terraform apply-- this creates the CloudFront distribution, the OAC, and the Lambda permission in a single apply.Notes
client.tsis already OAC-ready (usesX-Authorization, sendsx-amz-content-sha256on mutating requests)..invalidplaceholder origins -- update to real domains before applying.https://33pz7pombdqwu3bdlxp4lqxyra0bsriy.lambda-url.us-east-1.on.aws(from the currentgithub-dev.tfvars).Closes LeanerCloud/cloud-commitments-cli#424