AWSStatic-verified

CloudFront Site (S3 + ACM + Route53)

Complete HTTPS site/CDN: CloudFront distribution, OAC-locked S3 origin, ACM cert, and Route53 alias records.

terraformAWSaws

Compare CDN & Edge Delivery across clouds →

Part of: AWS Production Landing Zone

aws-cloudfront-sitevizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-06-28 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o aws-cloudfront-site-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/aws-cloudfront-site/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle aws-cloudfront-site-1.0.0.sigstore.json \
  aws-cloudfront-site-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "89eda210ff78ea70d1cc4f3b5629b55e4450d2b8159282d1390db9ea0e092177  aws-cloudfront-site-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "cloudfront_site" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-cloudfront-site/aws"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads static-verified because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: static-verified](https://www.iac-bazaar.com/api/artifacts/aws-cloudfront-site/badge)](https://www.iac-bazaar.com/catalog/aws-cloudfront-site?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Terraform module 1.0.0, static-verified on IaC Bazaar: [CloudFront Site (S3 + ACM + Route53)](https://www.iac-bazaar.com/catalog/aws-cloudfront-site?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```hcl
module "cloudfront_site" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-cloudfront-site/aws"
  version = "1.0.0"
}
```

Preview:IaC Bazaar: static-verified

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

aws-cloudfront-site

Complete HTTPS site/CDN: CloudFront distribution, OAC-locked S3 origin, ACM cert, and Route53 alias records. Works with Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.

Secure defaults:

  • Origin bucket is private (full public-access block), encrypted, versioned, and readable only by this distribution (Origin Access Control, SigV4, AWS:SourceArn condition) — plus a non-TLS deny policy
  • ACM certificate issued in us-east-1 with fully automated Route 53 DNS validation (the classic cross-region footgun, handled)
  • HTTPS enforced (redirect-to-https), TLS 1.2 (2021 policy) minimum, HTTP/2 + HTTP/3, compression on
  • Security response headers (HSTS 2y, nosniff, SAMEORIGIN, strict referrer) attached by default
  • A + AAAA alias records created for the apex/primary domain and every SAN

Requirements

  • Terraform or OpenTofu >= 1.6
  • AWS provider >= 6.0, < 7.0, two configurations (default + aws.us_east_1)
  • A registered domain with a Route 53 public hosted zone you control

License

Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Dual provider requirement
  • Inputs
  • Outputs
  • Notes

Related modules

Static validatedLive test pending

tencent-cdn

A Tencent Cloud CDN domain in front of your COS bucket or origin hosts, serving outside mainland China unless an ICP-filed area is accepted by name, with the certificate from SSL Certificate Service, every HTTP request redirected, HSTS, HTTP/2, OCSP stapling, TLS 1.0 and 1.1 off, IPv6, and the origin fetched over HTTPS. The CNAME to point the domain at is exported.

View module
Static validatedLive test pending

huawei-cdn

A Huawei Cloud CDN domain in front of your OBS bucket or origin host, serving outside mainland China unless an ICP-filed area is accepted by name, with the certificate from Cloud Certificate Manager, every HTTP request redirected, HSTS, HTTP/2, OCSP stapling, TLS 1.0 and 1.1 off, IPv6, cache headers followed from the origin, and the origin fetched over HTTPS. The CNAME is exported.

View module
Static validatedLive test pending

alicloud-cdn

An Alibaba Cloud CDN domain in front of your OSS bucket or origin host, serving outside mainland China unless an ICP-filed scope is accepted by name, with the certificate from Certificate Management, every HTTP request redirected, HSTS, HTTP/2, TLS 1.0 and 1.1 off, IPv6, and the origin fetched over HTTPS. The CNAME to point the domain at is exported.

View module
Static validatedLive test pending

do-cdn

A DigitalOcean CDN endpoint in front of a Spaces bucket, served on your domain with a DigitalOcean-managed certificate you name (the cdn.digitaloceanspaces.com name is accepted by name), with a cache TTL you chose. The CDN serves the bucket's public objects; a private object stays private through it.

View module
Static validatedLive test pending

akamai-property-ion

End-to-end Ion CDN property: origin, edge hostname, caching/performance rule tree, CP code, and staging/production activation.

View module
Static validatedLive test pending

scaleway-cdn

Edge Services is a chain of stages, each naming the one it forwards to, and every stage is content to exist naming nothing: a half-wired pipeline shows a name and a status in the console and answers no requests. This builds the whole chain, subscribes the plan without which nothing serves, and puts a certificate and your own domain in front of a bucket.

View module