PluginBench
Skill
Official
Pass
Audit score 90

cloudfront

aws/agent-toolkit-for-aws

Configure Amazon CloudFront content delivery: distributions, caching, certificates, origin protection, content security, and observability.

What is cloudfront?

Expert guidance for setting up CloudFront as a content delivery layer. Covers deciding whether to use CloudFront, creating and tuning distributions, managing TLS certificates for custom domains, locking origins to CloudFront-only access, restricting viewer access via signed URLs and geographic controls, and analyzing traffic with logs. Use this when deploying CloudFront in front of content or securing/observing a distribution.

  • Route to six specialized workflows: when to use CloudFront, managing certificates, protecting origins, securing content, multi-tenant distributions, and observability
  • Decide whether CloudFront fits your architecture and how it integrates with WAF, Shield, CloudFront Functions, Lambda@Edge, and Route 53
  • Create distributions, configure caching strategies, and choose between Flat Rate Pricing and pay-as-you-go
  • Manage ACM certificates in us-east-1 for custom domains and multi-tenant setups
  • Protect origins with origin access control (OAC), VPC origins, and mutual TLS
  • Secure content with signed URLs, cookies, geographic restrictions, viewer mTLS, and edge token validation

How to install cloudfront

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill cloudfront
Prerequisites
  • AWS account with CloudFront API access
  • AWS CLI or AWS MCP server connection (for command execution)
  • ACM certificate in us-east-1 for custom domains (optional, depending on task)
  • Existing origin (S3 bucket, custom HTTP origin, or VPC origin) for distribution creation
Claude Code
Cursor
Windsurf
Cline

How to use cloudfront

  1. 1.Identify your task from the six workflows: when to use CloudFront, certificates, origin protection, content security, multi-tenant, or observability
  2. 2.Read the matching reference file in full before proceeding
  3. 3.Follow the constraints, decision tables, and step-by-step procedures in the reference
  4. 4.Execute AWS API calls using the AWS MCP server (preferred) or AWS CLI
  5. 5.Verify configuration with CloudFront console or describe-distribution API calls

Use cases

Good for
  • Determine if CloudFront is the right entry layer for your application and set up a distribution with appropriate caching
  • Serve a custom domain over HTTPS by requesting and validating an ACM certificate and configuring alternate domain names
  • Lock an S3 origin or custom origin so it is only reachable through CloudFront using OAC or origin mTLS
  • Restrict content access by viewer identity, location, or client certificate using signed URLs, cookies, or geographic restrictions
  • Analyze CloudFront traffic patterns and troubleshoot delivery issues using standard and real-time logs
Who it's for
  • AWS architects designing content delivery layers
  • DevOps engineers deploying and securing CloudFront distributions
  • SaaS platform teams building multi-tenant delivery infrastructure
  • Security engineers implementing origin protection and content access controls
  • Operations teams monitoring and troubleshooting CloudFront traffic

cloudfront FAQ

When should I use CloudFront instead of serving content directly from my origin?

Use CloudFront when you need global edge caching, reduced origin load, DDoS protection via Shield, WAF integration, content signing, or geographic restrictions. See the when-to-use-cloudfront reference for a full decision framework.

Can I use the same ACM certificate for multiple CloudFront distributions?

Yes. ACM certificates must be created in us-east-1 regardless of where your application runs. You can attach the same certificate to multiple distributions as an alternate domain name.

What is the difference between origin access control (OAC) and origin mTLS?

OAC restricts S3 bucket access to CloudFront only via bucket policy. Origin mTLS authenticates CloudFront to your custom origin using client certificates. Both lock the origin; use OAC for S3 and origin mTLS for custom HTTP origins.

How do I restrict content access by viewer location or identity?

Use geographic restrictions to block or allow countries, signed URLs/cookies to require authentication, viewer mTLS to require client certificates, or edge token validation for custom auth. See the securing-your-content reference for implementation details.

Does this skill handle Route 53 DNS configuration for my custom domain?

No. This skill configures the CloudFront side only: ACM certificates and alternate domain names. Pointing your domain's DNS at the distribution is handled by the separate route53-cloudfront skill.

Full instructions (SKILL.md)

Source of truth, from aws/agent-toolkit-for-aws.


name: cloudfront description: > Configures Amazon CloudFront content delivery across six workflows: when to use CloudFront and how it fits with AWS WAF, Shield, CloudFront Functions, Lambda@Edge, Route 53, and origins (creating a distribution, caching, and Flat Rate Pricing (FRP) versus pay-as-you-go pricing); managing custom-domain TLS certificates (ACM in us-east-1); configuring multi-tenant distributions; protecting origins with origin access control (OAC), VPC origins, and origin mutual TLS (mTLS); securing content with signed URLs and cookies, geographic restrictions, viewer mutual TLS, and edge token validation; and observing traffic with standard and real-time logs. Applicable when the customer wants to put CloudFront in front of content, choose pricing, lock an origin, restrict who can view content, or analyze logs. Not applicable for the Route 53 DNS side of a CloudFront custom domain or failover between distributions (see the route53-cloudfront skill), or for pure-Route 53 DNS work (see the route53 skill). version: 1

Amazon CloudFront

Overview

Domain expertise for configuring Amazon CloudFront content delivery: deciding when to use CloudFront and how it fits the wider architecture, managing custom-domain certificates and multi-tenant distributions, protecting origins, securing content, and observing traffic.

This skill is a router. Each customer task maps to a procedure file under references/. Read the matching reference in full before acting, then follow its constraints and steps. The reference files are self-contained: each carries its own decision tables, constraints, procedure, and troubleshooting.

Execute commands using the AWS MCP server when connected (sandboxed execution, audit logging, observability). Fall back to the AWS CLI otherwise. CloudFront is a global service; its API calls and the AWS Certificate Manager (ACM) certificates it uses are made in us-east-1 regardless of where the customer's application runs.

Which CloudFront task do you need?

GoalReference
Decide whether CloudFront is the right layer, see how it integrates, create a distribution, tune caching, or choose pricingwhen to use CloudFront
Serve a custom domain over HTTPS, manage ACM certificates, or run many domains with a certificate per tenantmanaging certificates with CloudFront
Make CloudFront the only way to reach the origin (S3 OAC, VPC origins, origin mutual TLS, security groups)protecting your origins
Limit who can view content by identity, location, client certificate, or auth tokensecuring your content
Get visibility into traffic with standard and real-time logs, and analyze themCloudFront observability
Serve multiple domains through shared configuration with per-tenant customization (SaaS, platform)multi-tenant distributions

Routing notes

  • Choosing the layer and creating a distribution vs the rest. Whether CloudFront is the right entry layer, what it integrates with, creating a distribution, caching, and pricing live in the when-to-use reference. The other references assume a distribution exists and configure one aspect of it.
  • Protecting origins vs securing content. Locking the origin so it is reachable only through CloudFront (OAC, VPC origins, origin mTLS) is the protecting-your-origins reference. Restricting which viewers can see content (signed URLs and cookies, geographic restrictions, viewer mTLS, edge token validation) is the securing-your-content reference. They are paired: a content control only holds when the origin is also locked.
  • Viewer mTLS vs origin mTLS. Authenticating the client to CloudFront (viewer mTLS) is content security. Authenticating CloudFront to the origin (origin mTLS) is origin protection. Different controls, different references.
  • Custom domain certificate vs Route 53 DNS cutover. Requesting and validating the ACM certificate and adding the alternate domain name is the managing-certificates reference here. Pointing the domain's DNS at the distribution, including the zone apex alias and any failover, is Route 53 work owned by the separate route53-cloudfront skill.

Cross-service work

Pointing a custom domain's DNS at a CloudFront distribution, or failing over between distributions with Route 53 records, is cross-service work owned by the separate route53-cloudfront skill. Use this skill for the CloudFront-side configuration only.

Additional Resources