routing-traffic-with-route53-and-cloudfront
aws/agent-toolkit-for-aws
Configure Route 53 DNS routing to CloudFront distributions with custom domains and HTTPS.
What is routing-traffic-with-route53-and-cloudfront?
Sets up Amazon Route 53 to route traffic to CloudFront distributions using custom domain names, alias records, and ACM certificates. Use this when you need to connect a custom domain to a CloudFront distribution with HTTPS support and IPv6 capability.
- Create and manage Route 53 hosted zones for CloudFront distributions
- Configure alias A and AAAA records pointing to CloudFront endpoints
- Set up alternate domain names (CNAMEs) in CloudFront configuration
- Request and validate ACM certificates in us-east-1 for HTTPS
- Monitor DNS propagation and troubleshoot routing issues
How to install routing-traffic-with-route53-and-cloudfront
npx skills add https://github.com/aws/agent-toolkit-for-aws --skill routing-traffic-with-route53-and-cloudfront- An existing CloudFront distribution
- An AWS account with Route 53 access
- An ACM certificate (or ability to request one in us-east-1)
- A public hosted zone in Route 53 (or permission to create one)
How to use routing-traffic-with-route53-and-cloudfront
- 1.Verify your CloudFront distribution is active and note its domain name
- 2.Add your custom domain as an alternate domain name (CNAME) in the CloudFront distribution settings
- 3.Request an ACM certificate for your custom domain in the us-east-1 region and validate it
- 4.Create or locate your public hosted zone in Route 53
- 5.Create alias A and AAAA records in Route 53 pointing to your CloudFront distribution
- 6.Monitor DNS propagation using nslookup or dig to confirm routing is working
Use cases
- Setting up a custom domain (e.g., cdn.example.com) for a CloudFront distribution
- Enabling HTTPS on a CloudFront distribution with an ACM certificate
- Adding IPv6 support to a CloudFront-backed website
- Migrating traffic from one CloudFront distribution to another via DNS
- Configuring multiple alternate domain names for a single CloudFront distribution
- AWS infrastructure engineers
- DevOps practitioners managing CDN deployments
- Solutions architects designing content delivery networks
- Backend developers setting up custom domains for web applications
routing-traffic-with-route53-and-cloudfront FAQ
CloudFront only works with public hosted zones. If you only have a private hosted zone, you must create a public one.
CloudFront requires ACM certificates to be in the us-east-1 region, regardless of where your distribution is located.
Changes typically propagate within 60 seconds, but full global propagation can take up to 48 hours.
Ensure the domain is added as an alternate domain name (CNAME) in the CloudFront distribution configuration before creating Route 53 records.
Use nslookup or dig commands to query your domain and confirm it resolves to your CloudFront distribution's endpoint.
Full instructions (SKILL.md)
Source of truth, from aws/agent-toolkit-for-aws.
name: routing-traffic-with-route53-and-cloudfront description: Configures Amazon Route 53 to route traffic to a CloudFront distribution using a custom domain. Use when setting up DNS alias records, alternate domain names (CNAMEs), ACM certificates for HTTPS, and IPv6 support for CloudFront. version: 1
Routing Traffic with Route 53 and CloudFront
Overview
Domain expertise for configuring Amazon Route 53 to route traffic to Amazon CloudFront distributions using custom domain names. Covers hosted zone management, alias A/AAAA records, alternate domain name (CNAME) configuration, and ACM certificate setup for HTTPS.
Configure Route 53 to route traffic to a CloudFront distribution
To set up a custom domain for a CloudFront distribution with Route 53 DNS, follow the procedure exactly. See Route 53 CloudFront routing procedure.
The procedure covers:
- Verifying CloudFront distribution status and CNAME configuration
- Requesting and validating ACM certificates (must be in us-east-1)
- Creating or locating public hosted zones
- Creating alias A and AAAA records pointing to CloudFront
- Monitoring DNS propagation
Troubleshooting
Domain not in CloudFront CNAMEs
Add the domain as an alternate domain name in the CloudFront distribution configuration before creating Route 53 records.
SSL certificate issues
ACM certificates for CloudFront must be in us-east-1. Ensure the certificate is validated and associated with the distribution.
Private hosted zone
CloudFront only works with public hosted zones. Create a public hosted zone if only a private one exists.
DNS propagation delays
Changes typically propagate within 60 seconds but full global propagation can take up to 48 hours. Use nslookup or dig to verify.
Related skills
More from aws/agent-toolkit-for-aws and the wider catalog.

running-release-tests
Run automated UI and API release tests via AWS DevOps Agent using pre-configured test profiles.

scanning-with-aws-security-agent
Run AWS Security Agent scans on your codebase to find vulnerabilities with ranked findings and remediation guidance.

securing-s3-buckets
Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation.

setting-up-cloudtrail-multi-region
Set up centralized multi-region AWS CloudTrail logging with S3 and CloudWatch integration for security monitoring.

setting-up-cloudwatch-alarm-notifications
Set up encrypted SNS topics and subscriptions for CloudWatch alarm notifications with proper security controls.

setting-up-ec2-instance-profiles
Securely grant EC2 instances AWS service access via IAM roles and instance profiles without hardcoded credentials.