routing-traffic-with-route53-and-cloudfront
aws/agent-toolkit-for-aws
How to install routing-traffic-with-route53-and-cloudfront
npx skills add https://github.com/aws/agent-toolkit-for-aws --skill routing-traffic-with-route53-and-cloudfrontFull instructions (SKILL.md)
Source of truth, from aws/agent-toolkit-for-aws.
name: routing-traffic-with-route53-and-cloudfront description: Configures Amazon Route 53 to route traffic to a CloudFront distribution using a custom domain. Use when setting up DNS alias records, alternate domain names (CNAMEs), ACM certificates for HTTPS, and IPv6 support for CloudFront. version: 1
Routing Traffic with Route 53 and CloudFront
Overview
Domain expertise for configuring Amazon Route 53 to route traffic to Amazon CloudFront distributions using custom domain names. Covers hosted zone management, alias A/AAAA records, alternate domain name (CNAME) configuration, and ACM certificate setup for HTTPS.
Configure Route 53 to route traffic to a CloudFront distribution
To set up a custom domain for a CloudFront distribution with Route 53 DNS, follow the procedure exactly. See Route 53 CloudFront routing procedure.
The procedure covers:
- Verifying CloudFront distribution status and CNAME configuration
- Requesting and validating ACM certificates (must be in us-east-1)
- Creating or locating public hosted zones
- Creating alias A and AAAA records pointing to CloudFront
- Monitoring DNS propagation
Troubleshooting
Domain not in CloudFront CNAMEs
Add the domain as an alternate domain name in the CloudFront distribution configuration before creating Route 53 records.
SSL certificate issues
ACM certificates for CloudFront must be in us-east-1. Ensure the certificate is validated and associated with the distribution.
Private hosted zone
CloudFront only works with public hosted zones. Create a public hosted zone if only a private one exists.
DNS propagation delays
Changes typically propagate within 60 seconds but full global propagation can take up to 48 hours. Use nslookup or dig to verify.
Related skills
More from aws/agent-toolkit-for-aws and the wider catalog.

securing-s3-buckets
Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation.

setting-up-cloudtrail-multi-region
Enables a multi-region AWS CloudTrail trail with S3 log storage, CloudWatch Logs integration, and CloudWatch Logs Insights queries for security monitoring and compliance auditing. Use when setting up centralized API activity logging across all AWS regions.

setting-up-cloudwatch-alarm-notifications
Set up encrypted SNS topics and subscriptions for CloudWatch alarm notifications with proper security controls.

setting-up-ec2-instance-profiles
Configures EC2 instances to securely call AWS services by creating and attaching IAM roles via instance profiles, eliminating hardcoded credentials. Use when an EC2 instance needs permissions to access AWS services like S3, DynamoDB, SQS, or CloudWatch through temporary credentials.

storing-and-querying-vectors
Cost-effective vector storage and semantic search with Amazon S3 Vectors

troubleshooting-application-failures
Diagnose application failures by analyzing CloudWatch logs for error patterns and root causes.