Abstract
Terraform AWS Cloudfront S3 Cdn is an open-source Blockchain & Cloud Computing project. Terraform module to easily provision CloudFront CDN backed by an S3 origin. Terraform module to provision an AWS CloudFront CDN with an S3 origin. It is built using HCL, Terraform, AWS. The complete source code is publicly available on GitHub under the Apache License 2.0, making it a useful reference for students building a Blockchain & Cloud Computing mini project or final-year project.
1. Introduction
Terraform module to provision an AWS CloudFront CDN with an S3 origin.
There are some settings you need to be aware of when using this module. In order to understand the settings, you need to understand some of the basics of CDNs and web servers, so we are providing this _highly simplified_ explanation of how they work in order for you to understand the implications of the settings you are providing.
A "CDN" (Content Distribution Network) is a collection of servers scattered around the internet with the aim of making it faster for people to retrieve content from a website. The details of why that is wanted/needed are beyond the scope of this document, as are most of the details of how a CDN is implemented. For this discussion, we will simply treat a CDN as a set of web servers all serving the same content to different users.
2. Objective
Terraform module to easily provision CloudFront CDN backed by an S3 origin
This project demonstrates how HCL, Terraform, AWS can be applied to a real-world Blockchain & Cloud Computing problem.
4. Technology Stack
5. System Requirements
General requirements for this technology stack — check the README for exact versions.
- Terraform CLI
- Cloud provider account (e.g. AWS) with CLI configured
- Git (to clone the repository)
6. Installation & Setup
git clone https://github.com/cloudposse/terraform-aws-cloudfront-s3-cdn.git
cd terraform-aws-cloudfront-s3-cdnmodule "cdn" {
source = "cloudposse/cloudfront-s3-cdn/aws"
# Cloud Posse recommends pinning every module to a specific version
# version = "x.x.x"
namespace = "eg"
stage = "prod"
name = "app"
aliases = ["assets.cloudposse.com"]
dns_alias_enabled = true
parent_zone_name = "cloudposse.com"
deployment_principal_arns = {
"arn:aws:iam::123456789012:role/principal1" = ["prefix1/", "prefix2/"]
"arn:aws:iam::123456789012:role/principal2" = [""]
}
}module "cdn" {
source = "cloudposse/cloudfront-s3-cdn/aws"
# Cloud Posse recommends pinning every module to a specific version
# version = "x.x.x"
origin_bucket = "eg-prod-app"
aliases = ["assets.cloudposse.com"]
dns_alias_enabled = true
parent_zone_name = "cloudposse.com"
name = "eg-prod-app"
}module "s3_bucket" {
source = "cloudposse/s3-bucket/aws"
# Cloud Posse recommends pinning every module to a specific version
# version = "x.x.x"
attributes = ["failover-assets"]
}
module "cdn" {
source = "cloudposse/cloudfront-s3-cdn/aws"
# Cloud Posse recommends pinning every module to a specific version
# version = "x.x.x"
aliases = ["assets.cloudposse.com"]
dns_alias_enabled = true
parent_zone_name = "cloudposse.com"
s3_origins = [{
domain_name = module.s3_bucket.bucket_regional_domain_name
origin_id = module.s3_bucket.bucket_id
origin_path = null
s3_origin_config = {
origin_access_identity = null # will get translated to the origin_access_identity used by the origin created by this module.
}
}]
origin_groups = [{
primary_origin_id = null # will get translated to the origin id of the origin created by this module.
failover_origin_id = module.s3_bucket.bucket_id
failover_criteria = [
403,
404,
500,
502
]
}]
}Full setup instructions are in the project README.
7. Future Enhancements
Suggested extensions you can add to make this your own project.
- Add a CI/CD pipeline with GitHub Actions
- Deploy to a public test network or cloud free tier
- Add monitoring and cost alerts
8. Viva / Review Questions
Common questions examiners ask for projects in this domain.
- Why does this problem need a blockchain or cloud-native design?
- Explain the smart contract / infrastructure components and how they interact.
- How are gas costs or cloud costs kept under control?
- How is the system secured (keys, IAM, access control)?
- How would the solution scale to many more users?
9. Source Code & License
This project is developed by cloudposse and published on GitHub under the Apache License 2.0. Please follow the license terms and credit the original author when you use or modify this code.
Want to build this as your internship project?
Work on a Blockchain & Cloud Computing project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.
Apply for Blockchain & Cloud Computing Internship