Skip to content

fix(cloudfront): serve S3 REST origins from the local process - #2559

Open
Sorttech wants to merge 1 commit into
faiscadev:mainfrom
Sorttech:fix/cloudfront-s3-origin-resolution
Open

Sorttech wants to merge 1 commit into
faiscadev:mainfrom
Sorttech:fix/cloudfront-s3-origin-resolution

Conversation

@Sorttech

@Sorttech Sorttech commented Sep 25, 2026 •

Copy link
Copy Markdown

An origin whose domain is a bucket REST endpoint
(<bucket>.s3.<region>.amazonaws.com -- what S3OriginConfig origins and
CDK's S3BucketOrigin carry) resolves in real DNS, so the data plane
proxied the fetch to real AWS S3 and the distribution never served the
bucket. Route it to this process like an S3-website origin, keeping the
bucket domain in Host so the S3 front door resolves it virtual-hosted
style. An explicit CustomOriginConfig still wins.

Test plan

Regression test: serves_static_from_s3_rest_origin in crates/fakecloud-e2e/tests/cloudfront_dataplane.rs

Verification

On this exact head, rebased onto current main:

  • cargo fmt --all --check - clean.
  • cargo clippy --workspace --all-targets -- -D warnings - clean.
  • cargo test --workspace excluding fakecloud-e2e, fakecloud-conformance,
    fakecloud-tfacc and fakecloud-parity (the same set CI's test job runs),
    plus cargo test -p fakecloud-conformance --lib - 9931 passed, 0 failed.
  • cargo test -p fakecloud-e2e --test cloudfront_dataplane - the regression
    test above passes against a freshly built target/debug/fakecloud.

Found by deploying a CDK CloudFront + S3 SPA against fakecloud.


Summary by cubic

Fixes CloudFront data plane routing for S3 REST origins so the bucket is served from the local process instead of being proxied to real AWS S3.

Origins with a bucket REST domain (<bucket>.s3.<region>.amazonaws.com, what S3OriginConfig and CDK's S3BucketOrigin carry) resolve in real DNS, so the fetch went to AWS and the distribution never served the bucket. These now route to the local S3 front door like S3-website origins, keeping the bucket domain in Host. An explicit CustomOriginConfig still wins.

Adds serves_static_from_s3_rest_origin to crates/fakecloud-e2e/tests/cloudfront_dataplane.rs as a regression test.

Written for commit 0455356. Summary will update on new commits.

Review in cubic

An origin whose domain is a bucket REST endpoint
(`<bucket>.s3.<region>.amazonaws.com` -- what `S3OriginConfig` origins and
CDK's `S3BucketOrigin` carry) resolves in real DNS, so the data plane
proxied the fetch to real AWS S3 and the distribution never served the
bucket. Route it to this process like an S3-website origin, keeping the
bucket domain in `Host` so the S3 front door resolves it virtual-hosted
style. An explicit `CustomOriginConfig` still wins.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant