New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Enhancement]: Add lambda
and mediapackagev2
options for origin_access_control_origin_type
to aws_cloudfront_origin_access_control
#36660
Comments
Community NoteVoting for Prioritization
Volunteering to Work on This Issue
|
Interestingly, other official documentation is also missing the
Furthermore, the AWS Console does not seem to allow the creation of an OAC for custom or lambda function domains either. But the AWS CLI is happy to create one: $ aws cloudfront create-origin-access-control --origin-access-control-config "Name=oac,SigningProtocol=sigv4,SigningBehavior=always,OriginAccessControlOriginType=lambda" {
"Location": "https://cloudfront.amazonaws.com/2020-05-31/origin-access-control/XXXXXXXXXXXXX",
"ETag": "XXXXXXXXXXXXX",
"OriginAccessControl": {
"Id": "XXXXXXXXXXXXX",
"OriginAccessControlConfig": {
"Name": "oac",
"SigningProtocol": "sigv4",
"SigningBehavior": "always",
"OriginAccessControlOriginType": "lambda"
}
}
} This change is reflected in the AWS Console too: Manually updating the CloudFront Distribution to associate the OAC with the origin also works successfully, per the documentation here: https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-restricting-access-to-s3.html |
Did a quick check and looks like v1 cloudfront doesn't have those listed... but the AWS module isn't doing any validation on the string during creation. Ran a test without terraform validation and was able to get it to work. I can make this update. // Cloudfront V1 api.go
type OriginAccessControlConfig struct {
OriginAccessControlOriginType *string `type:"string" required:"true" enum:"OriginAccessControlOriginTypes"`
...
}
...
const (
// OriginAccessControlOriginTypesS3 is a OriginAccessControlOriginTypes enum value
OriginAccessControlOriginTypesS3 = "s3"
// OriginAccessControlOriginTypesMediastore is a OriginAccessControlOriginTypes enum value
OriginAccessControlOriginTypesMediastore = "mediastore"
)
// OriginAccessControlOriginTypes_Values returns all elements of the OriginAccessControlOriginTypes enum
func OriginAccessControlOriginTypes_Values() []string {
return []string{
OriginAccessControlOriginTypesS3,
OriginAccessControlOriginTypesMediastore,
}
} |
Warning This issue has been closed, meaning that any additional comments are hard for our team to see. Please assume that the maintainers will not see them. Ongoing conversations amongst community members are welcome, however, the issue will be locked after 30 days. Moving conversations to another venue, such as the AWS Provider forum, is recommended. If you have additional concerns, please open a new issue, referencing this one where needed. |
This functionality has been released in v5.46.0 of the Terraform AWS Provider. Please see the Terraform documentation on provider versioning or reach out if you need any assistance upgrading. For further feature requests or bug reports with this functionality, please create a new GitHub issue following the template. Thank you! |
I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues. |
Description
The
aws_cloudfront_origin_access_control
resource has argumentorigin_access_control_origin_type
with valid optionss3
andmediastore
. However,lambda
andmediapackagev2
should also be allowed.https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-cloudfront-originaccesscontrol-originaccesscontrolconfig.html
Affected Resource(s) and/or Data Source(s)
Potential Terraform Configuration
References
https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-cloudfront-originaccesscontrol-originaccesscontrolconfig.html
Would you like to implement a fix?
No
The text was updated successfully, but these errors were encountered: