-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathserverless.example.yml
More file actions
117 lines (106 loc) · 3.08 KB
/
Copy pathserverless.example.yml
File metadata and controls
117 lines (106 loc) · 3.08 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
service: test-plugin
plugins:
- ./index.js
- serverless-deployment-bucket
provider:
name: aws
deploymentBucket:
name: sls.tst.teamname.us-east-1.aws.com
blockPublicAccess: true
resources:
Resources:
StaticWebSiteBucket:
Type: 'AWS::S3::Bucket'
DeletionPolicy: Retain
Properties:
AccessControl: Private
BucketName: test-waf-ema
BucketEncryption:
ServerSideEncryptionConfiguration:
- ServerSideEncryptionByDefault:
SSEAlgorithm: AES256
WebsiteConfiguration:
IndexDocument: index.html
ErrorDocument: index.html
PublicAccessBlockConfiguration:
BlockPublicAcls: true
BlockPublicPolicy: true
IgnorePublicAcls: true
RestrictPublicBuckets: true
CloudFrontOriginAccessIdentity:
Type: 'AWS::CloudFront::CloudFrontOriginAccessIdentity'
Properties:
CloudFrontOriginAccessIdentityConfig:
Comment: 'Cloud front access to S3'
WebsiteBucketPolicy:
Type: AWS::S3::BucketPolicy
Properties:
Bucket: !Ref StaticWebSiteBucket
PolicyDocument:
Statement:
-
Sid: "PublicReadGetObject"
Action:
- "s3:GetObject"
Effect: Allow
MyRestApi:
Type: 'AWS::ApiGateway::RestApi'
Properties:
Body:
OpenAPI specification: null
Description: A test API
Name: MyRestAPI
LoadBalancer:
Type: AWS::ElasticLoadBalancingV2::LoadBalancer
Properties:
Subnets: 'dddddd'
LoadBalancerListener:
Type: AWS::ElasticLoadBalancingV2::Listener
Properties:
LoadBalancerArn: !Ref LoadBalancer
Port: 80
Protocol: HTTP
DefaultActions:
- Type: forward
TargetGroupArn: aadasda
DefaultTargetGroup:
Type: AWS::ElasticLoadBalancingV2::TargetGroup
Properties:
Name: ddd-default
VpcId: aaaaaa
Port: 80
Protocol: HTTP
CloudFrontDistribution:
Type: AWS::CloudFront::Distribution
DependsOn:
#- StaticWebSiteBucket
- CloudFrontOriginAccessIdentity
Properties:
DistributionConfig:
DefaultCacheBehavior:
AllowedMethods:
- GET
- HEAD
- OPTIONS
TargetOriginId: "s3-waf-ema"
Compress: true
ForwardedValues:
QueryString: false
Cookies:
Forward: none
ViewerProtocolPolicy: redirect-to-https
Enabled: true
DefaultRootObject: index.html
HttpVersion: "http2"
PriceClass: PriceClass_100
# required for cname field
ViewerCertificate:
CloudFrontDefaultCertificate: 'true'
IPV6Enabled: false
CustomErrorResponses:
- ErrorCode: 404
ResponseCode: 200
ResponsePagePath: /index.html
- ErrorCode: 403
ResponseCode: 200
ResponsePagePath: /index.html