AWS Security

S3 Security

The S3 bucket will remain private and public access will be blocked.

CloudFront OAC

CloudFront Origin Access Control allows CloudFront to securely access the S3 bucket.

HTTPS

HTTPS will be configured using an SSL/TLS certificate from AWS Certificate Manager.

AWS WAF

AWS WAF will inspect web requests and protect the CloudFront distribution.

IAM

IAM will be used to control access to AWS resources using least privilege.

CloudTrail

CloudTrail will provide an audit trail of AWS API activity.