-
Notifications
You must be signed in to change notification settings - Fork 0
/
serverless.yml
124 lines (115 loc) · 3.41 KB
/
serverless.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
#
# docs.serverless.com
# https://www.serverless.com/framework/docs/providers/aws/guide/serverless.yml/
#
service: brickage-service
useDotenv: true
projectDir: ./
frameworkVersion: "2"
provider:
name: aws
profile: default
region: ${env:REGION}
runtime: nodejs14.x
lambdaHashingVersion: 20201221
deploymentBucket:
blockPublicAccess: true
plugins:
- serverless-finch
- serverless-single-page-app-plugin
custom:
client:
distributionFolder: ./dist/app
bucketName: ${env:BUCKET_NAME}
indexDocument: index.html
region: ${env:REGION}
uploadOrder:
- .*
- index\.html
manageResources: true
s3LocalPath: ${self:custom.client.distributionFolder}/
s3BucketName: ${self:custom.client.bucketName}
resources:
Resources:
WebAppS3Bucket:
Type: AWS::S3::Bucket
Properties:
BucketName: ${self:custom.s3BucketName}
AccessControl: PublicRead
WebsiteConfiguration:
IndexDocument: index.html
ErrorDocument: index.html
VersioningConfiguration:
Status: Enabled
WebAppS3BucketPolicy:
Type: AWS::S3::BucketPolicy
Properties:
Bucket:
Ref: WebAppS3Bucket
PolicyDocument:
Statement:
- Sid: "AllowCloudFrontAccessIdentity"
Effect: Allow
Action: s3:GetObject
Resource: arn:aws:s3:::${self:custom.s3BucketName}/*
Principal:
AWS:
Fn::Join:
- " "
- - "arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity"
- !Ref OriginAccessIdentity
OriginAccessIdentity:
Type: AWS::CloudFront::CloudFrontOriginAccessIdentity
Properties:
CloudFrontOriginAccessIdentityConfig:
Comment: Access identity between CloudFront and S3 bucket
WebAppCloudFrontDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
Origins:
- DomainName: ${self:custom.s3BucketName}.s3.amazonaws.com
Id: ${env.ORIGIN_ID}
S3OriginConfig:
OriginAccessIdentity: !Sub origin-access-identity/cloudfront/${OriginAccessIdentity}
Enabled: true
DefaultRootObject: index.html
CustomErrorResponses:
- ErrorCode: 404
ResponseCode: 200
ResponsePagePath: /index.html
DefaultCacheBehavior:
AllowedMethods:
- DELETE
- GET
- HEAD
- OPTIONS
- PATCH
- POST
- PUT
CachedMethods:
- GET
- HEAD
- OPTIONS
ForwardedValues:
Headers:
- Access-Control-Request-Headers
- Access-Control-Request-Method
- Origin
- Authorization
QueryString: "false"
Cookies:
Forward: none
TargetOriginId: ${env.ORIGIN_ID}
ViewerProtocolPolicy: redirect-to-https
Compress: true
DefaultTTL: 0
ViewerCertificate:
CloudFrontDefaultCertificate: "true"
Outputs:
WebAppS3BucketOutput:
Value:
"Ref": WebAppS3Bucket
WebAppCloudFrontDistributionOutput:
Value:
"Fn::GetAtt": [WebAppCloudFrontDistribution, DomainName]