Serverless Image Handler
Serverless Image Handler

Security

When you build systems on AWS infrastructure, security responsibilities are shared between you and AWS. This shared model can reduce your operational burden as AWS operates, manages, and controls the components from the host operating system and virtualization layer down to the physical security of the facilities in which the services operate. For more information about security on AWS, visit the AWS Security Center.

This solution creates Amazon CloudFront and Amazon API Gateway resources that are publicly accessible. Be aware that while this is likely appropriate for publicly facing websites, it may not be appropriate for all customer use cases for this solution. AWS offers several different options for end-to-end security,such as AWS Identity and Access Management (IAM), Amazon Cognito User Pools, AWS Certificate Manager, Amazon CloudFront signed URLs. For private image handling use cases, AWS recommends using signed URLs with Amazon CloudFront and implementing an Amazon API Gateway custom authorizer with Amazon CloudFront to secure your stack.

Demo User Interface

This solution deploys a demo UI as a static website hosted in an Amazon S3 bucket. To help reduce latency and improve security, this solution includes an Amazon CloudFront distribution with an origin access identity, which is a special CloudFront user that helps restrict access to the solution’s website bucket contents. For more information, see Restricting Access to Amazon S3 Content by Using an Origin Access Identity.

On this page: