How to configure nginx to only allow requests from cloudfront client?
21:17 20 Sep 2020

I have an server behind nginx, and I have a frontend distributed on AWS cloudfront using AWS Amplify. I'd like requests coming not from my client to be denied at the reverse proxy level. If others think I should do this on the app level, please lmk.

What I've tried so far is to allow all the ips of AWS' cloudfront system (https://ip-ranges.amazonaws.com/ip-ranges.json), and deny all after that. However, my requests from the correct client get blocked.

My other alternative is to do a lookup by IP of the domain for every request, and check against that - but I'd rather not do a DNS lookup every time.

I can also include some kind of token with every request, but come on - there's gotta be some easier way to get this done.

Any ideas?

nginx reverse-proxy