> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tensor9.com/llms.txt
> Use this file to discover all available pages before exploring further.

# CloudFront

> AWS CloudFront. Caches origin responses at edge locations worldwide, terminating TLS and routing URL paths to different origins through cache behaviors.

**On this page**

* [Coverage by target cloud](#coverage-by-target-cloud)
* [How the targets compare](#how-the-targets-compare)
  * [Infrastructure-only adaptation](#infrastructure-only-adaptation)
* [On Google Cloud](#on-google-cloud)
* [On Azure](#on-azure)
  * [Via Azure Front Door Premium](#via-azure-front-door-premium)
  * [Via Azure Front Door Standard](#via-azure-front-door-standard)

## Coverage by target cloud

| Target             | Available |
| ------------------ | --------- |
| Google Cloud       | ✓         |
| Azure              | ✓         |
| OCI                | -         |
| Private Kubernetes | -         |

## How the targets compare

Each row compares a capability of CloudFront with its adaptation on each target.
A dash means this row is not stated for that target.

### Infrastructure-only adaptation

| Capability                                                    | CloudFront                                                 | Google Cloud                                                                                                                       | Azure · Azure Front Door Premium                                                                                                   | Azure · Azure Front Door Standard                                                                                                 |
| ------------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| Edge network · who serves the traffic                         | CloudFront's global PoPs                                   | Google Cloud CDN on the external load balancer                                                                                     | Azure Front Door's global edge                                                                                                     | Azure Front Door Standard's global edge                                                                                           |
| Origins · origin domains → backend                            | Yes - multiple origins + origin groups with failover       | Partial - first HTTP backend service or bucket backend; additional origins and groups are reported                                 | Partial - origin-group members selected by health probes                                                                           | Partial - origin-group members selected by health probes; public endpoints required                                               |
| Cache behaviors · paths, TTLs, cache key                      | Yes - path patterns, per-behavior TTLs, cache key, methods | Partial - backend cache policy with default/max/client TTLs, negative caching and cache keys; header/method differences remain     | Partial - path rules with one cache duration and query-string behavior; separate min/max TTL and header/method differences remain  | Partial - path rules with one cache duration and query-string behavior; separate min/max TTL and header/method differences remain |
| Compression · automatic gzip/brotli                           | Yes - automatic edge compression                           | Yes - the backend's compression mode                                                                                               | Yes - the route's compression setting                                                                                              | Yes - the route's compression setting                                                                                             |
| HTTPS redirect · viewer protocol policy                       | Yes - redirect-to-https / https-only                       | Yes - a url\_map HTTPS redirect rule                                                                                               | Yes - the route's HTTPS-redirect setting                                                                                           | Yes - the route's HTTPS-redirect setting                                                                                          |
| Custom domains + TLS · aliases + certificate                  | Yes - alternate domain names + ACM viewer certificate      | Partial - target-managed certificate after domain validation; ACM material and TLS settings require review                         | Partial - target-managed certificate after domain validation; ACM material and TLS settings require review                         | Partial - target-managed certificate after domain validation; ACM material and TLS settings require review                        |
| WAF / geo restrictions · web ACL + geo                        | Yes - AWS WAF web ACL + geo restrictions                   | No - Cloud Armor configured separately; no automatic AWS web ACL or geo translation                                                | Partial - custom match, rate-limit and country rules; Microsoft-managed rule selection differs from AWS groups                     | Partial - custom match, rate-limit and country rules; managed rules and bot protection require Premium                            |
| Origin access & signed URLs · origin and viewer authorization | Yes - OAI / OAC + trusted-signer signed URLs               | Partial - Cloud CDN signed URLs require a new HMAC signer; private bucket access or HTTP-origin controls are configured separately | Partial - approved Private Link access to supported origins; viewer signed-URL verification requires a separate application design | Partial - public origin with separate access controls; no Private Link or CloudFront viewer-signature verification                |
| Edge functions · Lambda\@Edge / Functions                     | Yes - Lambda\@Edge + CloudFront Functions                  | No - no function runtime; unsupported associations reported and standalone functions rejected                                      | No - rule conditions and actions; no arbitrary function runtime                                                                    | Partial - header, URL and redirect rules; no arbitrary function runtime                                                           |
| API coverage                                                  | full                                                       | high                                                                                                                               | high                                                                                                                               | high                                                                                                                              |

## On Google Cloud

| Operation                                                                                                | Area             | Support      | Depth        | Notes                                                                                                                                                                                                                                     |
| -------------------------------------------------------------------------------------------------------- | ---------------- | ------------ | ------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Origin access (OAI / OAC)                                                                                | Access control   | Partial      | Most usage   | configure private bucket IAM or the HTTP origin's access controls separately. Attaching a backend to the load balancer does not prevent direct access. An origin access identity without a supported translation causes a build error     |
| Signed URLs                                                                                              | Access control   | Partial      | Most usage   | Cloud CDN uses HMAC signed URLs and cookies. Replace the CloudFront RSA/ECDSA signer and issue new URLs; configure origin access separately.                                                                                              |
| WAF & geo restrictions                                                                                   | Access control   | Out of scope | Most usage   | Automatic WAF/geo translation is outside this mapping. Configure Cloud Armor separately; backend buckets support a narrower edge security policy than backend services.                                                                   |
| Cache behaviors                                                                                          | Cache            | Partial      | Most usage   | Backend cdn\_policy retains cache mode, default/max/client TTLs, negative caching and cache-key settings. URL-map matches select paths; per-behavior header forwarding and method differences are reported.                               |
| Content delivery                                                                                         | Content delivery | Supported    | Common       | served on Google Cloud CDN: enable\_cdn = true plus a cdn\_policy on the external load balancer's backend inside your Google Cloud project; the load balancer fronts it with a URL map, HTTPS proxy, and forwarding rule                  |
| DNS cutover                                                                                              | Content delivery | Supported    | Common       | Supported Route 53 aliases point to the target frontend. CloudFront domain\_name, arn and hosted\_zone\_id are not target identifiers; unsupported output references are removed and active configuration references cause a build error. |
| Custom domains + TLS                                                                                     | Domains & TLS    | Partial      | Most usage   | Custom domains use target-managed certificates. Complete domain validation before cutover; an ACM ARN supplies no certificate material. Minimum TLS-version and SSL support-method differences are reported.                              |
| Edge logic (Lambda\@Edge / CloudFront Functions)                                                         | Edge logic       | Out of scope | Most usage   | Cloud CDN does not run Lambda\@Edge or CloudFront Functions code. Unsupported associations are omitted and reported; standalone functions cause a build error.                                                                            |
| Policy & monitoring facets (cache / origin-request / response-headers policies, monitoring subscription) | Facets           | Out of scope | Full surface | these resources are not supported by this mapping; the build reports an error                                                                                                                                                             |
| Origins                                                                                                  | Origins          | Partial      | Common       | The first HTTP origin becomes a backend service; a bucket origin becomes a backend bucket. Confirm unresolved origin addresses. Additional origins and origin groups are omitted and reported.                                            |

#### How it works

Tensor9 translates the CloudFront distribution into a Google external Application Load Balancer with Cloud CDN enabled on its backend. A forwarding rule supplies the public address, an HTTPS proxy terminates TLS, and a URL map selects the backend. Google operates the cache and serves requests; Tensor9 provisions the resources in the customer's project.

A custom DNS name can remain in use after its record points to the new frontend and its certificate is ready. The CloudFront-generated hostname and existing cached objects do not move to Google. Plan for cache misses during cutover.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTUwIiB2aWV3Qm94PSIwIDAgODM2IDE1MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJSZXF1ZXN0cyBwYXNzIHRocm91Z2ggdGhlIEdvb2dsZSBsb2FkIGJhbGFuY2VyIGFuZCBjYWNoZSB0byB0aGUgc2VsZWN0ZWQgb3JpZ2luLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPjxyZWN0IHg9IjI0IiB5PSI0MCIgd2lkdGg9IjI0MCIgaGVpZ2h0PSI4MCIgcng9IjEwIiBmaWxsPSIjZjhmYWZjIiBzdHJva2U9IiM2NDc0OGIiLz48dGV4dCB4PSIxNDQiIHk9IjcwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+Q3VzdG9tZXIgcmVxdWVzdDwvdGV4dD48dGV4dCB4PSIxNDQiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+Y3VzdG9tIGRvbWFpbjwvdGV4dD48cGF0aCBkPSJNMjY2LDgwIGgyMiBsLTYsLTUgbTYsNSBsLTYsNSIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjIiLz48cmVjdCB4PSIyOTQiIHk9IjQwIiB3aWR0aD0iMjQwIiBoZWlnaHQ9IjgwIiByeD0iMTAiIGZpbGw9IiNmOGZhZmMiIHN0cm9rZT0iIzY0NzQ4YiIvPjx0ZXh0IHg9IjQxNCIgeT0iNzAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5Hb29nbGUgbG9hZCBiYWxhbmNlcjwvdGV4dD48dGV4dCB4PSI0MTQiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+VVJMIG1hcCArIENsb3VkIENETjwvdGV4dD48cGF0aCBkPSJNNTM2LDgwIGgyMiBsLTYsLTUgbTYsNSBsLTYsNSIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjIiLz48cmVjdCB4PSI1NjQiIHk9IjQwIiB3aWR0aD0iMjQwIiBoZWlnaHQ9IjgwIiByeD0iMTAiIGZpbGw9IiNmOGZhZmMiIHN0cm9rZT0iIzY0NzQ4YiIvPjx0ZXh0IHg9IjY4NCIgeT0iNzAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5PcmlnaW48L3RleHQ+PHRleHQgeD0iNjg0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmJ1Y2tldCBvciBIVFRQIGJhY2tlbmQ8L3RleHQ+PC9zdmc+" alt="Requests pass through the Google load balancer and cache to the selected origin." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTUwIiB2aWV3Qm94PSIwIDAgODM2IDE1MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJSZXF1ZXN0cyBwYXNzIHRocm91Z2ggdGhlIEdvb2dsZSBsb2FkIGJhbGFuY2VyIGFuZCBjYWNoZSB0byB0aGUgc2VsZWN0ZWQgb3JpZ2luLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPjxyZWN0IHg9IjI0IiB5PSI0MCIgd2lkdGg9IjI0MCIgaGVpZ2h0PSI4MCIgcng9IjEwIiBmaWxsPSIjMWEyNjMxIiBzdHJva2U9IiM2NDc0OGIiLz48dGV4dCB4PSIxNDQiIHk9IjcwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+Q3VzdG9tZXIgcmVxdWVzdDwvdGV4dD48dGV4dCB4PSIxNDQiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+Y3VzdG9tIGRvbWFpbjwvdGV4dD48cGF0aCBkPSJNMjY2LDgwIGgyMiBsLTYsLTUgbTYsNSBsLTYsNSIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjIiLz48cmVjdCB4PSIyOTQiIHk9IjQwIiB3aWR0aD0iMjQwIiBoZWlnaHQ9IjgwIiByeD0iMTAiIGZpbGw9IiMxYTI2MzEiIHN0cm9rZT0iIzY0NzQ4YiIvPjx0ZXh0IHg9IjQxNCIgeT0iNzAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5Hb29nbGUgbG9hZCBiYWxhbmNlcjwvdGV4dD48dGV4dCB4PSI0MTQiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+VVJMIG1hcCArIENsb3VkIENETjwvdGV4dD48cGF0aCBkPSJNNTM2LDgwIGgyMiBsLTYsLTUgbTYsNSBsLTYsNSIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjIiLz48cmVjdCB4PSI1NjQiIHk9IjQwIiB3aWR0aD0iMjQwIiBoZWlnaHQ9IjgwIiByeD0iMTAiIGZpbGw9IiMxYTI2MzEiIHN0cm9rZT0iIzY0NzQ4YiIvPjx0ZXh0IHg9IjY4NCIgeT0iNzAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5PcmlnaW48L3RleHQ+PHRleHQgeD0iNjg0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmJ1Y2tldCBvciBIVFRQIGJhY2tlbmQ8L3RleHQ+PC9zdmc+" alt="Requests pass through the Google load balancer and cache to the selected origin." />
</div>

#### Origins and cache configuration

A bucket origin uses a CDN-enabled backend bucket; a custom HTTP origin uses a backend service. Confirm any origin address that compilation cannot resolve. This mapping selects the first origin; additional origins and CloudFront origin-group failover require separate configuration and are reported during compilation.

Supported path behaviors become URL-map matchers. Each backend has a `cdn_policy` for cache mode, default, maximum and client TTLs, negative caching, and the cache key's host, path and query settings. Behaviors sharing a backend also share its cache policy. Check whether the source needs different policies for those paths.

The origin-headers cache mode respects the origin's `Cache-Control` instructions. For example, a policy might set default and client TTLs to 3600 seconds, a maximum of 86400 seconds, and cache a 404 response for 120 seconds; these are illustrative settings, not promised deployment defaults. Per-behavior forwarded-header lists and allowed-method lists are not fully preserved. Review the reported differences before caching authenticated or user-specific responses.

#### Origin connectivity and access

The load balancer's backend configuration identifies where requests go; being in the same project does not make an origin reachable or private. Configure the network path, firewall rules, DNS, and backend access for the selected origin type. A custom origin can be outside the project and may need additional connectivity.

CloudFront origin access control authenticates requests to supported origins; it is distinct from a private network connection. On Google, private bucket access uses the appropriate bucket IAM grant. An HTTP origin needs its own controls to reject direct or unauthorized requests. Attaching a backend to a load balancer does not, by itself, make that load balancer the only way to reach it.

Provisioning uses the deployment's Google identity. Limit that identity's resource permissions separately from the access rules governing viewer and origin requests.

#### Signed URLs and cookies

CloudFront signed URLs and cookies use a public/private key pair: RSA or ECDSA. Cloud CDN uses a shared HMAC signing key. Update the application that issues signed URLs to use the Cloud CDN format and key; previously issued CloudFront signatures will not validate there.

Viewer authorization and origin protection are separate. Configure private bucket access where applicable. For an HTTP origin, follow Google's requirements to validate signed requests and decide whether to reject unsigned requests. Adding a signing key alone does not make every path private.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTUwIiB2aWV3Qm94PSIwIDAgODM2IDE1MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJUaGUgYXBwbGljYXRpb24gc2lnbnMgYSBDbG91ZCBDRE4gcmVxdWVzdDsgdGhlIGVkZ2UgdmFsaWRhdGVzIGl0LCB3aGlsZSBvcmlnaW4gYWNjZXNzIHJlcXVpcmVzIHNlcGFyYXRlIGNvbnRyb2xzLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPjxyZWN0IHg9IjI0IiB5PSI0MCIgd2lkdGg9IjI0MCIgaGVpZ2h0PSI4MCIgcng9IjEwIiBmaWxsPSIjZjhmYWZjIiBzdHJva2U9IiM2NDc0OGIiLz48dGV4dCB4PSIxNDQiIHk9IjcwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+QXBwbGljYXRpb24gc2lnbmVyPC90ZXh0Pjx0ZXh0IHg9IjE0NCIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5DbG91ZCBDRE4gSE1BQyBrZXk8L3RleHQ+PHBhdGggZD0iTTI2Niw4MCBoMjIgbC02LC01IG02LDUgbC02LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+PHJlY3QgeD0iMjk0IiB5PSI0MCIgd2lkdGg9IjI0MCIgaGVpZ2h0PSI4MCIgcng9IjEwIiBmaWxsPSIjZjhmYWZjIiBzdHJva2U9IiM2NDc0OGIiLz48dGV4dCB4PSI0MTQiIHk9IjcwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+Q2xvdWQgQ0ROPC90ZXh0Pjx0ZXh0IHg9IjQxNCIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj52YWxpZGF0ZXMgc2lnbmVkIHJlcXVlc3Q8L3RleHQ+PHBhdGggZD0iTTUzNiw4MCBoMjIgbC02LC01IG02LDUgbC02LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+PHJlY3QgeD0iNTY0IiB5PSI0MCIgd2lkdGg9IjI0MCIgaGVpZ2h0PSI4MCIgcng9IjEwIiBmaWxsPSIjZjhmYWZjIiBzdHJva2U9IiM2NDc0OGIiLz48dGV4dCB4PSI2ODQiIHk9IjcwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+UHJvdGVjdGVkIG9yaWdpbjwvdGV4dD48dGV4dCB4PSI2ODQiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+c2VwYXJhdGUgYWNjZXNzIGNvbnRyb2xzPC90ZXh0Pjwvc3ZnPg==" alt="The application signs a Cloud CDN request; the edge validates it, while origin access requires separate controls." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTUwIiB2aWV3Qm94PSIwIDAgODM2IDE1MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJUaGUgYXBwbGljYXRpb24gc2lnbnMgYSBDbG91ZCBDRE4gcmVxdWVzdDsgdGhlIGVkZ2UgdmFsaWRhdGVzIGl0LCB3aGlsZSBvcmlnaW4gYWNjZXNzIHJlcXVpcmVzIHNlcGFyYXRlIGNvbnRyb2xzLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPjxyZWN0IHg9IjI0IiB5PSI0MCIgd2lkdGg9IjI0MCIgaGVpZ2h0PSI4MCIgcng9IjEwIiBmaWxsPSIjMWEyNjMxIiBzdHJva2U9IiM2NDc0OGIiLz48dGV4dCB4PSIxNDQiIHk9IjcwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+QXBwbGljYXRpb24gc2lnbmVyPC90ZXh0Pjx0ZXh0IHg9IjE0NCIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5DbG91ZCBDRE4gSE1BQyBrZXk8L3RleHQ+PHBhdGggZD0iTTI2Niw4MCBoMjIgbC02LC01IG02LDUgbC02LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+PHJlY3QgeD0iMjk0IiB5PSI0MCIgd2lkdGg9IjI0MCIgaGVpZ2h0PSI4MCIgcng9IjEwIiBmaWxsPSIjMWEyNjMxIiBzdHJva2U9IiM2NDc0OGIiLz48dGV4dCB4PSI0MTQiIHk9IjcwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+Q2xvdWQgQ0ROPC90ZXh0Pjx0ZXh0IHg9IjQxNCIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij52YWxpZGF0ZXMgc2lnbmVkIHJlcXVlc3Q8L3RleHQ+PHBhdGggZD0iTTUzNiw4MCBoMjIgbC02LC01IG02LDUgbC02LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+PHJlY3QgeD0iNTY0IiB5PSI0MCIgd2lkdGg9IjI0MCIgaGVpZ2h0PSI4MCIgcng9IjEwIiBmaWxsPSIjMWEyNjMxIiBzdHJva2U9IiM2NDc0OGIiLz48dGV4dCB4PSI2ODQiIHk9IjcwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+UHJvdGVjdGVkIG9yaWdpbjwvdGV4dD48dGV4dCB4PSI2ODQiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+c2VwYXJhdGUgYWNjZXNzIGNvbnRyb2xzPC90ZXh0Pjwvc3ZnPg==" alt="The application signs a Cloud CDN request; the edge validates it, while origin access requires separate controls." />
</div>

#### Web application firewall

This distribution mapping does not automatically translate the AWS web ACL or geographic restrictions. Configure Google Cloud Armor separately if those controls are required.

A backend security policy supports managed WAF rules, custom rules and rate controls on a backend service. A backend bucket supports the narrower edge security policy, which does not provide the same managed-rule and rate-limiting features. Choose the policy type for the selected backend and test both allowed and blocked requests.

#### Edge functions and encryption

Cloud CDN does not execute Lambda\@Edge or CloudFront Functions code. Move application code to a suitable runtime and reconnect the request flow when that behavior is required. The translation reports omitted function associations; a standalone CloudFront function without a supported translation causes a build error.

CloudFront field-level encryption encrypts selected request fields at the edge. It is a separate feature, not a customer function runtime, and this mapping does not reproduce it.

#### Custom domains, TLS and cutover

Each supported alias receives a Google-managed certificate on the HTTPS proxy. Validate domain ownership and wait for certificate readiness before changing DNS. An ACM reference does not supply certificate material; the source minimum TLS version and SSL support method are not copied field for field. Verify the target TLS policy.

Supported Route 53 aliases are updated to the Google frontend address. CloudFront `domain_name`, `arn`, and `hosted_zone_id` are not native Google identifiers. References without a target equivalent are removed from outputs or rejected in active configuration; review consumers outside the translated stack.

#### Operations and remaining limits

Google's edge locations replace CloudFront's price-class selection. Configure Cloud Logging and Cloud Monitoring for the target; AWS access-log and additional-metrics settings are not copied as distribution attributes. Monitor cache hits, origin requests and errors after cutover.

Standalone cache, origin-request, response-headers policy, monitoring-subscription, or origin-access-identity resources that have no supported attachment cannot be translated. Review those resources and the per-behavior differences with the distribution before deployment.

Provider references: [content access control](https://docs.cloud.google.com/cdn/docs/authenticate-content) and [signed URLs](https://docs.cloud.google.com/cdn/docs/using-signed-urls).

## On Azure

### Via Azure Front Door Premium

| Operation                                                                                                | Area             | Support      | Depth        | Notes                                                                                                                                                                                                                                                    |
| -------------------------------------------------------------------------------------------------------- | ---------------- | ------------ | ------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Origin access (OAI / OAC)                                                                                | Access control   | Partial      | Most usage   | Premium can connect to a supported origin through an approved Private Link endpoint. Configure the compatible origin and close unwanted alternate access paths. A standalone origin access identity without a supported translation causes a build error |
| Signed URLs & trusted keys                                                                               | Access control   | Out of scope | Most usage   | CloudFront signed URLs and signed cookies use RSA or ECDSA signatures that Front Door cannot verify; it is a different request authorization scheme, out of this option's scope and flagged during the build                                             |
| WAF & geo restrictions                                                                                   | Access control   | Partial      | Most usage   | Custom match, rate-limit and country rules become target WAF rules attached through a security policy. Premium supports Microsoft-managed rules and bot protection; AWS managed groups require target-specific rule selection.                           |
| Cache behaviors                                                                                          | Cache            | Partial      | Most usage   | Path-matched rules retain cache duration and query-string behavior. CloudFront default TTL supplies a single duration; separate minimum/maximum constraints and per-behavior header/method differences are reported.                                     |
| Content delivery                                                                                         | Content delivery | Supported    | Common       | served on Azure Front Door: Tensor9 provisions a Front Door profile and endpoint that front your origin, with an origin group and origins pointing at your backend; Microsoft operates the edge                                                          |
| DNS cutover                                                                                              | Content delivery | Supported    | Common       | Supported Route 53 aliases point to the target frontend. CloudFront domain\_name, arn and hosted\_zone\_id are not target identifiers; unsupported output references are removed and active configuration references cause a build error.                |
| Custom domains + TLS                                                                                     | Domains & TLS    | Partial      | Most usage   | Custom domains use target-managed certificates. Complete domain validation before cutover; an ACM ARN supplies no certificate material. Minimum TLS-version and SSL support-method differences are reported.                                             |
| Edge logic (Lambda\@Edge / CloudFront Functions)                                                         | Edge logic       | Out of scope | Most usage   | Rules engine conditions can express headers, URL changes and redirects, but cannot run arbitrary function code. Unsupported associations are omitted and reported; standalone functions cause a build error.                                             |
| Policy & monitoring facets (cache / origin-request / response-headers policies, monitoring subscription) | Facets           | Out of scope | Full surface | these resources are not supported by this mapping; the build reports an error                                                                                                                                                                            |
| Origins                                                                                                  | Origins          | Partial      | Common       | Origin hosts become members of an origin group. Confirm unresolved addresses and review differences between source failover conditions and Front Door health-probe selection.                                                                            |

#### How it works

Tensor9 translates the CloudFront distribution into an Azure Front Door Premium profile, endpoint, origin group, origins, route and rule set. Microsoft operates the edge cache and serves requests. The customer controls the origin and the target configuration.

A custom DNS name can remain after its record and certificate are ready for Front Door. The CloudFront-generated hostname and cached objects do not transfer. Expect origin requests as the new cache fills.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTUwIiB2aWV3Qm94PSIwIDAgODM2IDE1MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJGcm9udCBEb29yIHJvdXRlcyBhIHJlcXVlc3QgdGhyb3VnaCBjYWNoZSBydWxlcyB0byBhbiBvcmlnaW4gaW4gdGhlIGNvbmZpZ3VyZWQgZ3JvdXAuIj48c3R5bGU+dGV4dHtmb250LWZhbWlseTpJbnRlciwtYXBwbGUtc3lzdGVtLEJsaW5rTWFjU3lzdGVtRm9udCwnU2Vnb2UgVUknLFJvYm90bywnSGVsdmV0aWNhIE5ldWUnLEFyaWFsLHNhbnMtc2VyaWY7ZmlsbDojMzM0MTU1fTwvc3R5bGU+PHJlY3QgeD0iMjQiIHk9IjQwIiB3aWR0aD0iMjQwIiBoZWlnaHQ9IjgwIiByeD0iMTAiIGZpbGw9IiNmOGZhZmMiIHN0cm9rZT0iIzY0NzQ4YiIvPjx0ZXh0IHg9IjE0NCIgeT0iNzAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5DdXN0b21lciByZXF1ZXN0PC90ZXh0Pjx0ZXh0IHg9IjE0NCIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5jdXN0b20gZG9tYWluPC90ZXh0PjxwYXRoIGQ9Ik0yNjYsODAgaDIyIGwtNiwtNSBtNiw1IGwtNiw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPjxyZWN0IHg9IjI5NCIgeT0iNDAiIHdpZHRoPSIyNDAiIGhlaWdodD0iODAiIHJ4PSIxMCIgZmlsbD0iI2Y4ZmFmYyIgc3Ryb2tlPSIjNjQ3NDhiIi8+PHRleHQgeD0iNDE0IiB5PSI3MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPkZyb250IERvb3IgUHJlbWl1bTwvdGV4dD48dGV4dCB4PSI0MTQiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+cm91dGUgKyBjYWNoZSBydWxlczwvdGV4dD48cGF0aCBkPSJNNTM2LDgwIGgyMiBsLTYsLTUgbTYsNSBsLTYsNSIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjIiLz48cmVjdCB4PSI1NjQiIHk9IjQwIiB3aWR0aD0iMjQwIiBoZWlnaHQ9IjgwIiByeD0iMTAiIGZpbGw9IiNmOGZhZmMiIHN0cm9rZT0iIzY0NzQ4YiIvPjx0ZXh0IHg9IjY4NCIgeT0iNzAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5PcmlnaW4gZ3JvdXA8L3RleHQ+PHRleHQgeD0iNjg0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmhlYWx0aHkgb3JpZ2luPC90ZXh0Pjwvc3ZnPg==" alt="Front Door routes a request through cache rules to an origin in the configured group." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTUwIiB2aWV3Qm94PSIwIDAgODM2IDE1MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJGcm9udCBEb29yIHJvdXRlcyBhIHJlcXVlc3QgdGhyb3VnaCBjYWNoZSBydWxlcyB0byBhbiBvcmlnaW4gaW4gdGhlIGNvbmZpZ3VyZWQgZ3JvdXAuIj48c3R5bGU+dGV4dHtmb250LWZhbWlseTpJbnRlciwtYXBwbGUtc3lzdGVtLEJsaW5rTWFjU3lzdGVtRm9udCwnU2Vnb2UgVUknLFJvYm90bywnSGVsdmV0aWNhIE5ldWUnLEFyaWFsLHNhbnMtc2VyaWY7ZmlsbDojY2JkNWUxfTwvc3R5bGU+PHJlY3QgeD0iMjQiIHk9IjQwIiB3aWR0aD0iMjQwIiBoZWlnaHQ9IjgwIiByeD0iMTAiIGZpbGw9IiMxYTI2MzEiIHN0cm9rZT0iIzY0NzQ4YiIvPjx0ZXh0IHg9IjE0NCIgeT0iNzAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5DdXN0b21lciByZXF1ZXN0PC90ZXh0Pjx0ZXh0IHg9IjE0NCIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5jdXN0b20gZG9tYWluPC90ZXh0PjxwYXRoIGQ9Ik0yNjYsODAgaDIyIGwtNiwtNSBtNiw1IGwtNiw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPjxyZWN0IHg9IjI5NCIgeT0iNDAiIHdpZHRoPSIyNDAiIGhlaWdodD0iODAiIHJ4PSIxMCIgZmlsbD0iIzFhMjYzMSIgc3Ryb2tlPSIjNjQ3NDhiIi8+PHRleHQgeD0iNDE0IiB5PSI3MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPkZyb250IERvb3IgUHJlbWl1bTwvdGV4dD48dGV4dCB4PSI0MTQiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+cm91dGUgKyBjYWNoZSBydWxlczwvdGV4dD48cGF0aCBkPSJNNTM2LDgwIGgyMiBsLTYsLTUgbTYsNSBsLTYsNSIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjIiLz48cmVjdCB4PSI1NjQiIHk9IjQwIiB3aWR0aD0iMjQwIiBoZWlnaHQ9IjgwIiByeD0iMTAiIGZpbGw9IiMxYTI2MzEiIHN0cm9rZT0iIzY0NzQ4YiIvPjx0ZXh0IHg9IjY4NCIgeT0iNzAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5PcmlnaW4gZ3JvdXA8L3RleHQ+PHRleHQgeD0iNjg0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmhlYWx0aHkgb3JpZ2luPC90ZXh0Pjwvc3ZnPg==" alt="Front Door routes a request through cache rules to an origin in the configured group." />
</div>

#### Origins and routing

The endpoint supplies the public host. A route associates that endpoint with an origin group and the rules applied to requests. Each declared origin host becomes an origin; the group uses health probes to select available origins. This differs from CloudFront origin-group failover, so review failover conditions and origin selection.

Confirm any origin address that compilation cannot resolve. An S3 origin follows the selected storage mapping to the target endpoint. Validate the origin host header, TLS and network access against that endpoint rather than retaining an AWS-specific address.

#### Origin access

Front Door Premium can reach supported origins through Private Link. For a Kubernetes service, provide the compatible Azure Private Link service and load balancer arrangement, then approve Front Door's managed private endpoint. An arbitrary private cluster is not reachable merely because the profile uses Premium.

Traffic reaches the origin through a private connection over Microsoft's network. The origin still needs to accept that private traffic, and the platform team must close any unwanted public or alternate access paths. Private Link does not require a connector process inside the application cluster.

CloudFront OAI and OAC govern authenticated access to supported origins; OAC is not a general private-network connection. The target requires the access controls appropriate to its origin type. Neither Standard nor Premium verifies existing CloudFront viewer signed-URL or signed-cookie signatures; that viewer-authorization scheme needs a separate application design.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTUwIiB2aWV3Qm94PSIwIDAgODM2IDE1MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQcmVtaXVtIHJlYWNoZXMgYSBzdXBwb3J0ZWQgb3JpZ2luIHRocm91Z2ggYW4gYXBwcm92ZWQgUHJpdmF0ZSBMaW5rIGNvbm5lY3Rpb24uIj48c3R5bGU+dGV4dHtmb250LWZhbWlseTpJbnRlciwtYXBwbGUtc3lzdGVtLEJsaW5rTWFjU3lzdGVtRm9udCwnU2Vnb2UgVUknLFJvYm90bywnSGVsdmV0aWNhIE5ldWUnLEFyaWFsLHNhbnMtc2VyaWY7ZmlsbDojMzM0MTU1fTwvc3R5bGU+PHJlY3QgeD0iMjQiIHk9IjQwIiB3aWR0aD0iMjQwIiBoZWlnaHQ9IjgwIiByeD0iMTAiIGZpbGw9IiNmOGZhZmMiIHN0cm9rZT0iIzY0NzQ4YiIvPjx0ZXh0IHg9IjE0NCIgeT0iNzAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5Gcm9udCBEb29yIFByZW1pdW08L3RleHQ+PHRleHQgeD0iMTQ0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPm9yaWdpbiByZXF1ZXN0PC90ZXh0PjxwYXRoIGQ9Ik0yNjYsODAgaDIyIGwtNiwtNSBtNiw1IGwtNiw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPjxyZWN0IHg9IjI5NCIgeT0iNDAiIHdpZHRoPSIyNDAiIGhlaWdodD0iODAiIHJ4PSIxMCIgZmlsbD0iI2Y4ZmFmYyIgc3Ryb2tlPSIjNjQ3NDhiIi8+PHRleHQgeD0iNDE0IiB5PSI3MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPlByaXZhdGUgTGluazwvdGV4dD48dGV4dCB4PSI0MTQiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+YXBwcm92ZWQgY29ubmVjdGlvbjwvdGV4dD48cGF0aCBkPSJNNTM2LDgwIGgyMiBsLTYsLTUgbTYsNSBsLTYsNSIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjIiLz48cmVjdCB4PSI1NjQiIHk9IjQwIiB3aWR0aD0iMjQwIiBoZWlnaHQ9IjgwIiByeD0iMTAiIGZpbGw9IiNmOGZhZmMiIHN0cm9rZT0iIzY0NzQ4YiIvPjx0ZXh0IHg9IjY4NCIgeT0iNzAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5PcmlnaW48L3RleHQ+PHRleHQgeD0iNjg0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPnZhbGlkYXRlcyBhY2Nlc3M8L3RleHQ+PC9zdmc+" alt="Premium reaches a supported origin through an approved Private Link connection." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTUwIiB2aWV3Qm94PSIwIDAgODM2IDE1MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQcmVtaXVtIHJlYWNoZXMgYSBzdXBwb3J0ZWQgb3JpZ2luIHRocm91Z2ggYW4gYXBwcm92ZWQgUHJpdmF0ZSBMaW5rIGNvbm5lY3Rpb24uIj48c3R5bGU+dGV4dHtmb250LWZhbWlseTpJbnRlciwtYXBwbGUtc3lzdGVtLEJsaW5rTWFjU3lzdGVtRm9udCwnU2Vnb2UgVUknLFJvYm90bywnSGVsdmV0aWNhIE5ldWUnLEFyaWFsLHNhbnMtc2VyaWY7ZmlsbDojY2JkNWUxfTwvc3R5bGU+PHJlY3QgeD0iMjQiIHk9IjQwIiB3aWR0aD0iMjQwIiBoZWlnaHQ9IjgwIiByeD0iMTAiIGZpbGw9IiMxYTI2MzEiIHN0cm9rZT0iIzY0NzQ4YiIvPjx0ZXh0IHg9IjE0NCIgeT0iNzAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5Gcm9udCBEb29yIFByZW1pdW08L3RleHQ+PHRleHQgeD0iMTQ0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPm9yaWdpbiByZXF1ZXN0PC90ZXh0PjxwYXRoIGQ9Ik0yNjYsODAgaDIyIGwtNiwtNSBtNiw1IGwtNiw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPjxyZWN0IHg9IjI5NCIgeT0iNDAiIHdpZHRoPSIyNDAiIGhlaWdodD0iODAiIHJ4PSIxMCIgZmlsbD0iIzFhMjYzMSIgc3Ryb2tlPSIjNjQ3NDhiIi8+PHRleHQgeD0iNDE0IiB5PSI3MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPlByaXZhdGUgTGluazwvdGV4dD48dGV4dCB4PSI0MTQiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+YXBwcm92ZWQgY29ubmVjdGlvbjwvdGV4dD48cGF0aCBkPSJNNTM2LDgwIGgyMiBsLTYsLTUgbTYsNSBsLTYsNSIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjIiLz48cmVjdCB4PSI1NjQiIHk9IjQwIiB3aWR0aD0iMjQwIiBoZWlnaHQ9IjgwIiByeD0iMTAiIGZpbGw9IiMxYTI2MzEiIHN0cm9rZT0iIzY0NzQ4YiIvPjx0ZXh0IHg9IjY4NCIgeT0iNzAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5PcmlnaW48L3RleHQ+PHRleHQgeD0iNjg0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPnZhbGlkYXRlcyBhY2Nlc3M8L3RleHQ+PC9zdmc+" alt="Premium reaches a supported origin through an approved Private Link connection." />
</div>

#### Web application firewall

A Front Door firewall policy contains the target WAF rules; a security policy attaches it to the endpoint. Supported custom AWS match and rate-limit rules are expressed using Front Door conditions and actions, and geographic restrictions use country-match rules. An AWS `web_acl_id` is a reference, not an Azure policy.

Premium supports Microsoft-managed WAF rule sets and bot protection as well as custom rules. AWS managed groups are not the same rule sets: select the corresponding target protections and test their effect. Complex AWS conditions without a matching Front Door expression remain a reported limitation.

#### Cache behavior

Default and ordered cache behaviors become rules matched by path. A route-configuration override sets the cache duration and query-string behavior; compression is configured on the route. Check the query parameters included in the cache key, especially for personalized responses.

CloudFront's minimum, default and maximum TTLs do not map to three independent Front Door settings. The default TTL supplies the single cache duration; separate minimum and maximum constraints are reported during compilation. Forwarded-header lists and allowed-method lists also have differences. Verify the effective cache key and request handling rather than assuming that two source requests always remain distinct.

#### Rules and application code

The Rules engine can express header changes, URL or path rewrites and redirects. Those behaviors can be implemented with target rule conditions and actions on both Front Door tiers; arbitrary Lambda\@Edge or CloudFront Functions code does not run there.

Function associations that cannot be translated are omitted and reported. A standalone CloudFront function without a supported translation causes a build error. Move required application logic to a suitable runtime before cutover. CloudFront field-level encryption also has no equivalent in this mapping.

#### Domains and certificates

Each alias becomes a Front Door custom domain with a managed certificate. Complete domain validation and wait for certificate readiness before updating DNS. Front Door issues and renews that certificate; it does not copy an ACM certificate from its ARN. Review minimum TLS version and SSL support-method differences.

Supported Route 53 aliases are updated to the Front Door endpoint. CloudFront `domain_name`, `arn` and `hosted_zone_id` do not become Azure identifiers. References without a target equivalent are removed from outputs or rejected in active configuration. Update external DNS consumers and allowlists separately.

#### Operations and remaining limits

Azure's edge locations replace CloudFront price classes. Use Azure Monitor and diagnostic settings for access logs and metrics; an AWS monitoring subscription is not a Front Door setting. Review cache hit rates, origin health, latency and errors after cutover.

Cache, origin-request and response-headers policy resources need a supported distribution attachment and translation. Standalone policies, monitoring subscriptions and origin-access identities without one cause a build error. Resolve those resources together with the behavior they configure.

Provider reference: [securing Front Door origins](https://learn.microsoft.com/en-us/azure/frontdoor/origin-security).

### Via Azure Front Door Standard

| Operation                                                                                                           | Area             | Support      | Depth        | Notes                                                                                                                                                                                                                                                      |
| ------------------------------------------------------------------------------------------------------------------- | ---------------- | ------------ | ------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Origin access & signed URLs                                                                                         | Access control   | Partial      | Most usage   | Standard reaches public origins. Restrict origin network access and validate configured origin headers; a secret header is not private networking. Private Link requires Premium. Existing CloudFront viewer signatures are not verified.                  |
| Signed URLs                                                                                                         | Access control   | Out of scope | Most usage   | CloudFront trusted-signer and trusted-key-group signed URLs are a different request authorization scheme (Front Door cannot verify CloudFront's RSA or ECDSA signatures), so signed URLs have no counterpart and are flagged during the build              |
| WAF / geo restrictions                                                                                              | Access control   | Partial      | Most usage   | Custom match, rate-limit and country rules become target WAF rules attached through a security policy. Microsoft-managed rules and bot protection require Premium. Unsupported source conditions are reported.                                             |
| Cache behaviors                                                                                                     | Cache            | Partial      | Most usage   | Path-matched rules retain cache duration and query-string behavior. CloudFront default TTL supplies a single duration; separate minimum/maximum constraints and per-behavior header/method differences are reported.                                       |
| Content delivery                                                                                                    | Content delivery | Supported    | Common       | served on Azure Front Door Standard: Tensor9 provisions a Front Door Standard profile and endpoint that front your origin, with an origin group and origins pointing at your backend; Microsoft operates the edge                                          |
| DNS cutover                                                                                                         | Content delivery | Supported    | Common       | Supported Route 53 aliases point to the target frontend. CloudFront domain\_name, arn and hosted\_zone\_id are not target identifiers; unsupported output references are removed and active configuration references cause a build error.                  |
| Custom domains + TLS                                                                                                | Domains & TLS    | Partial      | Most usage   | Custom domains use target-managed certificates. Complete domain validation before cutover; an ACM ARN supplies no certificate material. Minimum TLS-version and SSL support-method differences are reported.                                               |
| Declarative edge logic (Rules engine)                                                                               | Edge logic       | Partial      | Most usage   | Header, URL and redirect behavior can use Rules engine conditions and actions. Arbitrary function code, external calls and request-body inspection are outside this translation; unsupported associations are reported and standalone functions rejected.  |
| Policy & monitoring facets (standalone cache / origin-request / response-headers policies, monitoring subscription) | Facets           | Out of scope | Full surface | a cache, origin-request, or response-headers policy referenced by a behavior is re-expressed in that behavior's route and rules; a standalone policy claimed by no distribution, and the monitoring subscription, have no compiler and cause a build error |
| Origins                                                                                                             | Origins          | Partial      | Common       | Origin hosts become members of an origin group. Confirm unresolved addresses and review differences between source failover conditions and Front Door health-probe selection. Standard requires a public origin endpoint.                                  |

#### How it works

Tensor9 translates the CloudFront distribution into an Azure Front Door Standard profile, endpoint, origin group, origins, route and rule set. Microsoft operates the edge cache and serves requests. The customer controls the origin and the target configuration.

A custom DNS name can remain after its record and certificate are ready for Front Door. The CloudFront-generated hostname and cached objects do not transfer. Expect origin requests as the new cache fills.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTUwIiB2aWV3Qm94PSIwIDAgODM2IDE1MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJGcm9udCBEb29yIHJvdXRlcyBhIHJlcXVlc3QgdGhyb3VnaCBjYWNoZSBydWxlcyB0byBhbiBvcmlnaW4gaW4gdGhlIGNvbmZpZ3VyZWQgZ3JvdXAuIj48c3R5bGU+dGV4dHtmb250LWZhbWlseTpJbnRlciwtYXBwbGUtc3lzdGVtLEJsaW5rTWFjU3lzdGVtRm9udCwnU2Vnb2UgVUknLFJvYm90bywnSGVsdmV0aWNhIE5ldWUnLEFyaWFsLHNhbnMtc2VyaWY7ZmlsbDojMzM0MTU1fTwvc3R5bGU+PHJlY3QgeD0iMjQiIHk9IjQwIiB3aWR0aD0iMjQwIiBoZWlnaHQ9IjgwIiByeD0iMTAiIGZpbGw9IiNmOGZhZmMiIHN0cm9rZT0iIzY0NzQ4YiIvPjx0ZXh0IHg9IjE0NCIgeT0iNzAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5DdXN0b21lciByZXF1ZXN0PC90ZXh0Pjx0ZXh0IHg9IjE0NCIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5jdXN0b20gZG9tYWluPC90ZXh0PjxwYXRoIGQ9Ik0yNjYsODAgaDIyIGwtNiwtNSBtNiw1IGwtNiw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPjxyZWN0IHg9IjI5NCIgeT0iNDAiIHdpZHRoPSIyNDAiIGhlaWdodD0iODAiIHJ4PSIxMCIgZmlsbD0iI2Y4ZmFmYyIgc3Ryb2tlPSIjNjQ3NDhiIi8+PHRleHQgeD0iNDE0IiB5PSI3MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPkZyb250IERvb3IgU3RhbmRhcmQ8L3RleHQ+PHRleHQgeD0iNDE0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPnJvdXRlICsgY2FjaGUgcnVsZXM8L3RleHQ+PHBhdGggZD0iTTUzNiw4MCBoMjIgbC02LC01IG02LDUgbC02LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+PHJlY3QgeD0iNTY0IiB5PSI0MCIgd2lkdGg9IjI0MCIgaGVpZ2h0PSI4MCIgcng9IjEwIiBmaWxsPSIjZjhmYWZjIiBzdHJva2U9IiM2NDc0OGIiLz48dGV4dCB4PSI2ODQiIHk9IjcwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+T3JpZ2luIGdyb3VwPC90ZXh0Pjx0ZXh0IHg9IjY4NCIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5oZWFsdGh5IG9yaWdpbjwvdGV4dD48L3N2Zz4=" alt="Front Door routes a request through cache rules to an origin in the configured group." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTUwIiB2aWV3Qm94PSIwIDAgODM2IDE1MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJGcm9udCBEb29yIHJvdXRlcyBhIHJlcXVlc3QgdGhyb3VnaCBjYWNoZSBydWxlcyB0byBhbiBvcmlnaW4gaW4gdGhlIGNvbmZpZ3VyZWQgZ3JvdXAuIj48c3R5bGU+dGV4dHtmb250LWZhbWlseTpJbnRlciwtYXBwbGUtc3lzdGVtLEJsaW5rTWFjU3lzdGVtRm9udCwnU2Vnb2UgVUknLFJvYm90bywnSGVsdmV0aWNhIE5ldWUnLEFyaWFsLHNhbnMtc2VyaWY7ZmlsbDojY2JkNWUxfTwvc3R5bGU+PHJlY3QgeD0iMjQiIHk9IjQwIiB3aWR0aD0iMjQwIiBoZWlnaHQ9IjgwIiByeD0iMTAiIGZpbGw9IiMxYTI2MzEiIHN0cm9rZT0iIzY0NzQ4YiIvPjx0ZXh0IHg9IjE0NCIgeT0iNzAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5DdXN0b21lciByZXF1ZXN0PC90ZXh0Pjx0ZXh0IHg9IjE0NCIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5jdXN0b20gZG9tYWluPC90ZXh0PjxwYXRoIGQ9Ik0yNjYsODAgaDIyIGwtNiwtNSBtNiw1IGwtNiw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPjxyZWN0IHg9IjI5NCIgeT0iNDAiIHdpZHRoPSIyNDAiIGhlaWdodD0iODAiIHJ4PSIxMCIgZmlsbD0iIzFhMjYzMSIgc3Ryb2tlPSIjNjQ3NDhiIi8+PHRleHQgeD0iNDE0IiB5PSI3MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPkZyb250IERvb3IgU3RhbmRhcmQ8L3RleHQ+PHRleHQgeD0iNDE0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPnJvdXRlICsgY2FjaGUgcnVsZXM8L3RleHQ+PHBhdGggZD0iTTUzNiw4MCBoMjIgbC02LC01IG02LDUgbC02LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+PHJlY3QgeD0iNTY0IiB5PSI0MCIgd2lkdGg9IjI0MCIgaGVpZ2h0PSI4MCIgcng9IjEwIiBmaWxsPSIjMWEyNjMxIiBzdHJva2U9IiM2NDc0OGIiLz48dGV4dCB4PSI2ODQiIHk9IjcwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+T3JpZ2luIGdyb3VwPC90ZXh0Pjx0ZXh0IHg9IjY4NCIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5oZWFsdGh5IG9yaWdpbjwvdGV4dD48L3N2Zz4=" alt="Front Door routes a request through cache rules to an origin in the configured group." />
</div>

#### Origins and routing

The endpoint supplies the public host. A route associates that endpoint with an origin group and the rules applied to requests. Each declared origin host becomes an origin; the group uses health probes to select available origins. This differs from CloudFront origin-group failover, so review failover conditions and origin selection.

Confirm any origin address that compilation cannot resolve. An S3 origin follows the selected storage mapping to the target endpoint. Validate the origin host header, TLS and network access against that endpoint rather than retaining an AWS-specific address.

#### Origin access

Front Door Standard needs an origin reachable through a public endpoint; it does not support Private Link origins. Use Premium with a compatible Private Link arrangement when the origin must have no public endpoint.

Restrict direct access to a public origin. The backend can validate a shared secret inserted in an origin request header, but that secret must be protected and rotated. Azure's origin-security guidance also combines the `AzureFrontDoor.Backend` network selector with validation of the expected `X-Azure-FDID` value. A header alone is not network isolation.

CloudFront OAI and OAC govern authenticated access to supported origins; OAC is not a general private-network connection. The target requires the access controls appropriate to its origin type. Neither Standard nor Premium verifies existing CloudFront viewer signed-URL or signed-cookie signatures; that viewer-authorization scheme needs a separate application design.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTUwIiB2aWV3Qm94PSIwIDAgODM2IDE1MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJTdGFuZGFyZCByZWFjaGVzIGEgcHVibGljIGVuZHBvaW50IHdob3NlIG5ldHdvcmsgYW5kIGFwcGxpY2F0aW9uIGNvbnRyb2xzIHJlc3RyaWN0IGFjY2Vzcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiMzMzQxNTV9PC9zdHlsZT48cmVjdCB4PSIyNCIgeT0iNDAiIHdpZHRoPSIyNDAiIGhlaWdodD0iODAiIHJ4PSIxMCIgZmlsbD0iI2Y4ZmFmYyIgc3Ryb2tlPSIjNjQ3NDhiIi8+PHRleHQgeD0iMTQ0IiB5PSI3MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPkZyb250IERvb3IgU3RhbmRhcmQ8L3RleHQ+PHRleHQgeD0iMTQ0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPm9yaWdpbiByZXF1ZXN0PC90ZXh0PjxwYXRoIGQ9Ik0yNjYsODAgaDIyIGwtNiwtNSBtNiw1IGwtNiw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPjxyZWN0IHg9IjI5NCIgeT0iNDAiIHdpZHRoPSIyNDAiIGhlaWdodD0iODAiIHJ4PSIxMCIgZmlsbD0iI2Y4ZmFmYyIgc3Ryb2tlPSIjNjQ3NDhiIi8+PHRleHQgeD0iNDE0IiB5PSI3MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPlB1YmxpYyBlbmRwb2ludDwvdGV4dD48dGV4dCB4PSI0MTQiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+cmVzdHJpY3RlZCBhY2Nlc3M8L3RleHQ+PHBhdGggZD0iTTUzNiw4MCBoMjIgbC02LC01IG02LDUgbC02LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+PHJlY3QgeD0iNTY0IiB5PSI0MCIgd2lkdGg9IjI0MCIgaGVpZ2h0PSI4MCIgcng9IjEwIiBmaWxsPSIjZjhmYWZjIiBzdHJva2U9IiM2NDc0OGIiLz48dGV4dCB4PSI2ODQiIHk9IjcwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzBmMTcyYSI+T3JpZ2luPC90ZXh0Pjx0ZXh0IHg9IjY4NCIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj52YWxpZGF0ZXMgYWNjZXNzPC90ZXh0Pjwvc3ZnPg==" alt="Standard reaches a public endpoint whose network and application controls restrict access." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMTUwIiB2aWV3Qm94PSIwIDAgODM2IDE1MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJTdGFuZGFyZCByZWFjaGVzIGEgcHVibGljIGVuZHBvaW50IHdob3NlIG5ldHdvcmsgYW5kIGFwcGxpY2F0aW9uIGNvbnRyb2xzIHJlc3RyaWN0IGFjY2Vzcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiNjYmQ1ZTF9PC9zdHlsZT48cmVjdCB4PSIyNCIgeT0iNDAiIHdpZHRoPSIyNDAiIGhlaWdodD0iODAiIHJ4PSIxMCIgZmlsbD0iIzFhMjYzMSIgc3Ryb2tlPSIjNjQ3NDhiIi8+PHRleHQgeD0iMTQ0IiB5PSI3MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPkZyb250IERvb3IgU3RhbmRhcmQ8L3RleHQ+PHRleHQgeD0iMTQ0IiB5PSI5OCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPm9yaWdpbiByZXF1ZXN0PC90ZXh0PjxwYXRoIGQ9Ik0yNjYsODAgaDIyIGwtNiwtNSBtNiw1IGwtNiw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPjxyZWN0IHg9IjI5NCIgeT0iNDAiIHdpZHRoPSIyNDAiIGhlaWdodD0iODAiIHJ4PSIxMCIgZmlsbD0iIzFhMjYzMSIgc3Ryb2tlPSIjNjQ3NDhiIi8+PHRleHQgeD0iNDE0IiB5PSI3MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPlB1YmxpYyBlbmRwb2ludDwvdGV4dD48dGV4dCB4PSI0MTQiIHk9Ijk4IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+cmVzdHJpY3RlZCBhY2Nlc3M8L3RleHQ+PHBhdGggZD0iTTUzNiw4MCBoMjIgbC02LC01IG02LDUgbC02LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+PHJlY3QgeD0iNTY0IiB5PSI0MCIgd2lkdGg9IjI0MCIgaGVpZ2h0PSI4MCIgcng9IjEwIiBmaWxsPSIjMWEyNjMxIiBzdHJva2U9IiM2NDc0OGIiLz48dGV4dCB4PSI2ODQiIHk9IjcwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogNjUwIDEzLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2VkOCI+T3JpZ2luPC90ZXh0Pjx0ZXh0IHg9IjY4NCIgeT0iOTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij52YWxpZGF0ZXMgYWNjZXNzPC90ZXh0Pjwvc3ZnPg==" alt="Standard reaches a public endpoint whose network and application controls restrict access." />
</div>

#### Web application firewall

A Front Door firewall policy contains the target WAF rules; a security policy attaches it to the endpoint. Supported custom AWS match and rate-limit rules are expressed using Front Door conditions and actions, and geographic restrictions use country-match rules. An AWS `web_acl_id` is a reference, not an Azure policy.

Standard supports custom match rules, rate limits and country-based rules. Microsoft-managed rule sets and bot protection require Premium. A source web ACL that depends on managed groups therefore needs a different protection plan; custom rules alone do not reproduce those groups.

#### Cache behavior

Default and ordered cache behaviors become rules matched by path. A route-configuration override sets the cache duration and query-string behavior; compression is configured on the route. Check the query parameters included in the cache key, especially for personalized responses.

CloudFront's minimum, default and maximum TTLs do not map to three independent Front Door settings. The default TTL supplies the single cache duration; separate minimum and maximum constraints are reported during compilation. Forwarded-header lists and allowed-method lists also have differences. Verify the effective cache key and request handling rather than assuming that two source requests always remain distinct.

#### Rules and application code

The Rules engine can express header changes, URL or path rewrites and redirects. Those behaviors can be implemented with target rule conditions and actions on both Front Door tiers; arbitrary Lambda\@Edge or CloudFront Functions code does not run there.

Function associations that cannot be translated are omitted and reported. A standalone CloudFront function without a supported translation causes a build error. Move required application logic to a suitable runtime before cutover. CloudFront field-level encryption also has no equivalent in this mapping.

#### Domains and certificates

Each alias becomes a Front Door custom domain with a managed certificate. Complete domain validation and wait for certificate readiness before updating DNS. Front Door issues and renews that certificate; it does not copy an ACM certificate from its ARN. Review minimum TLS version and SSL support-method differences.

Supported Route 53 aliases are updated to the Front Door endpoint. CloudFront `domain_name`, `arn` and `hosted_zone_id` do not become Azure identifiers. References without a target equivalent are removed from outputs or rejected in active configuration. Update external DNS consumers and allowlists separately.

#### Operations and remaining limits

Azure's edge locations replace CloudFront price classes. Use Azure Monitor and diagnostic settings for access logs and metrics; an AWS monitoring subscription is not a Front Door setting. Review cache hit rates, origin health, latency and errors after cutover.

Cache, origin-request and response-headers policy resources need a supported distribution attachment and translation. Standalone policies, monitoring subscriptions and origin-access identities without one cause a build error. Resolve those resources together with the behavior they configure.

Provider reference: [securing Front Door origins](https://learn.microsoft.com/en-us/azure/frontdoor/origin-security).

[Service Catalog](/service-adapters/catalog).
