Option to disable the awsapprunner.com URL (when using WAF/Cloudfront)
- Dominant language
- No language data
- Stars
- 301
- Forks
- 15
- PR merge metrics
- No merged PRs in 30d
Description
**Community Note**
* Please vote on this issue by adding a 👍 reaction to the original issue to help the community and maintainers prioritize this request
* Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do * not help prioritize the request
If you are interested in working on this issue or have submitted a pull request, please leave a comment
**Tell us about your request**
When using Cloudfront and/or WAF in front of App Runner to hide the services IP-addresses, the services are still reachable on _https://foobar.region.awsapprunner.com_. While this URL is difficult to just guess, it's still a security (DDoS) risk if they somehow end up in the wrong hands.
If we could access the security group or even better just tick a box to disable the _awsapprunner.com_ URL, this would be solved.
**Describe alternatives you've considered**
Having some logic in the application level to ignore requests not coming from other AWS services, but this is only a slight protection as the requests will still saturate the App Runner services.
Contributor guide
Research direction
The issue names no repository files, tests, or implementation entry points. Start by investigating how App Runner exposes the awsapprunner.com URL when CloudFront or WAF is in front, then determine the service-level change needed. Done means an explicit way to disable or otherwise prevent direct access through that URL, with behavior documented and verified.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws
- Domain
- cloud, infrastructure, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100