Conversation
Serve codedang-media through CloudFront (OAC) at media.codedang.com. The bucket keeps its public read policy until persisted direct S3 URLs are migrated. New uploads get an immutable Cache-Control header, and FileService returns the CDN URL when MEDIA_CDN_URL is set (unset by default, so behavior is unchanged until rollout).
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (9)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe changes add a CloudFront distribution and DNS records for media, configure uploads to return a CDN URL when ChangesMedia CDN delivery
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant FileService
participant StorageService
participant S3MediaBucket
participant Client
participant CloudFront
FileService->>StorageService: Upload media file
StorageService->>S3MediaBucket: Store object with immutable cache policy
FileService-->>Client: Return media CDN URL when configured
Client->>CloudFront: Request media from media.codedang.com
CloudFront->>S3MediaBucket: Fetch object through SigV4 origin access control
S3MediaBucket-->>CloudFront: Return media object
CloudFront-->>Client: Return media object
Merge Risk: ⚪ Minimal · up to This adds CloudFront delivery for media, with DNS aliases and support for a CDN URL in uploads. Behavior does not change until MEDIA_CDN_URL is set, and no concrete merge-blocking issue was found. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The CDN has appropriate controls for its connection to S3, and the existing direct public-read access is not newly introduced. Review is warranted because DNS deployment now depends on state containing database credentials, and new uploads receive a one-year public cache lifetime that complicates removal of mistakenly published media. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Description
codedang-media버킷을 CloudFront(OAC) 뒤에 두고media.codedang.com으로 제공합니다.infra/aws/storage/cloudfront_media.tf: us-east-1 ACM 인증서(DNS 검증), OAC, 배포(PriceClass_200, 관리형 CachingOptimized)infra/aws/storage/s3_media.tf: 버킷 정책에 CloudFront OAC 허용 추가infra/aws/dns/media.tf: A/AAAA alias 레코드 (storage output을terraform_remote_state로 참조)FileService:MEDIA_CDN_URL이 설정되면 CDN URL 반환StorageService: 신규 업로드에Cache-Control: public, max-age=31536000, immutable지정 (키가 랜덤 UUID)next.config.ts:next/image에media.codedang.com허용이 PR만으로는 동작이 바뀌지 않습니다.
MEDIA_CDN_URL은 어떤 ConfigMap에도 설정하지 않았고, 기존 S3 URL이 contest poster와 rich-text에 저장되어 있어 버킷의 public read 정책도 유지했습니다.Additional context
비용: 읽기 전용 조회 기준 기존 CloudFront 사용량은 월 약 2.1 GB, 10.5만 요청($0)으로, 계정 전체 무료 한도(1 TB, 1,000만 요청) 내로 예상됩니다.
리뷰 포인트
dns가db.tfstate를 읽는 의존성 추가 (k8s-iam에 선례 있음)storage에 유지Before submitting the PR, please make sure you do the following
fixes #123).Closes TAS-3053
Summary by CodeRabbit
media.codedang.comfor faster delivery of uploaded images and files, with HTTPS support.