FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login

    How to resolve CloudFront conflict with custom domain on FusionAuth Cloud?

    Scheduled Pinned Locked Moved Solved
    Q&A
    cloudfront custom-domain fusionauth cloud dns
    1
    2
    16
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      FASupportBot
      last edited by

      We are using FusionAuth Cloud with a custom domain, and we've set up our own CloudFront distribution for that domain. However, we received notification that FusionAuth is implementing CloudFront as part of their cloud infrastructure.

      The issue is that AWS only allows one CloudFront distribution per hostname. Our custom domain is registered in our CloudFront distribution, but the DNS record points to the FusionAuth instance.

      What changes do we need to make to resolve this conflict and allow FusionAuth to enable CloudFront on their side for our instance?

      If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

      1 Reply Last reply Reply Quote 0
      • F
        FASupportBot
        last edited by dan

        To resolve this CloudFront conflict, you need to disassociate your custom domain from your CloudFront distribution.

        Since AWS only allows one CloudFront distribution per hostname, and FusionAuth Cloud is implementing CloudFront on their infrastructure, you have two options:

        1. Remove the custom domain from your CloudFront distribution — This allows FusionAuth to add the domain to their CloudFront distribution
        2. Set up your CloudFront as a proxy — Configure your distribution to proxy requests to FusionAuth's infrastructure

        The recommended approach is to remove your custom domain from your CloudFront distribution entirely, as FusionAuth will handle CloudFront configuration as part of their cloud service.

        How FusionAuth Custom Domains Work

        When you configure a custom domain with FusionAuth Cloud, you create a CNAME record pointing from your custom domain to your deployment's durable URL (something like <random-string>.durable.fusionauth.dev). FusionAuth manages the CloudFront distribution and SSL certificates on their infrastructure, so you don't need to maintain your own CloudFront distribution for the custom domain.

        The proper DNS setup should be:

        • Custom domain → CNAME → FusionAuth durable URL

        This allows FusionAuth to provision and manage the entire CloudFront infrastructure, including SSL certificate validation and renewal, as part of their cloud service.


        Related Documentation

        • FusionAuth Cloud Custom Domains - Official guide for setting up custom domains on FusionAuth Cloud
        • Adding a Custom Domain - Step-by-step walkthrough of the custom domain configuration process
        • How to set up a Custom Domain for FusionAuth using AWS CloudFront - Guide for self-hosted FusionAuth installations (note: this is for self-hosted, not FusionAuth Cloud)

        Note: If you're on a High Availability plan and want to use the Unlimited Custom Domains feature, or if you need assistance with the migration, open a support ticket.

        If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

        1 Reply Last reply Reply Quote 0
        • danD dan has marked this topic as solved
        • danD dan moved this topic from Hidden
        • First post
          Last post