<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[How to resolve CloudFront conflict with custom domain on FusionAuth Cloud?]]></title><description><![CDATA[<p dir="auto">We are using FusionAuth Cloud with a custom domain, and we've set up our own CloudFront distribution for that domain. However, we received notification that FusionAuth is implementing CloudFront as part of their cloud infrastructure.</p>
<p dir="auto">The issue is that AWS only allows one CloudFront distribution per hostname. Our custom domain is registered in our CloudFront distribution, but the DNS record points to the FusionAuth instance.</p>
<p dir="auto">What changes do we need to make to resolve this conflict and allow FusionAuth to enable CloudFront on their side for our instance?</p>
]]></description><link>https://fusionauth.io/community/forum/topic/3158/how-to-resolve-cloudfront-conflict-with-custom-domain-on-fusionauth-cloud</link><generator>RSS for Node</generator><lastBuildDate>Tue, 29 Sep 2026 01:01:29 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3158.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 28 Sep 2026 16:13:35 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to How to resolve CloudFront conflict with custom domain on FusionAuth Cloud? on Mon, 28 Sep 2026 16:13:47 GMT]]></title><description><![CDATA[<p dir="auto">To resolve this CloudFront conflict, you need to <strong>disassociate your custom domain from your CloudFront distribution</strong>.</p>
<p dir="auto">Since AWS only allows one CloudFront distribution per hostname, and FusionAuth Cloud is implementing CloudFront on their infrastructure, you have two options:</p>
<ol>
<li><strong>Remove the custom domain from your CloudFront distribution</strong> — This allows FusionAuth to add the domain to their CloudFront distribution</li>
<li><strong>Set up your CloudFront as a proxy</strong> — Configure your distribution to proxy requests to FusionAuth's infrastructure</li>
</ol>
<p dir="auto">The recommended approach is to remove your custom domain from your CloudFront distribution entirely, as FusionAuth will handle CloudFront configuration as part of their cloud service.</p>
<h2>How FusionAuth Custom Domains Work</h2>
<p dir="auto">When you configure a custom domain with FusionAuth Cloud, you create a CNAME record pointing from your custom domain to your deployment's durable URL (something like <code>&lt;random-string&gt;.durable.fusionauth.dev</code>). FusionAuth manages the CloudFront distribution and SSL certificates on their infrastructure, so you don't need to maintain your own CloudFront distribution for the custom domain.</p>
<p dir="auto">The proper DNS setup should be:</p>
<ul>
<li><strong>Custom domain</strong> → CNAME → <strong>FusionAuth durable URL</strong></li>
</ul>
<p dir="auto">This allows FusionAuth to provision and manage the entire CloudFront infrastructure, including SSL certificate validation and renewal, as part of their cloud service.</p>
<h2>Migration Timeline</h2>
<p dir="auto">This change is important but not urgent. A timeline of 1-2 weeks for investigation and implementation is reasonable. FusionAuth support can assist you through the migration process if you have any questions during implementation.</p>
<hr />
<h2>Related Documentation</h2>
<ul>
<li><a href="https://fusionauth.io/docs/get-started/run-in-the-cloud/cloud#custom-domains" rel="nofollow ugc">FusionAuth Cloud Custom Domains</a> - Official guide for setting up custom domains on FusionAuth Cloud</li>
<li><a href="https://fusionauth.io/blog/introducing-unlimited-custom-domains-for-fusionauth-cloud" rel="nofollow ugc">Adding a Custom Domain</a> - Step-by-step walkthrough of the custom domain configuration process</li>
<li><a href="https://fusionauth.io/blog/cloudfront" rel="nofollow ugc">How to set up a Custom Domain for FusionAuth using AWS CloudFront</a> - Guide for self-hosted FusionAuth installations (note: this is for self-hosted, not FusionAuth Cloud)</li>
</ul>
<p dir="auto"><strong>Note:</strong> If you're on a High Availability plan and want to use the Unlimited Custom Domains feature, or if you need assistance with the migration, <a href="https://account.fusionauth.io/account/support/" rel="nofollow ugc">open a support ticket</a>.</p>
]]></description><link>https://fusionauth.io/community/forum/post/8654</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8654</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Mon, 28 Sep 2026 16:13:47 GMT</pubDate></item></channel></rss>