In AWS, why isn't there a security group that allows you to allow inbound traffic from CloudFront? This should be easy.

Instead, you have to create a stupid ass Lambda function.

Comments