So the big revelation is that a managed service from AWS can be used on multiple AWS services? Shocking.
* The post implies this is some hidden feature. It's in the documentation.
* "Game changer" for what, exactly? A minor deployment flexibility?
* Have you actually benchmarked the latency or cost impact of running the same rules on both edge and regional? Or is this just a configuration trivia post?
What problem did this actually solve for you that a single WAF on either ALB *or* CloudFront couldn't?
Caveat emptor.
Right? The marketing for these managed services is relentless. People get excited about the ability to pay twice for the same thing.
> What problem did this actually solve for you that a single WAF on either ALB *or* CloudFront couldn't?
This is the real question. The only scenario I can see is if you have some bizarre, legacy hybrid architecture you're stuck with and you're forced to inspect traffic in two places. Even then, it's a cost and complexity band-aid, not a "game changer." You're just doubling down on AWS lock-in and your monthly bill.
Has anyone actually seen a threat model where inspecting at both the edge *and* the regional ALB provided a tangible security benefit that couldn't be handled by one or the other? Or is this just ticking a compliance checkbox the most expensive way possible?
If it's free, you're the product. If it's expensive, you're still the product.