Installation guide
// Create a service builder using a configuration file
$aws = Aws::factory('/path/to/my_config.json');
// Get the client from the builder by namespace
$client = $aws->get('CloudFront');
Signing CloudFront URLs for Private Distributions
Signed URLs allow you to provide users access to your private content. A signed URL includes additional
information (e.g., expiration time) that gives you more control over access to your content. This additional
information appears in a policy statement, which is based on either a canned policy or a custom policy. For
information about how to set up private distributions and why you need to sign URLs, please read the Serving
Private Content through CloudFront section of the CloudFront Developer Guide.
You can sign a URL using the CloudFront client in the SDK. First you must make sure to provide your CloudFront
Private Key and Key Pair ID to the CloudFront client.
<?php
$cloudFront = CloudFrontClient::factory(array(
'private_key' => '/path/to/your/cloudfront-private-key.pem',
'key_pair_id' => '<cloudfront key pair id>',
));
You can alternatively specify the Private Key and Key Pair ID in your AWS config file and use the service builder to
instantiate the CloudFront client. The following is an example config file that specifies the CloudFront key
information.
<?php return array(
'includes' => array('_aws'),
'services' => array(
'default_settings' => array(
'params' => array(
'key' => '<aws access key>',
'secret' => '<aws secret key>',
'region' => 'us-west-2'
)
),
'cloudfront' => array(
'extends' => 'cloudfront',
'params' => array(
'private_key' => '/path/to/your/cloudfront-private-key.pem',
'key_pair_id' => '<cloudfront key pair id>'
)
)
)
);
You can sign a CloudFront URL for a video resource using either a canned or custom policy.
// Setup parameter values for the resource
$streamHostUrl = 'rtmp://example-distribution.cloudfront.net';
$resourceKey = 'videos/example.mp4';
$expires = time() + 300;
// Create a signed URL for the resource using the canned policy
$signedUrlCannedPolicy = $cloudFront->getSignedUrl(array(
'url' => $streamHostUrl . '/' . $resourceKey,
'expires' => $expires,
));
For versions of the SDK later than 2.3.1, instead of providing your private key information when you instantiate the
client, you can provide it at the time when you sign the URL.
Amazon CloudFront
53