Choose the AWS WAF attachment point first
A web ACL protects a specific supported AWS entry point. CloudFront, Application Load Balancer, API Gateway, and AppSync have different traffic paths, scopes, and operational owners, so the architecture decision should come before the rule list.
- Use CloudFront when the protected application already relies on AWS edge delivery.
- Use a regional association for supported regional services such as ALB or API Gateway.
- Record the protected resource, web ACL scope, logging destination, and rollback owner together.