All infographics

CONTENT DELIVERY / 06

Amazon CloudFront

A low-latency content delivery network

Download sheet SVG

THE BIG PICTURE

Serve from the edge; fetch on a miss

  1. ViewersHTTPS requests
  2. Edge cacheCache hit → serve content
    Cache miss
  3. OriginS3 bucket or web server

Cache hits return from the edge. Cache misses fetch from the configured origin and can populate the cache.

01Distributions and behaviors

  • A distribution has a dxxxx.cloudfront.net domain and one or more origins.
  • Origins can be S3 buckets, load balancers, EC2 or other HTTP servers, API Gateway.
  • Path behaviors are checked in order; the default behavior catches the rest.
  • Path patterns are case-sensitive; the first matching pattern wins.
  • GET and HEAD are cached (OPTIONS if enabled); POST, PUT and DELETE go to the origin.

02Caching and invalidation

  • The cache key decides which requests share an object; each extra part splits it.
  • Forward extra headers, cookies or query strings with an origin request policy instead.
  • Min, default and max TTL control caching; positive min TTL overrides private and no-store.
  • Invalidations are not instant; check their status. Wildcard paths are allowed.
  • Versioned file names avoid invalidation: a changed file gets a new URL.

03OAC for S3 origins

  • Origin access control (OAC) lets CloudFront sign requests to a private S3 bucket.
  • Keep Block Public Access on; the bucket policy grants access to this distribution only.
  • OAC is the current method; origin access identity (OAI) is the legacy setup.
  • The S3 static website endpoint cannot use OAC; point the origin at the REST endpoint.
  • SSE-KMS objects also need the distribution allowed in the KMS key policy.

04HTTPS and custom domains

  • Viewer protocol policy can allow HTTP, redirect HTTP to HTTPS, or require HTTPS.
  • Custom domains are alternate domain names (CNAMEs) on the distribution.
  • The ACM certificate for CloudFront must be requested in us-east-1 (N. Virginia).
  • A bare apex domain needs an ALIAS or Route 53 alias record; a CNAME is not allowed.
  • One alternate domain name can be attached to only one distribution at a time.

05AWS WAF integration

  • A web ACL attached to the distribution filters requests at the edge.
  • CloudFront-scope web ACLs must be created in us-east-1.
  • Start from AWS managed rule groups, then add rate-based rules for abusive clients.
  • Pay-as-you-go WAF bills per ACL, rule and request; flat-rate plans include eligible WAF usage.
  • Requests that reach the origin directly skip WAF, so lock the origin to CloudFront.

06Restricting viewer access

  • Signed URLs grant one object; signed cookies grant access to several files.
  • Use trusted key groups to verify signatures; root-account key pairs are legacy.
  • Sign on the server; the private key must never reach the browser.
  • Geo restriction allowlists or blocklists countries by viewer IP address.
  • Geo rules use the viewer IP, so VPNs bypass them; they are not authentication.

07Functions vs Lambda@Edge

  • CloudFront Functions run JavaScript at edge locations, on viewer events only.
  • CloudFront Functions have tight run time and memory limits and cannot make network calls.
  • Lambda@Edge runs Node.js or Python on viewer and origin events and can call services.
  • Lambda@Edge functions must be created in us-east-1 and attached by published version.
  • Use CloudFront Functions for header and URL rewrites; Lambda@Edge for heavier logic.

08Origin groups and failover

  • An origin group pairs one primary origin with one secondary origin.
  • The secondary is used when the primary returns a status code you list, such as 503.
  • Failover applies only to GET, HEAD and OPTIONS; other methods get no failover.
  • Test failover by making the primary return a listed status code.
  • Origin Shield adds one regional cache layer that reduces origin load; it is billed extra.

09Logging and metrics

  • Standard logging v2 sends delayed access logs to S3, CloudWatch Logs or Firehose.
  • Real-time logs send chosen fields and a sampling rate to Kinesis Data Streams.
  • Standard CloudWatch metrics are free and are reported in us-east-1.
  • Origin latency is a paid additional-metrics option, enabled per distribution.
  • Logging is not retroactive; turn it on before an incident, not during one.

10Pricing model

  • Pay-as-you-go bills viewer transfer per GB and requests by region and HTTP/HTTPS type.
  • Flat-rate plans bundle CDN, eligible WAF, DNS, Functions and log ingestion for a monthly price.
  • Price classes drop some edge locations to lower cost; excluded regions use farther edges.
  • Lambda@Edge bills per request and GB-second; Functions bill per invocation outside flat-rate plans.
  • Pay-as-you-go invalidations beyond the free allowance bill per path; version assets to avoid them.

11Common patterns

  • Static site: private S3 bucket behind OAC, with a default root object of index.html.
  • Static site: short TTL on HTML, long TTL on hashed asset file names.
  • Single-page app: map 403 and 404 responses to index.html with a 200 status.
  • API acceleration: use CachingDisabled or short TTLs; forward needed headers via policy.
  • Mixed site: path behaviors route /static/ to S3 and /api/ to the API origin.

12Common pitfalls

  • Putting all cookies or headers in the cache key drops the hit ratio sharply.
  • For private user responses, disable caching or use min TTL 0 with private/no-store headers.
  • The default root object applies only to the site root, not to subfolder URLs.
  • S3 returns 403, not 404, for missing objects unless ListBucket is granted.
  • By default the origin sees its own Host; forward Host if it routes by Host header.

Go to the source

Use AWS documentation for current limits, availability, and pricing.

CloudFront cache expiration CloudFront standard logging v2 CloudFront flat-rate pricing plans CloudFront pricing