CONTENT DELIVERY / 06
Amazon CloudFront
A low-latency content delivery network
THE BIG PICTURE
Serve from the edge; fetch on a miss
- ViewersHTTPS requests
- Edge cacheCache hit → serve contentCache miss
- OriginS3 bucket or web server
Cache hits return from the edge. Cache misses fetch from the configured origin and can populate the cache.
01Distributions and behaviors
- A distribution has a dxxxx.cloudfront.net domain and one or more origins.
- Origins can be S3 buckets, load balancers, EC2 or other HTTP servers, API Gateway.
- Path behaviors are checked in order; the default behavior catches the rest.
- Path patterns are case-sensitive; the first matching pattern wins.
- GET and HEAD are cached (OPTIONS if enabled); POST, PUT and DELETE go to the origin.
02Caching and invalidation
- The cache key decides which requests share an object; each extra part splits it.
- Forward extra headers, cookies or query strings with an origin request policy instead.
- Min, default and max TTL control caching; positive min TTL overrides private and no-store.
- Invalidations are not instant; check their status. Wildcard paths are allowed.
- Versioned file names avoid invalidation: a changed file gets a new URL.
03OAC for S3 origins
- Origin access control (OAC) lets CloudFront sign requests to a private S3 bucket.
- Keep Block Public Access on; the bucket policy grants access to this distribution only.
- OAC is the current method; origin access identity (OAI) is the legacy setup.
- The S3 static website endpoint cannot use OAC; point the origin at the REST endpoint.
- SSE-KMS objects also need the distribution allowed in the KMS key policy.
04HTTPS and custom domains
- Viewer protocol policy can allow HTTP, redirect HTTP to HTTPS, or require HTTPS.
- Custom domains are alternate domain names (CNAMEs) on the distribution.
- The ACM certificate for CloudFront must be requested in us-east-1 (N. Virginia).
- A bare apex domain needs an ALIAS or Route 53 alias record; a CNAME is not allowed.
- One alternate domain name can be attached to only one distribution at a time.
05AWS WAF integration
- A web ACL attached to the distribution filters requests at the edge.
- CloudFront-scope web ACLs must be created in us-east-1.
- Start from AWS managed rule groups, then add rate-based rules for abusive clients.
- Pay-as-you-go WAF bills per ACL, rule and request; flat-rate plans include eligible WAF usage.
- Requests that reach the origin directly skip WAF, so lock the origin to CloudFront.
06Restricting viewer access
- Signed URLs grant one object; signed cookies grant access to several files.
- Use trusted key groups to verify signatures; root-account key pairs are legacy.
- Sign on the server; the private key must never reach the browser.
- Geo restriction allowlists or blocklists countries by viewer IP address.
- Geo rules use the viewer IP, so VPNs bypass them; they are not authentication.
07Functions vs Lambda@Edge
- CloudFront Functions run JavaScript at edge locations, on viewer events only.
- CloudFront Functions have tight run time and memory limits and cannot make network calls.
- Lambda@Edge runs Node.js or Python on viewer and origin events and can call services.
- Lambda@Edge functions must be created in us-east-1 and attached by published version.
- Use CloudFront Functions for header and URL rewrites; Lambda@Edge for heavier logic.
08Origin groups and failover
- An origin group pairs one primary origin with one secondary origin.
- The secondary is used when the primary returns a status code you list, such as 503.
- Failover applies only to GET, HEAD and OPTIONS; other methods get no failover.
- Test failover by making the primary return a listed status code.
- Origin Shield adds one regional cache layer that reduces origin load; it is billed extra.
09Logging and metrics
- Standard logging v2 sends delayed access logs to S3, CloudWatch Logs or Firehose.
- Real-time logs send chosen fields and a sampling rate to Kinesis Data Streams.
- Standard CloudWatch metrics are free and are reported in us-east-1.
- Origin latency is a paid additional-metrics option, enabled per distribution.
- Logging is not retroactive; turn it on before an incident, not during one.
10Pricing model
- Pay-as-you-go bills viewer transfer per GB and requests by region and HTTP/HTTPS type.
- Flat-rate plans bundle CDN, eligible WAF, DNS, Functions and log ingestion for a monthly price.
- Price classes drop some edge locations to lower cost; excluded regions use farther edges.
- Lambda@Edge bills per request and GB-second; Functions bill per invocation outside flat-rate plans.
- Pay-as-you-go invalidations beyond the free allowance bill per path; version assets to avoid them.
11Common patterns
- Static site: private S3 bucket behind OAC, with a default root object of index.html.
- Static site: short TTL on HTML, long TTL on hashed asset file names.
- Single-page app: map 403 and 404 responses to index.html with a 200 status.
- API acceleration: use CachingDisabled or short TTLs; forward needed headers via policy.
- Mixed site: path behaviors route /static/ to S3 and /api/ to the API origin.
12Common pitfalls
- Putting all cookies or headers in the cache key drops the hit ratio sharply.
- For private user responses, disable caching or use min TTL 0 with private/no-store headers.
- The default root object applies only to the site root, not to subfolder URLs.
- S3 returns 403, not 404, for missing objects unless ListBucket is granted.
- By default the origin sees its own Host; forward Host if it routes by Host header.
Go to the source
Use AWS documentation for current limits, availability, and pricing.