Memory hook: CloudFront caches HTTP content, Global Accelerator routes network connections, and replication creates durable regional copies.
Must remember
Match the origin and cache behavior to the application
- CloudFront accepts viewer HTTP(S) requests at edge locations. A distribution can use different origins and cache behaviors for static assets and dynamic API paths.
- S3 REST origin plus OAC: CloudFront signs origin requests, and a bucket policy permits the intended distribution. The bucket can remain private. For SSE-KMS objects, the key policy also needs appropriate access.
- An S3 website endpoint is a custom origin, cannot use OAC, and does not provide origin HTTPS. Do not choose it when the requirement is private S3 access through signed origin requests. S3 origin restrictions
- ALB/EC2 origins serve dynamic HTTP applications. CloudFront can pass requests through without caching user-specific responses; “CDN” does not mean static files only.
- Current VPC origins support eligible private-subnet ALBs, NLBs and EC2 instances, subject to service/Region constraints. Do not memorize the outdated rule that every application origin must be public. Public custom origins still need protection against bypassing the distribution. VPC origins
Keep caching separate from authorization
- The cache key decides which requests can reuse a response. Include only relevant headers, cookies and query parameters: unnecessary variation lowers hit rate; missing user-specific variation can expose private content.
- The origin request policy decides what reaches the backend. Forwarding a value and including it in the cache key are different decisions. Disable caching where that is the safest fit for personalized data.
- TTL bounds freshness. Versioned object names make immutable assets easy to update without replacing the contents behind a cached URL. Invalidations remove cached paths earlier and may add cost.
- Signed URLs suit individual restricted resources or clients that do not support cookies. Signed cookies suit access to multiple restricted files without rewriting each URL, such as a media presentation with many segments.
- OAC authorizes CloudFront to S3; signed URLs/cookies authorize viewers to CloudFront. They solve different boundaries and may be used together. Signed access choices
- Geo restriction controls viewer countries based on location signals. Price classes constrain the eligible edge footprint to trade price against reach. Neither determines the S3 bucket's storage Region or guarantees data residency.
- TLS applies on both viewer and origin connections. For a CloudFront custom hostname using ACM, the viewer certificate is obtained in us-east-1; an ALB's certificate is regional to that ALB.
Distinguish routing, resilience and edge code
- Global Accelerator provides static anycast IPs and routes TCP/UDP through AWS networking to supported healthy endpoints. Endpoint groups are regional; traffic dials and endpoint weights influence traffic distribution.
- It does not cache S3 objects or replace application authorization. Its control API uses us-west-2, although application endpoints can be elsewhere. Global Accelerator overview
- S3 CRR stores durable copies in another Region. CloudFront caches can expire or evict objects, so caching alone is not regional disaster recovery.
- CloudFront Functions is for lightweight viewer request/response logic, such as URL or header changes. Lambda@Edge supports richer processing and origin events, with different limits and replicated-resource lifecycle behavior.
- CloudFront changes/deletion need propagation. Lambda@Edge replicas can delay cleanup; avoid treating edge code as an ordinary instantly deleted regional function. See serverless services and S3 replication.
Choose under exam pressure
| Requirement in the question | Best direction |
|---|---|
| Millions of identical global HTTP downloads | CloudFront caching |
| Private S3 origin with controlled viewer access | OAC plus signed viewer access |
| Many restricted media segments | Signed cookies |
| Static global IPs for TCP/UDP applications | Global Accelerator |
| Durable regional recovery copy | S3 CRR |
| Personalized API behind an ALB | Appropriate cache policy or caching disabled |
| Simple viewer URL/header rewrite | CloudFront Functions |
Traps
- A CDN cache is not a backup, and a replica is not an authorization mechanism.
- Country filtering is not the same as choosing where original data is stored.
- Allowing all CloudFront traffic to a public origin does not necessarily restrict access to your specific distribution.
- A long TTL on a personalized response can be a security mistake, not just a freshness mistake.
Active recall
1. A private S3 bucket serves paid video made of many files. Which two controls protect the two access boundaries?
Use OAC and a scoped bucket policy for CloudFront-to-S3 access, and signed cookies for the viewer's access to the collection. OAC alone would not establish who paid.
2. A globally used UDP application requires stable allow-listed IPs. CloudFront or Global Accelerator?
Global Accelerator fits TCP/UDP routing and static anycast IPs. CloudFront is an HTTP(S) delivery service; object caching is not the requirement.
3. An API varies responses by authenticated customer. Why is forwarding the identity header insufficient?
The cache may still reuse one response across customers if its key ignores the relevant identity context. Choose safe cache separation or disable caching for that behavior.
4. A software release needs fresh downloads immediately. Why prefer versioned filenames to repeated broad invalidations?
A new immutable key has a distinct cache identity, allowing long caching of old assets without serving them as the new release. Broad invalidations add coordination and possible cost.
5. An origin Region fails. Why don't populated edge caches satisfy a durable DR requirement?
Caches may lack requested objects and can expire or evict them. Durable regional copies and an origin failover/recovery design address a failure class that caching alone does not.
Terraform anchor: Guard optional resource references and review distribution, origin-policy and viewer-access changes as separate plan decisions.