What the exam asks
- Speed up static and dynamic web content for global users, and reduce load on the origin.
- Protect content: private S3 origins, paid content, country restrictions, origins that cannot be bypassed.
- Fail over between origins or Regions automatically.
- Run logic at the edge with the cheapest tool that can do the job.
- Give non-HTTP or allow-listed clients fixed IP addresses and fast Regional failover.
Core ideas
CloudFront building blocks
- Origins: an S3 bucket, an ALB, EC2, API Gateway, a Lambda function URL or any custom HTTP server. One distribution can have many origins.
- Cache behaviours: path patterns (
/api/*,/images/*, the default*) that route requests to an origin, each with its own cache and viewer settings. Behaviours let a single domain serve an S3 front end and an ALB API. - Cache key and TTLs: a cache policy decides which headers, cookies and query strings make up the cache key, plus the minimum, default and maximum TTL. Anything in the cache key splits the cache, so include only the values that change the response. An origin request policy forwards values to the origin without adding them to the key.
- Invalidations remove objects before their TTL expires. For frequent releases, versioned file names (
app.v42.js) are cheaper and more reliable. - Origin Shield adds a central caching layer in front of the origin to raise the overall hit rate and protect the origin.
- Dynamic content: even with caching disabled, CloudFront speeds up APIs because it reuses TLS connections and carries traffic over the AWS backbone.
Securing content
| Requirement | Feature |
|---|---|
| S3 bucket readable only through CloudFront | Origin access control (OAC) plus a bucket policy that allows the CloudFront service principal for that distribution. OAC replaces the legacy OAI and supports SSE-KMS |
| One protected file per link (a download) |