Amazon CloudFront
Content delivery network that caches responses at edge locations close to viewers. In front of a private S3 bucket it both cuts latency and keeps the bucket itself unreachable from the internet.
Limits
Origin access control (OAC) is the recommended way to reach a private S3 origin; the legacy origin access identity (OAI) does not support SSE-KMS, dynamic PUT/POST/DELETE requests, or Regions launched after January 2023
When using OAC with an S3 origin, S3 Object Ownership on that bucket must be set to Bucket owner enforced
An S3 bucket configured as a website endpoint cannot use OAC or OAI at all and must be attached as a custom origin instead
HTTPS between CloudFront and an S3 origin is guaranteed only when the OAC signing behaviour is set to always sign requests
Pricing model
Per-GB data transfer out to the internet, priced by geographic region, plus per-request charges (HTTP and HTTPS differ). Traffic served from the CloudFront cache avoids the S3 GET request and egress charge it replaces.
Cross-provider equivalents
No cross-provider equivalent has been mapped for this service yet.