awsCDN

Amazon CloudFront

Content delivery network that caches responses at edge locations close to viewers. In front of a private S3 bucket it both cuts latency and keeps the bucket itself unreachable from the internet.

Limits

  • Origin access control (OAC) is the recommended way to reach a private S3 origin; the legacy origin access identity (OAI) does not support SSE-KMS, dynamic PUT/POST/DELETE requests, or Regions launched after January 2023

  • When using OAC with an S3 origin, S3 Object Ownership on that bucket must be set to Bucket owner enforced

  • An S3 bucket configured as a website endpoint cannot use OAC or OAI at all and must be attached as a custom origin instead

  • HTTPS between CloudFront and an S3 origin is guaranteed only when the OAC signing behaviour is set to always sign requests

Pricing model

Per-GB data transfer out to the internet, priced by geographic region, plus per-request charges (HTTP and HTTPS differ). Traffic served from the CloudFront cache avoids the S3 GET request and egress charge it replaces.

Cross-provider equivalents

No cross-provider equivalent has been mapped for this service yet.