Proposed flow for this scenario
- Viewer hostname
- DNS alias to CloudFront
- Viewer certificate and HTTPS policy
- Path cache lookup
- Signed OAC request on a miss
- S3 bucket policy and object
This flow describes a design to evaluate. The local experiment explores one stated mechanism. Its scope appears with the controls; the proposed services are not provisioned.
Decision checkpoints
| Choice | Fits when | Watch for |
|---|---|---|
| Private S3 REST origin + OAC | Public assets should be delivered through a controlled CDN origin path. | Assuming origin privacy restricts who can view the CDN URL. |
| S3 website endpoint as custom origin | Website-endpoint behaviors are an intentional requirement. | Expecting OAC or HTTPS on the website-origin connection. |
| Viewer authorization in addition to origin protection | Customer-specific content needs an independent access decision. | Using an unguessable path as an authorization system. |
Start with two different privacy questions
Suppose a synthetic QuantumSketch gallery publishes reusable illustrations to everyone. The team wants HTTPS and CDN caching, while preventing anonymous reads through the S3 endpoint. These requirements concern the origin path. If a customer document must also be private, the viewer needs a separate authorization design.
A CDN can serve a cached object without fetching it again from S3. Consequently, removing an origin permission is not a complete content-revocation plan. Specify whether the asset is public, who may request it, and how already-delivered copies should be treated before selecting the cache behavior.
Choose the origin deliberately
For the private-bucket design, use the regular S3 bucket endpoint and an OAC configured to always sign requests. Grant the CloudFront service principal the necessary object-read action, scoped to the intended distribution ARN. Keep the bucket private rather than fixing an origin denial with a broad public-read grant.
An S3 website endpoint is a different kind of origin. CloudFront treats it as a custom origin; it cannot use OAC, and that website endpoint does not provide an HTTPS origin connection. Decide whether its website behaviors are worth that different access model. The simulator rejects website origins in its private-OAC workflow.
A custom hostname adds independent dependencies
For a CloudFront viewer certificate obtained through ACM, select us-east-1 and cover the intended hostname. Add that hostname as a distribution alternate domain name and route its public DNS record to the distribution. A DNS record alone neither attaches the hostname to CloudFront nor proves certificate coverage.
In the local exercise, use quantumsketch.shahriarlabs.example as fictional lesson data. Create certificate metadata, reproduce its validation CNAME in the synthetic zone, attach the issued metadata and add the alias. These steps do not register a domain, issue a trusted certificate or change public DNS.
Break the policy, then repair the correct boundary
Upload a synthetic index.html, create the OAC and distribution, then run the local CDN request diagnostic before allowing that distribution in the bucket policy. Inspect the denied origin step. Repair the service-principal and SourceArn relationship, then repeat the request and inspect the miss followed by a hit.
Change the object and repeat the request before the modeled TTL expires. An older cached body is a cache result, not proof that the upload failed. Use the separate stale-content guide to compare expiry, path invalidation and a new asset name.
Security, cost and the changed scenario
This console models one private S3 REST origin, selected policy decisions and a bounded path cache. It does not sign real requests, negotiate TLS, emulate edge locations, authorize signed viewers or calculate a CloudFront bill. The policy experiment below explains access decisions; it does not deploy this architecture.
Question: tomorrow the gallery includes paid customer drafts. Is the same OAC sufficient? No. It still protects only the origin path. Define viewer authorization, private-cache handling and revocation before placing those drafts behind the public gallery behavior. Estimate requests, transfer and invalidations from actual workload assumptions.
Practice the supported console workflow
Create the synthetic origin objects
Uses simulated resources stored on this device. No website account or AWS credentials required.
ExploreTrace the CDN origin and cache
Uses simulated resources stored on this device. No website account or AWS credentials required.
ExploreConfigure certificate metadata
Uses simulated resources stored on this device. No website account or AWS credentials required.
ExploreInspect synthetic DNS records
Uses simulated resources stored on this device. No website account or AWS credentials required.
Explore
Predict it. Test it. Change one thing.
Local educational model. No account or cloud charges. Nothing is deployed to AWS.
{
"Statement": [
{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::lesson-assets/Report.txt"
}
]
}Selected same-account identity-policy behavior. This is not a complete AWS policy simulator.
sim.shahriarlabs.com · Free to explore
Sources and scope
Reviewed against these official references. The model’s supported scope appears alongside its controls.
- AWS: restrict a regular S3 origin with OAC
- AWS: origin privacy and viewer access
- AWS: CloudFront certificate requirements