Proposed flow for this scenario
- Website behavior requirement
- Origin endpoint choice
- Origin authorization
- Viewer hostname and HTTPS
- Cache and publication lifecycle
This flow describes a design to evaluate. The local experiment explores one stated mechanism. Its scope appears with the controls; the proposed services are not provisioned.
Decision checkpoints
| Choice | Fits when | Watch for |
|---|---|---|
| S3 website endpoint | Its website-specific behavior is needed with an intentional public/custom-origin arrangement. | Expecting the endpoint to support HTTPS or OAC. |
| Private S3 REST origin + CloudFront OAC | The origin should remain private while the CDN serves suitable content. | Assuming a private origin makes a public viewer URL private. |
| Another static hosting platform | Its deployment and route behavior fit the real project. | Assuming an AWS lesson requires the learning site itself to use AWS. |
Ask which behavior belongs to the origin
A synthetic QuantumSketch gallery needs an index document, asset paths and a custom hostname. Decide how deep links and missing pages should behave. An S3 website endpoint and a regular object API endpoint are different interfaces, not merely two spellings of the same URL.
CloudFront can use a website endpoint as a custom origin, but that choice changes the origin security and protocol options. Do not copy the private-S3 OAC instructions into a website-origin configuration and expect them to apply.
Compare privacy on both sides of the CDN
The regular S3 private-origin design uses OAC and a bucket policy for the intended distribution. A website endpoint cannot use OAC and does not support an HTTPS origin connection. Viewer HTTPS at CloudFront is a separate connection from the origin path.
Public gallery assets may be available to everyone through the CDN while remaining unavailable through direct anonymous S3 reads. Customer-only drafts require a viewer authorization design as well. Changing the origin endpoint is not a substitute for that decision.
Plan deep links and error responses deliberately
A static single-page application and a set of prerendered documents have different routing needs. Define the response for an actual missing asset separately from an application route. Returning HTML with a success status for every broken file can conceal deployment errors and confuse clients.
The local CloudFront subset supports a private S3 REST origin and a default root mapping. It rejects website/custom origins and does not model arbitrary error-response rewrites. The local S3 website settings are selected metadata, not a working public website endpoint.
Original comparison worksheet
For the scenario worksheet, test three requested paths: the homepage, an existing image and a missing image. Write the expected status and content type for each, then test a deep application route separately. This exposes whether a fallback intended for navigation also masks an accidentally missing release asset.
Next, ask whether an anonymous viewer should receive each object and whether an anonymous direct-origin request should receive it. Those answers can differ. Preserve that distinction in the bucket policy and publication procedure. A clean public viewer experience does not require pretending all origin endpoints have the same security behavior.
A changed requirement exposes the trade-off
Question: QuantumSketch wants a private origin and also depends on a website-endpoint redirect. Does enabling OAC on the website endpoint satisfy both? No. Review how to implement the required redirect elsewhere or choose a different access arrangement deliberately.
Use the S3 access experiment below to inspect selected public-read decisions, then practice the private-origin console trace. Neither publishes a website or negotiates TLS. Compare complete hosting, transfer and operations with current requirements; the learning platform’s Cloudflare Pages deployment is a separate practical product choice.
Practice the supported console workflow
Predict it. Test it. Change one thing.
Local educational model. No account or cloud charges. Nothing is deployed to AWS.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::lesson-assets/*"
}
]
}Assumes the object exists and the policy has already been stored. BlockPublicPolicy controls submission of public policies; RestrictPublicBuckets controls the public read modeled here. KMS, ACLs and endpoint policies are outside this model.
sim.shahriarlabs.com · Free to explore
Sources and scope
Reviewed against these official references. The model’s supported scope appears alongside its controls.
How we review explanations