Proposed flow for this scenario

  1. Website behavior requirement
  2. Origin endpoint choice
  3. Origin authorization
  4. Viewer hostname and HTTPS
  5. Cache and publication lifecycle

This flow describes a design to evaluate. The local experiment explores one stated mechanism. Its scope appears with the controls; the proposed services are not provisioned.

Decision checkpoints

ChoiceFits whenWatch for
S3 website endpointIts website-specific behavior is needed with an intentional public/custom-origin arrangement.Expecting the endpoint to support HTTPS or OAC.
Private S3 REST origin + CloudFront OACThe origin should remain private while the CDN serves suitable content.Assuming a private origin makes a public viewer URL private.
Another static hosting platformIts deployment and route behavior fit the real project.Assuming an AWS lesson requires the learning site itself to use AWS.

Ask which behavior belongs to the origin

A synthetic QuantumSketch gallery needs an index document, asset paths and a custom hostname. Decide how deep links and missing pages should behave. An S3 website endpoint and a regular object API endpoint are different interfaces, not merely two spellings of the same URL.

CloudFront can use a website endpoint as a custom origin, but that choice changes the origin security and protocol options. Do not copy the private-S3 OAC instructions into a website-origin configuration and expect them to apply.

Compare privacy on both sides of the CDN

The regular S3 private-origin design uses OAC and a bucket policy for the intended distribution. A website endpoint cannot use OAC and does not support an HTTPS origin connection. Viewer HTTPS at CloudFront is a separate connection from the origin path.

Public gallery assets may be available to everyone through the CDN while remaining unavailable through direct anonymous S3 reads. Customer-only drafts require a viewer authorization design as well. Changing the origin endpoint is not a substitute for that decision.

Plan deep links and error responses deliberately

A static single-page application and a set of prerendered documents have different routing needs. Define the response for an actual missing asset separately from an application route. Returning HTML with a success status for every broken file can conceal deployment errors and confuse clients.

The local CloudFront subset supports a private S3 REST origin and a default root mapping. It rejects website/custom origins and does not model arbitrary error-response rewrites. The local S3 website settings are selected metadata, not a working public website endpoint.

Original comparison worksheet

For the scenario worksheet, test three requested paths: the homepage, an existing image and a missing image. Write the expected status and content type for each, then test a deep application route separately. This exposes whether a fallback intended for navigation also masks an accidentally missing release asset.

Next, ask whether an anonymous viewer should receive each object and whether an anonymous direct-origin request should receive it. Those answers can differ. Preserve that distinction in the bucket policy and publication procedure. A clean public viewer experience does not require pretending all origin endpoints have the same security behavior.

A changed requirement exposes the trade-off

Question: QuantumSketch wants a private origin and also depends on a website-endpoint redirect. Does enabling OAC on the website endpoint satisfy both? No. Review how to implement the required redirect elsewhere or choose a different access arrangement deliberately.

Use the S3 access experiment below to inspect selected public-read decisions, then practice the private-origin console trace. Neither publishes a website or negotiates TLS. Compare complete hosting, transfer and operations with current requirements; the learning platform’s Cloudflare Pages deployment is a separate practical product choice.

Practice the supported console workflow

SimAWS · ShahriarLabs

Predict it. Test it. Change one thing.

Local educational model. No account or cloud charges. Nothing is deployed to AWS.

Anonymous index.html request
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::lesson-assets/*"
    }
  ]
}

Assumes the object exists and the policy has already been stored. BlockPublicPolicy controls submission of public policies; RestrictPublicBuckets controls the public read modeled here. KMS, ACLs and endpoint policies are outside this model.

sim.shahriarlabs.com · Free to explore

Sources and scope

Reviewed against these official references. The model’s supported scope appears alongside its controls.

How we review explanations