Proposed flow for this scenario
- Confirm requested hostname and path
- Inspect current origin object
- Identify cached response
- Choose new filename, expiry or invalidation
- Verify the requested revision
This flow describes a design to evaluate. The local experiment explores one stated mechanism. Its scope appears with the controls; the proposed services are not provisioned.
Decision checkpoints
| Choice | Fits when | Watch for |
|---|---|---|
| Versioned asset filename | A release can update references to immutable assets. | Overwriting the same supposedly immutable path. |
| Targeted path invalidation | An existing URL must refresh before CDN expiry. | Assuming it clears browser or intermediary caches. |
| Wait for expiry | The stale period is acceptable under the freshness requirement. | Treating TTL as permission to cache customer-specific responses unsafely. |
Reproduce the exact stale request
In this synthetic QuantumSketch release, index.html references scene-v1.svg. Uploading scene-v2.svg cannot change a browser that still requests scene-v1.svg. Before clearing anything, record the hostname, full path, expected revision and how the HTML refers to the asset. A release may be consistent but still point at its previous asset set.
Compare that request with the current origin object. In real infrastructure, inspect response headers and relevant logs as evidence of which cache answered. The browser, a proxy and the CDN are distinct caches; the local exercise models only one bounded CDN path cache.
Choose the smallest repair that matches the requirement
A new filename lets the next release request a different asset while old references remain usable. Keep the previous release files for a defined retention period so an old tab or rollback does not immediately lose its dependencies. Do not label an overwritten filename immutable.
When the existing path must refresh, invalidate the appropriate CDN path. An invalidation causes a later edge request to retrieve the origin content, but does not erase an already cached browser copy. Decide separately how the HTML and browser-facing freshness policy should behave.
Run the local stale-object drill
Create the private S3/CloudFront exercise and request /index.html once. Replace the S3 object body with a second synthetic revision and request the same path before the modeled TTL expires. The hit should still show the previously cached body.
Create an invalidation for /index.html, advance simulated time through completion and repeat the request. This model maps the default root request / to the /index.html cache key. Use that explicit path or the supported /* wildcard for this drill; do not infer that its root mapping reproduces every real CloudFront configuration.
A permission change does not rewrite cached history
An origin-policy revocation blocks a new fetch, but a populated cache may still contain content previously fetched legitimately. The local diagnostic exposes that difference: try a hit after revocation, then invalidate and observe the denied miss. The order matters.
For sensitive material, define a revocation procedure spanning viewer access, edge caches and already-delivered copies. A shared-cache hit is unacceptable when the cache key or authorization behavior mixes customers. The path-only simulator cannot validate cookies, headers, query-string variants or private customer isolation.
Release question and practical limits
Question: a new homepage deploy references scene-v2.svg, but some viewers see a blank page after rollback. What should be checked? Inspect which HTML revision they received and whether both release asset sets still exist. A rollback that restores HTML but deletes its dependencies is incomplete.
The cache experiment below is conceptual. Console requests are local diagnostics with accelerated expiry and invalidation, no network fetch or geographical edge simulation. Measure real freshness and transfer costs in a deployed system; this exercise cannot establish a latency benefit or a savings percentage.
Practice the supported console workflow
Predict it. Test it. Change one thing.
Local educational model. No account or cloud charges. Nothing is deployed to AWS.
Break-even hit rate: 20.0%. User-supplied illustrative costs; excludes bandwidth, cache request charges, staleness and invalidation.
sim.shahriarlabs.com · Free to explore
Sources and scope
Reviewed against these official references. The model’s supported scope appears alongside its controls.
How we review explanations