Proposed flow for this scenario
- Hostname lookup
- Distribution alternate domain
- Viewer certificate
- Cache behavior
- Origin permission
- Object result
This flow describes a design to evaluate. The local experiment explores one stated mechanism. Its scope appears with the controls; the proposed services are not provisioned.
Decision checkpoints
| Choice | Fits when | Watch for |
|---|---|---|
| DNS fault | The name resolves incorrectly or does not resolve. | Editing origin permissions before establishing a route. |
| Viewer TLS fault | The client cannot establish a valid hostname-bound HTTPS connection. | Assuming an issued certificate is attached and covers every hostname. |
| Origin fault | The request reaches the distribution but the origin fetch fails. | Calling every HTTP error a DNS propagation issue. |
Start with the observed failure, not the most recent edit
Imagine that quantumsketch.shahriarlabs.example stops serving a synthetic image after a DNS and bucket-policy update. Write down what failed: name resolution, a TLS warning, an HTTP status, or the wrong response body. Those observations lead to different boundaries.
In a real environment, compare the intended public DNS authority with the resolver result and the distribution configuration. A record in an unused hosted zone can look correct in a dashboard while never answering the public domain. The simulator has fictional zones, so it cannot test delegation or a real resolver.
Check the hostname, alias and certificate as separate records
For Route 53 routing to CloudFront, the public alias points to the distribution and the distribution includes the same alternate hostname. An alias is not a certificate validation record. Conversely, ACM validation CNAMEs establish certificate-domain validation; they do not route application traffic.
The viewer certificate needs the intended hostname in its coverage and must be selected from us-east-1 when using ACM with CloudFront. Compare exact names and wildcard scope. A wildcard for *.shahriarlabs.example does not cover a deeper name such as assets.team.shahriarlabs.example.
Only then inspect the origin decision
If a request reaches the distribution, inspect its origin type and object path. For the private S3 workflow, compare the OAC association and the bucket policy distribution ARN. A policy for another distribution cannot justify this one.
A cached response may avoid the origin entirely. Reproduce a cache miss or a controlled invalidation when checking a changed origin permission. Do not make the whole bucket public merely because a CDN fetch is denied; repair the specific principal, resource or condition mismatch.
Use the local trace without pretending it is a network probe
In the console, request certificate metadata in us-east-1, copy the provided CNAME into the synthetic zone and run the certificate-DNS-validation diagnostic. Remove that CNAME before completion and inspect why issuance stays pending. Re-add it and repeat the modeled check.
After attaching the issued certificate metadata and alternate name, create the matching CloudFront alias. Use the local CDN diagnostic to inspect the selected distribution and origin result. Its issuance state means local metadata matched; there is no trusted certificate, live handshake, public DNS or internet request.
Counterexample and decision question
Question: the distribution hostname serves the right image, but the custom hostname produces a browser certificate warning. Should the S3 policy be broadened? No. The working distribution path is evidence against that first hypothesis. Check the custom-name routing, attached viewer certificate and hostname coverage.
For an actual outage, preserve timestamped resolver, handshake and request evidence. Monitor renewal and domain ownership separately from origin health. This network experiment explains configuration paths; it cannot reproduce CAA failures, real certificate renewal, DNSSEC, edge propagation or an origin TLS handshake.
Practice the supported console workflow
Inspect the synthetic zone
Uses simulated resources stored on this device. No website account or AWS credentials required.
ExploreCheck certificate metadata
Uses simulated resources stored on this device. No website account or AWS credentials required.
ExploreTrace the distribution request
Uses simulated resources stored on this device. No website account or AWS credentials required.
Explore
Predict it. Test it. Change one thing.
Local educational model. No account or cloud charges. Nothing is deployed to AWS.
sim.shahriarlabs.com · Free to explore
Sources and scope
Reviewed against these official references. The model’s supported scope appears alongside its controls.
- AWS: Route 53 alias to CloudFront
- AWS: viewer and origin certificate requirements
- AWS: ACM DNS validation