Amazon CloudFront
CloudFront
You need to deliver web content, static assets, and APIs to users globally with low latency and high transfer speeds.
Reach for it when
- Caching static website files (HTML, JS, CSS, images) at edge locations close to users worldwide.
- Offloading SSL/TLS negotiation from backend web servers to a globally distributed edge network.
- Restricting access to private media files using signed URLs or signed cookies.
Do not reach for it when
- Serving highly personalized dynamic data that cannot be cached and has no benefit from edge routing — use ALB instead.
- Routing internal microservice traffic within a private network — use Application Load Balancer instead.
- Managing domain registration and DNS record routing without caching needs — use Route 53 instead.
Alternatives, and how to choose
| Service | Pick it instead when |
|---|---|
| Route 53 | Choose it when you only need DNS resolution and global traffic routing without caching content. |
| ALB | Choose it when exposing dynamic backend APIs that do not benefit from edge caching. |
How you pay
- The model
- Pay for data transfer out from edge locations to the internet and the number of HTTP/HTTPS requests.
- The line item that surprises people
- Failing to configure cache invalidation correctly can lead to frequent wildcard invalidation API charges.
What trips people up
- Updating files on the origin does not update the edge immediately; invalidations are required to clear cached files.
- Failing to forward query strings, headers, or cookies to the origin can break backend application logic.
- The default behavior cache time-to-live is 24 hours; files will remain stale at edge locations unless customized.
Verify the live service
This page is a concept reference. Cost models are qualitative; confirm the current offering, Region and pricing before deploying.