CloudFront and Global Accelerator
Both services use AWS's global edge network to make applications faster and more resilient for users around the world. They solve different problems, and the exam loves to test the difference.
Amazon CloudFront
A content delivery network (CDN) that caches content at hundreds of edge locations.
Origins
- S3 buckets (private, accessed via Origin Access Control — OAC, which replaces the older Origin Access Identity).
- Custom origins — ALBs, EC2, API Gateway, any HTTP server, including on-premises.
- Origin groups — primary and secondary origins for automatic origin failover.
Key features
| Feature | Use |
|---|---|
| Cache behaviours | Different settings per path pattern (e.g. /static/* cached long, /api/* not cached) |
| TTLs and cache policies | Control how long content stays at the edge and what forms the cache key |
| Invalidations | Remove objects from edge caches before TTL expiry (or use versioned file names) |
| Signed URLs / signed cookies | Restrict access to private content (one file → signed URL; many files → signed cookies) |
| Geo restriction | Allow or block countries |
| HTTPS | ACM certificates (must be in us-east-1); redirect HTTP to HTTPS |
| Field-level encryption | Encrypt specific sensitive form fields at the edge |
| AWS WAF and Shield | Protect at the edge |
| CloudFront Functions | Lightweight JavaScript at the edge for simple header/URL manipulation, very high scale |
| Lambda@Edge | Richer logic (Node.js/Python) at edge locations — e.g. authentication, dynamic origin selection |
"Serve a private S3 bucket globally, users must not access S3 directly" → CloudFront with OAC, and a bucket policy that only allows the CloudFront distribution.
Why CloudFront also helps dynamic sites
Even uncached requests benefit: TLS terminates near the user, and traffic travels over AWS's optimised network to the origin. It also absorbs DDoS traffic at the edge.
AWS Global Accelerator
Gives you two static anycast IP addresses that route users to the nearest healthy endpoint over the AWS global network.
- Endpoints: ALBs, NLBs, EC2 instances, Elastic IPs — in one or more Regions.
- Fast failover between Regions based on health checks — no DNS caching delay.
- Supports TCP and UDP — any application, not just HTTP.
- No caching — it accelerates the network path, not content.
- Traffic dials and endpoint weights shift traffic between Regions.
CloudFront vs Global Accelerator
| Need | Choose |
|---|---|
| Cache static/dynamic web content near users | CloudFront |
| HTTP/HTTPS website or API with caching | CloudFront |
| Non-HTTP traffic (gaming over UDP, IoT, VoIP) | Global Accelerator |
| Fixed static IPs for allow-listing | Global Accelerator |
| Fast, deterministic multi-Region failover without DNS caching issues | Global Accelerator |
| Signed URLs, geo restriction, edge functions | CloudFront |
S3 Transfer Acceleration (for comparison)
Speeds up uploads to S3 from distant clients by routing through edge locations. CloudFront speeds up downloads/delivery.
Exam patterns
- "Users worldwide experience slow loading of images and videos" → CloudFront.
- "A multiplayer game uses UDP and needs low latency globally with static IPs" → Global Accelerator.
- "Restrict premium video downloads to paying users" → CloudFront signed URLs or cookies.
- "Upload large files to a bucket from around the world faster" → S3 Transfer Acceleration (or multipart upload).
- "Serve only to users in certain countries" → CloudFront geo restriction.