Amazon Web Services
Content Delivery — CloudFront & Edge Caching
Serve content from locations near the user, cut origin load, and know what is cacheable and what is not.
CloudFront is a CDN: a network of edge locations that cache your responses close to users.
A chain of local branch libraries. The first person to ask for a book waits while it comes from the central store; everyone else nearby borrows the local copy.
Key Concepts
1
user (Mumbai) -> edge (Mumbai) -> [miss] -> origin (us-east-1 S3/ALB)
<- cached for the TTL
next user -> edge (Mumbai) -> [hit] -> served in milliseconds2
Two wins, and interviewers want both. Latency drops because the bytes travel less far. Origin load drops
because a cache hit never reaches it — which is also what absorbs a traffic spike.
3
A behaviour decides how a path is treated.
/static/* cache 1 year, ignore cookies and query strings
/api/* do not cache, forward all headers and cookies
default cache 1 hour4
Ordering matters: the first matching behaviour wins, so the specific paths go above the default.
5
The cache key is what you choose to vary on.
too narrow users get each other's personalised pages
too wide every request is a miss and the CDN does nothing6
Forwarding every cookie is the classic mistake — it makes the key unique per user, so the hit rate collapses
to zero and you pay for a CDN that caches nothing.
7
TTL comes from the origin unless you override it.
Cache-Control: public, max-age=31536000, immutable -- hashed assets
Cache-Control: no-store -- never cache8
Invalidation is the escape hatch, not the plan. It is slow and charged beyond the free allowance.
Versioned filenames — app.8f3c2a.js — are the better answer, because a new name is simply a new object.
app.8f3c2a.js
9
Origin Access Control keeps the bucket private. The S3 bucket blocks public access and trusts only
CloudFront, so nobody can bypass the CDN and hit the origin directly.
10
Signed URLs and cookies gate private content for a limited time, which is how paid video and
customer-specific downloads work.
11
It also terminates TLS at the edge and integrates with AWS WAF and Shield, so filtering happens far from
your origin.
12
What the interviewer is probing.1. "Your hit rate is near zero. What is the most likely cause?" Probing: the cache key.
Stalls: "Not enough traffic." Moves up: forwarding cookies or unnecessary query strings makes
every request unique, so nothing is ever reused.
13
2. "How do you push out a new version of a static asset?" Probing: invalidation versus
versioning. Stalls: "Invalidate the path." Moves up: version the filename — app.8f3c2a.js is
simply a new object; invalidation is slow and chargeable, and belongs to emergencies.
14
3. "How do you stop people bypassing CloudFront and hitting S3 directly?" Probing: origin
access. Stalls: "Make the bucket private." Moves up: Origin Access Control plus Block Public
Access, so the bucket trusts only the distribution.
15
4. "What is the risk of caching an authenticated response?" Probing: the data leak. Stalls:
"It is faster." Moves up: one user's page served to another, unless identity is part of the cache
key or the response is marked private.