Appearance
CloudFront & Global Accelerator — Theory (Bản gốc slide / Original slide)
1. Amazon CloudFront — Tổng quan (Overview)
- Là một Content Delivery Network (CDN)
- Cải thiện hiệu năng đọc — nội dung được cache tại edge
- Cải thiện trải nghiệm người dùng
- Có hàng trăm Points of Presence trên toàn cầu (edge location, cache)
- Bảo vệ DDoS (nhờ phân tán toàn cầu), tích hợp với AWS Shield và AWS WAF
- A Content Delivery Network (CDN)
- Improves read performance — content is cached at the edge
- Improves user experience
- Hundreds of Points of Presence globally (edge locations, caches)
- DDoS protection (because worldwide), integrates with AWS Shield and AWS WAF
2. CloudFront — Origins
CloudFront có thể lấy nội dung từ 3 loại Origin:
- S3 bucket
- Để phân phối file và cache chúng tại edge
- Để upload file lên S3 thông qua CloudFront
- Bảo mật bằng Origin Access Control (OAC)
- VPC Origin
- Cho ứng dụng host trong VPC private subnet
- Private Application Load Balancer / Network Load Balancer / EC2 Instance
- Custom Origin (HTTP)
- S3 website (phải bật bucket ở chế độ static website trước)
- Bất kỳ HTTP backend public nào (ví dụ: public ALB)
CloudFront can pull content from 3 kinds of Origin:
- S3 bucket
- For distributing files and caching them at the edge
- For uploading files to S3 through CloudFront
- Secured using Origin Access Control (OAC)
- VPC Origin
- For applications hosted in VPC private subnets
- Private Application Load Balancer / Network Load Balancer / EC2 Instances
- Custom Origin (HTTP)
- S3 website (must first enable the bucket as a static S3 website)
- Any public HTTP backend you want (e.g., public ALB)
3. CloudFront — Luồng hoạt động tổng quát (High Level)
- Client gửi request (ví dụ
GET /beach.jpg?size=300x300) tới CloudFront Edge Location gần nhất - Nếu edge đã có bản cache → trả lời ngay từ Local Cache
- Nếu chưa có (cache miss) → edge forward request tới Origin (S3 hoặc HTTP backend), lấy dữ liệu, cache lại, rồi trả về client
- Client sends a request (e.g.,
GET /beach.jpg?size=300x300) to the nearest CloudFront Edge Location - If already cached → answered immediately from the Local Cache
- If not (cache miss) → the edge forwards the request to the Origin (S3 or HTTP backend), fetches the data, caches it, then returns it to the client
4. CloudFront — S3 làm Origin (S3 as an Origin)
- Mỗi CloudFront Edge Location (Los Angeles, Mumbai, São Paulo, Melbourne…) nhận traffic public www từ user gần nó nhất
- Từ edge, CloudFront kết nối tới origin S3 bucket qua mạng nội bộ (private) của AWS — không đi qua Internet công cộng
- Bảo mật bằng Origin Access Control (OAC) + Bucket Policy, đảm bảo chỉ CloudFront mới truy cập được bucket trực tiếp (user không thể bypass CloudFront để gọi thẳng vào S3)
- Each CloudFront Edge Location (Los Angeles, Mumbai, São Paulo, Melbourne…) receives public www traffic from its nearest users
- From the edge, CloudFront connects to the origin S3 bucket over AWS's private network — not over the public Internet
- Secured with Origin Access Control (OAC) + Bucket Policy, ensuring only CloudFront can access the bucket directly (users can't bypass CloudFront to hit S3 directly)
5. CloudFront vs. S3 Cross-Region Replication
| CloudFront | S3 Cross-Region Replication | |
|---|---|---|
| Phạm vi | Global Edge network | Phải setup riêng cho từng region muốn replicate |
| Độ mới của dữ liệu | File được cache theo TTL (có thể cả ngày) | Dữ liệu được cập nhật gần thời gian thực (near real-time) |
| Ghi/Đọc | — | Chỉ đọc (read only) |
| Phù hợp nhất cho | Nội dung tĩnh cần có mặt ở khắp nơi | Nội dung động cần low-latency ở một vài region cụ thể |
| CloudFront | S3 Cross-Region Replication | |
|---|---|---|
| Scope | Global Edge network | Must be set up for each region you want replication to happen |
| Data freshness | Files cached for a TTL (maybe a day) | Files updated in near real-time |
| Read/Write | — | Read only |
| Best fit | Static content that must be available everywhere | Dynamic content needing low-latency in a few specific regions |
6. CloudFront — ALB hoặc EC2 làm Origin
Cách 1 — Using VPC Origins:
- Cho phép phân phối nội dung từ ứng dụng host trong VPC private subnet (không cần expose ra Internet)
- Đưa traffic tới: Application Load Balancer, Network Load Balancer, hoặc EC2 Instance — đều ở chế độ private
Cách 2 — Using Public Network:
- Edge Location gọi tới origin qua địa chỉ IP public
- Security Group của ALB (public) phải cho phép IP public của các Edge Location (danh sách IP:
d7uri8nf7uskq.cloudfront.net/tools/list-cloudfront-ips) - Security Group của EC2 instance (có thể private) chỉ cần cho phép traffic từ Security Group của ALB
⚠️ VPC Origins là cách khuyến nghị hơn vì không cần expose origin ra Internet — an toàn hơn nhiều so với dùng Public Network.
Option 1 — Using VPC Origins:
- Allows you to deliver content from applications hosted in your VPC private subnets (no need to expose them on the Internet)
- Delivers traffic to: Application Load Balancer, Network Load Balancer, or EC2 Instances — all private
Option 2 — Using Public Network:
- The Edge Location reaches the origin over its public IP
- The public ALB's Security Group must allow the public IPs of the Edge Locations (IP list:
d7uri8nf7uskq.cloudfront.net/tools/list-cloudfront-ips) - The EC2 instance's Security Group (which can be private) only needs to allow traffic from the ALB's Security Group
⚠️ VPC Origins is the recommended approach since it doesn't require exposing the origin to the Internet — much safer than the Public Network approach.
7. CloudFront — Geo Restriction
- Có thể giới hạn ai truy cập được distribution:
- Allowlist: chỉ cho phép user truy cập nội dung nếu họ ở trong danh sách quốc gia được duyệt
- Blocklist: chặn user truy cập nếu họ ở trong danh sách quốc gia bị cấm
- "Quốc gia" được xác định bằng Geo-IP database của bên thứ ba
- Use case: kiểm soát truy cập nội dung theo luật bản quyền (Copyright Laws)
- You can restrict who can access your distribution:
- Allowlist: allow users to access your content only if they're in one of the approved countries
- Blocklist: prevent users from accessing your content if they're in one of the banned countries
- The "country" is determined using a 3rd party Geo-IP database
- Use case: Copyright Laws to control access to content
8. CloudFront — Cache Invalidations
- Khi bạn update backend origin, CloudFront không hề hay biết và chỉ lấy nội dung mới sau khi TTL hết hạn
- Có thể buộc refresh cache (toàn bộ hoặc một phần), bỏ qua TTL, bằng cách thực hiện CloudFront Invalidation
- Có thể invalidate toàn bộ file (
*) hoặc một path cụ thể (/images/*)
- When you update the back-end origin, CloudFront doesn't know about it and will only get the refreshed content after the TTL has expired
- You can force an entire or partial cache refresh (bypassing the TTL) by performing a CloudFront Invalidation
- You can invalidate all files (
*) or a specific path (/images/*)
9. Bài toán: Người dùng toàn cầu & Độ trễ (Global Users & Latency)
- Bạn đã deploy một ứng dụng và có user trên toàn cầu muốn truy cập trực tiếp
- Traffic đi qua Internet công cộng, có thể cộng dồn nhiều latency vì đi qua nhiều hop
- Ta muốn đi càng nhanh càng tốt qua mạng nội bộ của AWS để giảm thiểu latency
- You have deployed an application and have global users who want to access it directly
- They go over the public Internet, which can add a lot of latency due to many hops
- We wish to go as fast as possible through AWS's network to minimize latency
10. Unicast IP vs. Anycast IP
- Unicast IP: một server giữ một địa chỉ IP — mỗi server có IP riêng biệt
- Anycast IP: tất cả server cùng giữ chung một địa chỉ IP, và client sẽ được định tuyến tới server gần nhất
- Unicast IP: one server holds one IP address — each server has its own distinct IP
- Anycast IP: all servers hold the same IP address, and the client is routed to the nearest one
11. AWS Global Accelerator — Tổng quan (Overview)
- Tận dụng mạng nội bộ của AWS để định tuyến tới ứng dụng của bạn
- Tạo ra 2 Anycast IP cho ứng dụng
- Anycast IP gửi traffic thẳng tới Edge Location gần nhất
- Edge Location sau đó chuyển traffic tới ứng dụng của bạn (ở region gần nhất)
- Leverages the AWS internal network to route to your application
- 2 Anycast IPs are created for your application
- The Anycast IPs send traffic directly to Edge Locations
- The Edge Locations then send the traffic to your application
12. AWS Global Accelerator — Đặc điểm (Features)
- Hoạt động với Elastic IP, EC2 instance, ALB, NLB — cả public lẫn private
- Hiệu năng ổn định (Consistent Performance):
- Định tuyến thông minh tới nơi có latency thấp nhất, failover vùng nhanh
- Không gặp vấn đề với client cache (vì IP không hề thay đổi)
- Đi qua mạng nội bộ AWS
- Health Checks:
- Global Accelerator tự kiểm tra health ứng dụng của bạn
- Giúp ứng dụng hoạt động toàn cầu (failover dưới 1 phút khi phát hiện unhealthy)
- Rất tốt cho disaster recovery (nhờ health check)
- Bảo mật (Security):
- Chỉ cần whitelist 2 IP bên ngoài (2 Anycast IP)
- Bảo vệ DDoS nhờ AWS Shield
- Works with Elastic IP, EC2 instances, ALB, NLB — both public or private
- Consistent Performance:
- Intelligent routing to the lowest latency, fast regional failover
- No issue with client cache (because the IP doesn't change)
- Uses the internal AWS network
- Health Checks:
- Global Accelerator performs a health check of your applications
- Helps make your application global (failover less than 1 minute for unhealthy)
- Great for disaster recovery (thanks to the health checks)
- Security:
- Only 2 external IPs need to be whitelisted
- DDoS protection thanks to AWS Shield
13. AWS Global Accelerator vs. CloudFront
- Cả hai đều dùng mạng global và edge location của AWS
- Cả hai đều tích hợp với AWS Shield để chống DDoS
CloudFront:
- Tăng hiệu năng cho nội dung có thể cache (ảnh, video…)
- Cũng hỗ trợ nội dung động (API acceleration, dynamic site delivery)
- Nội dung được phục vụ ngay tại edge
Global Accelerator:
- Tăng hiệu năng cho nhiều loại ứng dụng đa dạng chạy trên TCP hoặc UDP
- Proxy packet tại edge tới ứng dụng chạy ở một hoặc nhiều AWS Region
- Rất phù hợp cho use case không phải HTTP: gaming (UDP), IoT (MQTT), Voice over IP
- Phù hợp cho use case HTTP cần địa chỉ IP tĩnh (static IP)
- Phù hợp cho use case HTTP cần failover vùng nhanh, xác định được (deterministic)
- Both use the AWS global network and edge locations around the world
- Both integrate with AWS Shield for DDoS protection
CloudFront:
- Improves performance for cacheable content (images, videos…)
- Also supports dynamic content (API acceleration, dynamic site delivery)
- Content is served at the edge
Global Accelerator:
- Improves performance for a wide range of applications over TCP or UDP
- Proxies packets at the edge to applications running in one or more AWS Regions
- Great fit for non-HTTP use cases: gaming (UDP), IoT (MQTT), Voice over IP
- Good for HTTP use cases that require static IP addresses
- Good for HTTP use cases that require deterministic, fast regional failover