Skip to content

CloudFront & Global Accelerator — Theory (Bản gốc slide / Original slide)

1. Amazon CloudFront — Tổng quan (Overview)

  • Là một Content Delivery Network (CDN)
  • Cải thiện hiệu năng đọc — nội dung được cache tại edge
  • Cải thiện trải nghiệm người dùng
  • hàng trăm Points of Presence trên toàn cầu (edge location, cache)
  • Bảo vệ DDoS (nhờ phân tán toàn cầu), tích hợp với AWS ShieldAWS WAF
  • A Content Delivery Network (CDN)
  • Improves read performance — content is cached at the edge
  • Improves user experience
  • Hundreds of Points of Presence globally (edge locations, caches)
  • DDoS protection (because worldwide), integrates with AWS Shield and AWS WAF

2. CloudFront — Origins

CloudFront có thể lấy nội dung từ 3 loại Origin:

  • S3 bucket
    • Để phân phối file và cache chúng tại edge
    • Để upload file lên S3 thông qua CloudFront
    • Bảo mật bằng Origin Access Control (OAC)
  • VPC Origin
    • Cho ứng dụng host trong VPC private subnet
    • Private Application Load Balancer / Network Load Balancer / EC2 Instance
  • Custom Origin (HTTP)
    • S3 website (phải bật bucket ở chế độ static website trước)
    • Bất kỳ HTTP backend public nào (ví dụ: public ALB)

CloudFront can pull content from 3 kinds of Origin:

  • S3 bucket
    • For distributing files and caching them at the edge
    • For uploading files to S3 through CloudFront
    • Secured using Origin Access Control (OAC)
  • VPC Origin
    • For applications hosted in VPC private subnets
    • Private Application Load Balancer / Network Load Balancer / EC2 Instances
  • Custom Origin (HTTP)
    • S3 website (must first enable the bucket as a static S3 website)
    • Any public HTTP backend you want (e.g., public ALB)

3. CloudFront — Luồng hoạt động tổng quát (High Level)

ClientGET /beach.jpg?size=300x300CloudFrontEdge LocationLocal Cacheforward on cache missS3orHTTPOrigin
  • Client gửi request (ví dụ GET /beach.jpg?size=300x300) tới CloudFront Edge Location gần nhất
  • Nếu edge đã có bản cache → trả lời ngay từ Local Cache
  • Nếu chưa có (cache miss) → edge forward request tới Origin (S3 hoặc HTTP backend), lấy dữ liệu, cache lại, rồi trả về client
  • Client sends a request (e.g., GET /beach.jpg?size=300x300) to the nearest CloudFront Edge Location
  • If already cached → answered immediately from the Local Cache
  • If not (cache miss) → the edge forwards the request to the Origin (S3 or HTTP backend), fetches the data, caches it, then returns it to the client

4. CloudFront — S3 làm Origin (S3 as an Origin)

Edge — LAEdge — MumbaiEdge — São PauloEdge — MelbourneS3 BucketOriginOAC + Bucket PolicyPrivate AWS network
  • Mỗi CloudFront Edge Location (Los Angeles, Mumbai, São Paulo, Melbourne…) nhận traffic public www từ user gần nó nhất
  • Từ edge, CloudFront kết nối tới origin S3 bucket qua mạng nội bộ (private) của AWS — không đi qua Internet công cộng
  • Bảo mật bằng Origin Access Control (OAC) + Bucket Policy, đảm bảo chỉ CloudFront mới truy cập được bucket trực tiếp (user không thể bypass CloudFront để gọi thẳng vào S3)
  • Each CloudFront Edge Location (Los Angeles, Mumbai, São Paulo, Melbourne…) receives public www traffic from its nearest users
  • From the edge, CloudFront connects to the origin S3 bucket over AWS's private network — not over the public Internet
  • Secured with Origin Access Control (OAC) + Bucket Policy, ensuring only CloudFront can access the bucket directly (users can't bypass CloudFront to hit S3 directly)

5. CloudFront vs. S3 Cross-Region Replication

CloudFrontS3 Cross-Region Replication
Phạm viGlobal Edge networkPhải setup riêng cho từng region muốn replicate
Độ mới của dữ liệuFile được cache theo TTL (có thể cả ngày)Dữ liệu được cập nhật gần thời gian thực (near real-time)
Ghi/ĐọcChỉ đọc (read only)
Phù hợp nhất choNội dung tĩnh cần có mặt ở khắp nơiNội dung động cần low-latencymột vài region cụ thể
CloudFrontS3 Cross-Region Replication
ScopeGlobal Edge networkMust be set up for each region you want replication to happen
Data freshnessFiles cached for a TTL (maybe a day)Files updated in near real-time
Read/WriteRead only
Best fitStatic content that must be available everywhereDynamic content needing low-latency in a few specific regions

6. CloudFront — ALB hoặc EC2 làm Origin

Cách 1 — Using VPC Origins:

  • Cho phép phân phối nội dung từ ứng dụng host trong VPC private subnet (không cần expose ra Internet)
  • Đưa traffic tới: Application Load Balancer, Network Load Balancer, hoặc EC2 Instance — đều ở chế độ private

Cách 2 — Using Public Network:

  • Edge Location gọi tới origin qua địa chỉ IP public
  • Security Group của ALB (public) phải cho phép IP public của các Edge Location (danh sách IP: d7uri8nf7uskq.cloudfront.net/tools/list-cloudfront-ips)
  • Security Group của EC2 instance (có thể private) chỉ cần cho phép traffic từ Security Group của ALB

⚠️ VPC Origins là cách khuyến nghị hơn vì không cần expose origin ra Internet — an toàn hơn nhiều so với dùng Public Network.

Option 1 — Using VPC Origins:

  • Allows you to deliver content from applications hosted in your VPC private subnets (no need to expose them on the Internet)
  • Delivers traffic to: Application Load Balancer, Network Load Balancer, or EC2 Instances — all private

Option 2 — Using Public Network:

  • The Edge Location reaches the origin over its public IP
  • The public ALB's Security Group must allow the public IPs of the Edge Locations (IP list: d7uri8nf7uskq.cloudfront.net/tools/list-cloudfront-ips)
  • The EC2 instance's Security Group (which can be private) only needs to allow traffic from the ALB's Security Group

⚠️ VPC Origins is the recommended approach since it doesn't require exposing the origin to the Internet — much safer than the Public Network approach.

7. CloudFront — Geo Restriction

  • Có thể giới hạn ai truy cập được distribution:
    • Allowlist: chỉ cho phép user truy cập nội dung nếu họ ở trong danh sách quốc gia được duyệt
    • Blocklist: chặn user truy cập nếu họ ở trong danh sách quốc gia bị cấm
  • "Quốc gia" được xác định bằng Geo-IP database của bên thứ ba
  • Use case: kiểm soát truy cập nội dung theo luật bản quyền (Copyright Laws)
  • You can restrict who can access your distribution:
    • Allowlist: allow users to access your content only if they're in one of the approved countries
    • Blocklist: prevent users from accessing your content if they're in one of the banned countries
  • The "country" is determined using a 3rd party Geo-IP database
  • Use case: Copyright Laws to control access to content

8. CloudFront — Cache Invalidations

S3 Bucket(origin)CloudFrontInvalidate:/index.html, /images/*update filesEdge Location AEdge Location Binvalidate
  • Khi bạn update backend origin, CloudFront không hề hay biếtchỉ lấy nội dung mới sau khi TTL hết hạn
  • Có thể buộc refresh cache (toàn bộ hoặc một phần), bỏ qua TTL, bằng cách thực hiện CloudFront Invalidation
  • Có thể invalidate toàn bộ file (*) hoặc một path cụ thể (/images/*)
  • When you update the back-end origin, CloudFront doesn't know about it and will only get the refreshed content after the TTL has expired
  • You can force an entire or partial cache refresh (bypassing the TTL) by performing a CloudFront Invalidation
  • You can invalidate all files (*) or a specific path (/images/*)

9. Bài toán: Người dùng toàn cầu & Độ trễ (Global Users & Latency)

  • Bạn đã deploy một ứng dụng và có user trên toàn cầu muốn truy cập trực tiếp
  • Traffic đi qua Internet công cộng, có thể cộng dồn nhiều latency vì đi qua nhiều hop
  • Ta muốn đi càng nhanh càng tốt qua mạng nội bộ của AWS để giảm thiểu latency
  • You have deployed an application and have global users who want to access it directly
  • They go over the public Internet, which can add a lot of latency due to many hops
  • We wish to go as fast as possible through AWS's network to minimize latency

10. Unicast IP vs. Anycast IP

  • Unicast IP: một server giữ một địa chỉ IP — mỗi server có IP riêng biệt
  • Anycast IP: tất cả server cùng giữ chung một địa chỉ IP, và client sẽ được định tuyến tới server gần nhất
  • Unicast IP: one server holds one IP address — each server has its own distinct IP
  • Anycast IP: all servers hold the same IP address, and the client is routed to the nearest one

11. AWS Global Accelerator — Tổng quan (Overview)

AmericaEuropeAustraliaIndiaEdge Location2 Anycast IPsPrivate AWS networkPublic ALB
  • Tận dụng mạng nội bộ của AWS để định tuyến tới ứng dụng của bạn
  • Tạo ra 2 Anycast IP cho ứng dụng
  • Anycast IP gửi traffic thẳng tới Edge Location gần nhất
  • Edge Location sau đó chuyển traffic tới ứng dụng của bạn (ở region gần nhất)
  • Leverages the AWS internal network to route to your application
  • 2 Anycast IPs are created for your application
  • The Anycast IPs send traffic directly to Edge Locations
  • The Edge Locations then send the traffic to your application

12. AWS Global Accelerator — Đặc điểm (Features)

  • Hoạt động với Elastic IP, EC2 instance, ALB, NLB — cả public lẫn private
  • Hiệu năng ổn định (Consistent Performance):
    • Định tuyến thông minh tới nơi có latency thấp nhất, failover vùng nhanh
    • Không gặp vấn đề với client cache (vì IP không hề thay đổi)
    • Đi qua mạng nội bộ AWS
  • Health Checks:
    • Global Accelerator tự kiểm tra health ứng dụng của bạn
    • Giúp ứng dụng hoạt động toàn cầu (failover dưới 1 phút khi phát hiện unhealthy)
    • Rất tốt cho disaster recovery (nhờ health check)
  • Bảo mật (Security):
    • Chỉ cần whitelist 2 IP bên ngoài (2 Anycast IP)
    • Bảo vệ DDoS nhờ AWS Shield
  • Works with Elastic IP, EC2 instances, ALB, NLB — both public or private
  • Consistent Performance:
    • Intelligent routing to the lowest latency, fast regional failover
    • No issue with client cache (because the IP doesn't change)
    • Uses the internal AWS network
  • Health Checks:
    • Global Accelerator performs a health check of your applications
    • Helps make your application global (failover less than 1 minute for unhealthy)
    • Great for disaster recovery (thanks to the health checks)
  • Security:
    • Only 2 external IPs need to be whitelisted
    • DDoS protection thanks to AWS Shield

13. AWS Global Accelerator vs. CloudFront

  • Cả hai đều dùng mạng global và edge location của AWS
  • Cả hai đều tích hợp với AWS Shield để chống DDoS

CloudFront:

  • Tăng hiệu năng cho nội dung có thể cache (ảnh, video…)
  • Cũng hỗ trợ nội dung động (API acceleration, dynamic site delivery)
  • Nội dung được phục vụ ngay tại edge

Global Accelerator:

  • Tăng hiệu năng cho nhiều loại ứng dụng đa dạng chạy trên TCP hoặc UDP
  • Proxy packet tại edge tới ứng dụng chạy ở một hoặc nhiều AWS Region
  • Rất phù hợp cho use case không phải HTTP: gaming (UDP), IoT (MQTT), Voice over IP
  • Phù hợp cho use case HTTP cần địa chỉ IP tĩnh (static IP)
  • Phù hợp cho use case HTTP cần failover vùng nhanh, xác định được (deterministic)
  • Both use the AWS global network and edge locations around the world
  • Both integrate with AWS Shield for DDoS protection

CloudFront:

  • Improves performance for cacheable content (images, videos…)
  • Also supports dynamic content (API acceleration, dynamic site delivery)
  • Content is served at the edge

Global Accelerator:

  • Improves performance for a wide range of applications over TCP or UDP
  • Proxies packets at the edge to applications running in one or more AWS Regions
  • Great fit for non-HTTP use cases: gaming (UDP), IoT (MQTT), Voice over IP
  • Good for HTTP use cases that require static IP addresses
  • Good for HTTP use cases that require deterministic, fast regional failover

Personal notes by thanhlt