FSO Cloud Consulting
← Back to projects
CompletedCloud & CDN

Secure frontend delivery on AWS

A deployed React SPA architecture using a private S3 origin, CloudFront, ACM, Route 53, and OAC.

A real configuration validated on AWS

The facts below reflect the deployed environment and were checked using read-only AWS queries and post-deployment HTTP tests.

Application
residencia.fsocloudconsulting.com
Origin
Private S3 bucket in us-east-1
Delivery
Deployed and enabled CloudFront distribution
Origin access
OAC with SigV4 signing
Certificate
ACM-issued certificate in us-east-1
Caching
Managed-CachingOptimized

Request flow and security boundaries

Route 53 resolves the hostname but does not carry application traffic. The browser connects to CloudFront over HTTPS, and the CDN reads the private S3 origin through OAC only when the object is not already cached.

Route 53DNS resolution
CloudFrontEdge delivery and TLS
ACMCertificate in us-east-1
Private S3Static origin

Concepts demonstrated by the implementation

DNS does not proxy content

Route 53 resolves the hostname. The browser then establishes an HTTPS connection directly with the CloudFront network.

Edge is not a Region

An edge location terminates TLS and serves cached objects. The S3 origin remains a regional resource.

Hit versus miss

A cache hit avoids S3. A miss fetches the object from the origin and may store a copy at the edge.

One public entry point

Keeping S3 private prevents users from bypassing the distribution's TLS, cache, logging, and security controls.

Authenticated origin access

OAC signs requests with SigV4 while the bucket policy restricts GetObject to the authorized distribution.

Deployment includes cache

Uploading files is not enough: the correct index and assets must be delivered by the CDN.

Choices behind the architecture

Private origin

The S3 website endpoint was not used. CloudFront reaches the private bucket through OAC and a distribution-scoped bucket policy.

Custom DNS

A Route 53 Alias A record resolves residencia.fsocloudconsulting.com to the CloudFront distribution.

Managed TLS

ACM provides the certificate for the application hostname from us-east-1, as required by CloudFront.

Distributed cache

CachingOptimized reduces origin requests. index.html still requires invalidation or an explicit short-TTL strategy during releases.

SPA routing

Custom 403 and 404 responses return index.html with status 200 so the client-side router can handle direct navigation.

HTTPS only

Every HTTP request is redirected to HTTPS before content is delivered.

Observed post-deployment evidence

CheckObserved result
HTTP to HTTPS301 redirect to the HTTPS application URL
Main pageHTTPS 200 response
SPA fallbackAn unknown route returns index.html with status 200
Private originDirect S3 access returns 403 AccessDenied
Edge cacheX-Cache: Hit from cloudfront
S3 controlsBlock Public Access enabled, ACLs disabled, and a non-public bucket policy

Checks repeated on September 27, 2026. Internal AWS account identifiers are intentionally omitted from this public page.

Technical case study

A simple-to-operate architecture with a protected origin and global delivery.