Route 53 and CloudFront for Cloud Engineers
Learn Route 53 DNS routing policies, CloudFront CDN, ACM certificates, and WAF - and how to design fast, resilient, global-facing traffic paths.
What You'll Learn
Understanding How DNS and CDN Fit Into Your Architecture
Route 53 and CloudFront solve two different problems, and most confusion about this stack comes from treating them as one thing.
Understanding DNS and How Route 53 Resolves Names
This topic covers what is specific to Route 53: what it is, and how its hosted zones work.
Configuring DNS Records - A, CNAME, and Alias
Record types and the CNAME rule are covered in Networking Fundamentals. This topic keeps only what is specific to Route 53.
Designing Route 53 Health Checks
Failover and some other routing policies depend on health checks. A wrong health check sends users to broken servers or takes down healthy ones.
Choosing the Right Route 53 Routing Policy
Route 53 offers eight routing policies, and you choose one per record set, not one for the whole domain.
Delivering Content Globally with CloudFront
CloudFront is where most of the real performance and traffic savings happen. It also has the most settings that can silently make caching useless.
Skills You'll Master
Curriculum Index10 topics
Understanding How DNS and CDN Fit Into Your Architecture
Route 53 and CloudFront solve two different problems, and most confusion about this stack comes from treating them as...
Understanding DNS and How Route 53 Resolves Names
This topic covers what is specific to Route 53: what it is, and how its hosted zones work.
Configuring DNS Records - A, CNAME, and Alias
Record types and the CNAME rule are covered in Networking Fundamentals.
Designing Route 53 Health Checks
Failover and some other routing policies depend on health checks.
Choosing the Right Route 53 Routing Policy
Route 53 offers eight routing policies, and you choose one per record set, not one for the whole domain.
Delivering Content Globally with CloudFront
CloudFront is where most of the real performance and traffic savings happen.
Securing CloudFront with ACM and WAF
HTTPS and request filtering at the edge protect your origin before bad traffic uses any of its compute.
Choosing Between CloudFront and Global Accelerator
Both services use the AWS edge network, but one caches and the other only routes.
Hands-on Lab - DNS, CDN, and Certificates End to End
You will put a private S3 bucket behind CloudFront, watch the cache work, hit and fix an Access Denied error, refresh...
Quick Reference and Common Mistakes
Quick reference Common mistakes Confusing what Route 53 does with what CloudFront does is the most common mix-up.
Career Impact
Roles that use the skills in this module.
Cloud Engineer
DevOps Engineer
Solutions Architect
Next Modules
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding SheetFrequently Asked Questions
Route 53 is a DNS service that answers which IP address a name points to. It never touches your application traffic. CloudFront is a CDN that receives the actual requests and serves cached or forwarded responses from edge locations.
CloudFront is a global service and reads its certificates from the US East (N. Virginia) Region only. A certificate requested in any other region will not appear when you attach it to a distribution.
No. Every distribution gets a domain ending in cloudfront.net that works over HTTPS. A custom domain, a Route 53 alias record, and an ACM certificate are only needed when you want your own name in the address bar.
Queries to alias records that point at supported AWS resources, such as CloudFront distributions and load balancers, are not charged. Standard records are billed per query, so check the Route 53 pricing page for current rates.