Skip to main content

Route 53 and CloudFront for Cloud Engineers

Learn Route 53 DNS routing policies, CloudFront CDN, ACM certificates, and WAF - and how to design fast, resilient, global-facing traffic paths.

~3 hours
10 Topics
Hands-on Scenarios

What You'll Learn

Understanding How DNS and CDN Fit Into Your Architecture

Route 53 and CloudFront solve two different problems, and most confusion about this stack comes from treating them as one thing.

Understanding DNS and How Route 53 Resolves Names

This topic covers what is specific to Route 53: what it is, and how its hosted zones work.

Configuring DNS Records - A, CNAME, and Alias

Record types and the CNAME rule are covered in Networking Fundamentals. This topic keeps only what is specific to Route 53.

Designing Route 53 Health Checks

Failover and some other routing policies depend on health checks. A wrong health check sends users to broken servers or takes down healthy ones.

Choosing the Right Route 53 Routing Policy

Route 53 offers eight routing policies, and you choose one per record set, not one for the whole domain.

Delivering Content Globally with CloudFront

CloudFront is where most of the real performance and traffic savings happen. It also has the most settings that can silently make caching useless.

Skills You'll Master

ROUTE-53CLOUDFRONTDNSCDNACM

Curriculum Index10 topics

Career Impact

Roles that use the skills in this module.

  • Cloud Engineer

  • DevOps Engineer

  • Solutions Architect

See how this is asked in interviews

Practice on the Coding Sheet

Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.

Open the Coding Sheet

Frequently Asked Questions

Route 53 is a DNS service that answers which IP address a name points to. It never touches your application traffic. CloudFront is a CDN that receives the actual requests and serves cached or forwarded responses from edge locations.

CloudFront is a global service and reads its certificates from the US East (N. Virginia) Region only. A certificate requested in any other region will not appear when you attach it to a distribution.

No. Every distribution gets a domain ending in cloudfront.net that works over HTTPS. A custom domain, a Route 53 alias record, and an ACM certificate are only needed when you want your own name in the address bar.

Queries to alias records that point at supported AWS resources, such as CloudFront distributions and load balancers, are not charged. Standard records are billed per query, so check the Route 53 pricing page for current rates.