Skip to training content
CertGraph

Global static site with a private S3 origin

Easy
Secure Architectures
Architecture Lab · topology construction

Build controls
not started

Click or drag services, connect directional handles, then validate the design rules.

Challenge brief

Aster Labs publishes a static documentation and marketing site: HTML, CSS, JavaScript, and about 900 product screenshots, held in one S3 bucket in eu-west-1. Readers open it from three continents, and the two-person platform team wants every asset answered by a cache close to the reader rather than the single Region. A security review closed with one rule: viewers may reach the site only through the CDN, and no browser request may read an object from the bucket itself. Which architecture keeps the S3 origin private while serving the site from the edge?

Success criteria

  • 1.Add one CloudFront distribution to cache the site near each reader.
  • 2.Add origin access control (OAC) so only CloudFront can read the private S3 origin.
  • 3.Add the S3 bucket that holds the site objects as the private origin.
  • 4.Connect CloudFront through origin access control to the S3 origin.
  • 5.Do not place a publicly readable bucket in the path; the origin stays private.

Service palette

Origin access control (OAC): CloudFront's access-control configuration for a private S3 origin, not a separately deployed forwarding service. CloudFront signs its origin requests and the bucket policy grants read access only to that distribution, so viewers must go through CloudFront.

Prepared guidance · deterministic simulation

Local

Prewritten hints from this exercise's rules, not live AI.

Use typed validation whenever you want a deterministic check. Suggestions never change the graph without your action or confirmation.

0 services · 0 directed connections·5 design rules