#AmazonCloudfront
🆕 AWS added four CloudFront features: smart cropping, automatic optimization, a transformation playground, and ECS/Lambda feature parity for better device-specific image delivery.

#AWS #AmazonCloudfront
Dynamic Image Transformation for Amazon CloudFront adds four new features
Today, AWS announced four new features for Dynamic Image Transformation for Amazon CloudFront (DIT). Customers can now use enhanced smart cropping with custom label detection and advanced composition controls that preserve products, text, logos, and custom objects within cropped images. In addition, customers benefit from enhanced automatic image optimization that delivers appropriately sized images across every browser and device type, from phones and tablets to smart TVs, using CloudFront's multi-tier device detection to maximize optimization reach regardless of how users access content. DIT also introduces an interactive image transformation playground for testing and validating transformations, and achieves full feature parity between it's ECS and Lambda architectures. DIT's expanded smart cropping enables customers to combine multiple detection methods including faces, labels, text, logos, and custom Amazon Rekognition models, in a single request with configurable aspect ratios, padding, and gravity constraints prioritized by business need. Enhanced automatic optimization now uses a tiered detection approach, layering CloudFront's device classification headers and configurable fallbacks behind Client Hints, to eliminate the browser-support gap that left ~30% of traffic previously served unoptimized and extend right-sized image delivery beyond browsers to all device types. The image transformation playground displays transformed images with extended metrics including original and output dimensions, format, file size, compression ratios, and processing time, enabling customers to validate the performance of their transformation policies.
aws.amazon.com
September 8, 2026 at 6:10 PM
Dynamic Image Transformation for Amazon CloudFront adds four new features

Today, AWS announced four new features for Dynamic Image Transformation for Amazon CloudFront (DIT). Customers can now use enhanced smart cropping with custom label detection and advanced compositio...

#AWS #AmazonCloudfront
Dynamic Image Transformation for Amazon CloudFront adds four new features
Today, AWS announced four new features for Dynamic Image Transformation for Amazon CloudFront (DIT). Customers can now use enhanced smart cropping with custom label detection and advanced composition controls that preserve products, text, logos, and custom objects within cropped images. In addition, customers benefit from enhanced automatic image optimization that delivers appropriately sized images across every browser and device type, from phones and tablets to smart TVs, using CloudFront's multi-tier device detection to maximize optimization reach regardless of how users access content. DIT also introduces an interactive image transformation playground for testing and validating transformations, and achieves full feature parity between it's ECS and Lambda architectures. DIT's expanded smart cropping enables customers to combine multiple detection methods including faces, labels, text, logos, and custom Amazon Rekognition models, in a single request with configurable aspect ratios, padding, and gravity constraints prioritized by business need. Enhanced automatic optimization now uses a tiered detection approach, layering CloudFront's device classification headers and configurable fallbacks behind Client Hints, to eliminate the browser-support gap that left ~30% of traffic previously served unoptimized and extend right-sized image delivery beyond browsers to all device types. The image transformation playground displays transformed images with extended metrics including original and output dimensions, format, file size, compression ratios, and processing time, enabling customers to validate the performance of their transformation policies.
aws.amazon.com
September 8, 2026 at 6:05 PM
🆕 Amazon CloudFront now offers flat-rate pricing via API, allowing programmatic subscription, upgrades, downgrades, and cancellations. This simplifies management, especially for automated workflows, with free plans activating instantly and paid plans needing two-phase activ…

#AWS #AmazonCloudfront
Amazon CloudFront announces API support for flat-rate pricing plans
Starting today, customers can subscribe and manage flat-rate pricing plans programmatically using the AWS CLI, AWS SDKs, CloudFormation, CDK, or the PricingPlanManager API. CloudFront flat-rate plans give you one monthly price covering global content delivery, WAF, DDoS, DNS, logging, and edge compute, with no usage-based overage charges regardless of traffic spikes or attacks. Previously, customers could only subscribe to flat-rate pricing plans using the console, which required manual steps when using the API or infrastructure as code (IaC) like CloudFormation to create and manage distributions. Now, customers can programmatically subscribe, upgrade, downgrade, and cancel flat-rate pricing plans using the API or IaC tools. Paid plans support an optional two-phase activation flow: you first create the plan, then approve it to begin billing. This prevents you from being committed to charges before you confirm, and makes the API well-suited for automated workflows and agents that provision infrastructure on your behalf. Free plans activate immediately and don’t require approval. To learn more, refer to the Getting started with the PricingPlanManager API. There are no additional fees for using the API to manage flat-rate pricing plans.
aws.amazon.com
September 3, 2026 at 7:10 PM
Amazon CloudFront announces API support for flat-rate pricing plans

Starting today, customers can subscribe and manage flat-rate pricing plans programmatically using the AWS CLI, AWS SDKs, CloudFormation, CDK, or the PricingPlanManager API.

CloudFront flat-rate plans ...

#AWS #AmazonCloudfront
Amazon CloudFront announces API support for flat-rate pricing plans
Starting today, customers can subscribe and manage flat-rate pricing plans programmatically using the AWS CLI, AWS SDKs, CloudFormation, CDK, or the PricingPlanManager API. CloudFront flat-rate plans give you one monthly price covering global content delivery, WAF, DDoS, DNS, logging, and edge compute, with no usage-based overage charges regardless of traffic spikes or attacks. Previously, customers could only subscribe to flat-rate pricing plans using the console, which required manual steps when using the API or infrastructure as code (IaC) like CloudFormation to create and manage distributions. Now, customers can programmatically subscribe, upgrade, downgrade, and cancel flat-rate pricing plans using the API or IaC tools. Paid plans support an optional two-phase activation flow: you first create the plan, then approve it to begin billing. This prevents you from being committed to charges before you confirm, and makes the API well-suited for automated workflows and agents that provision infrastructure on your behalf. Free plans activate immediately and don’t require approval. To learn more, refer to the https://docs.aws.amazon.com/PricingPlanManager/latest/UserGuide/getting-started-pricingplanmanager-api.html. There are no additional fees for using the API to manage flat-rate pricing plans.
aws.amazon.com
September 3, 2026 at 7:05 PM
August 24, 2026 at 3:52 AM
🆕 Amazon CloudFront adds Origin Access Control for S3 Multi-Region Access Points, enabling secure access from selected distributions, enhancing performance and resilience without needing SigV4a Authorization header. Available globally except CloudFront China; no extra fees.

#AWS #AmazonCloudfront
Amazon CloudFront now supports Origin Access Control (OAC) for Amazon S3 Multi-Region Access Points
Starting today, customers can protect their origins using Amazon S3 Multi-Region Access Points (MRAP) by using CloudFront Origin Access Control (OAC) to only allow access from designated CloudFront distributions. Customers use Amazon S3 MRAP with CloudFront to serve content from a single global endpoint that automatically routes to the closest available replicated bucket across regions during a cache miss, improving performance and resilience for globally distributed users. Previously, customers had to compute and forward their own Asymmetric Signature Version 4 (SigV4a) Authorization header using a custom Lambda@Edge Function. Now, CloudFront natively signs requests to S3 MRAP origins. Customers get faster cache-miss fills from the nearest region and restricted, OAC-secured MRAP access without  custom Authorization header computation. CloudFront OAC support for Amazon S3 MRAP origins is available worldwide, except in the CloudFront China region. To get started, use the CloudFront Console, SDK, CLI, or CloudFormation to enable OAC when configuring your Amazon S3 MRAP endpoint with CloudFront. For more information, refer to the CloudFront Developer Guide. There are no additional fees associated with this feature
aws.amazon.com
August 20, 2026 at 9:10 PM
Amazon CloudFront now supports Origin Access Control (OAC) for Amazon S3 Multi-Region Access Points

Starting today, customers can protect their origins using Amazon S3 Multi-Region Access Points (MRAP) by using CloudFront Origin Access Control (OAC) to only allow access f...

#AWS #AmazonCloudfront
Amazon CloudFront now supports Origin Access Control (OAC) for Amazon S3 Multi-Region Access Points
Starting today, customers can protect their origins using Amazon S3 Multi-Region Access Points (MRAP) by using CloudFront Origin Access Control (OAC) to only allow access from designated CloudFront distributions. Customers use Amazon S3 MRAP with CloudFront to serve content from a single global endpoint that automatically routes to the closest available replicated bucket across regions during a cache miss, improving performance and resilience for globally distributed users. Previously, customers had to compute and forward their own Asymmetric Signature Version 4 (SigV4a) Authorization header using a custom Lambda@Edge Function. Now, CloudFront natively signs requests to S3 MRAP origins. Customers get faster cache-miss fills from the nearest region and restricted, OAC-secured MRAP access without  custom Authorization header computation. CloudFront OAC support for Amazon S3 MRAP origins is available worldwide, except in the CloudFront China region. To get started, use the CloudFront Console, SDK, CLI, or CloudFormation to enable OAC when configuring your Amazon S3 MRAP endpoint with CloudFront. For more information, refer to the https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-restricting-access-to-s3-mrap.html. There are no additional fees associated with this feature
aws.amazon.com
August 20, 2026 at 9:05 PM
I was worried about the costs of hosting election visualizations on #AWS using #AmazonS3 and #AmazonCloudfront, but since I published my first visualizations on August 7, I have eaten literally pennies of incremental costs. Gofundme not forthcoming yet. 🤞
August 18, 2026 at 3:54 AM
🆕 Amazon CloudFront Functions now log custom data directly to CloudFront access logs via cf.logCustomData(), eliminating the need to correlate function decisions with separate CloudWatch Logs, available in all edge locations with no extra charge.

#AWS #AmazonCloudfront
Amazon CloudFront Functions now supports logging to CloudFront access logs
You can now write custom data directly into CloudFront access logs using a new helper method available from within CloudFront Functions. CloudFront Functions run lightweight JavaScript at the edge for tasks like URL rewrites, header manipulation, and request routing. Previously, you could only emit log data to Amazon CloudWatch Logs as a separate log file from your CloudFront access logs. With this launch, you no longer need to correlate function decisions with CloudFront access log data across separate logging systems. You can call cf.logCustomData() from viewer request or viewer response functions to log values such as A/B test variant assignments, authentication outcomes, or routing decisions directly into the CloudFront access log record for that request. This works with both CloudFront real time log configurations and standard logging (v2), so you can analyze function behavior and request outcomes in a single query. The existing console.log() functionality remains available and the two methods can be used together in the same function. Amazon CloudFront Functions custom log data is available today in all CloudFront edge locations. There is no additional charge for using cf.logCustomData(). Standard CloudFront Functions invocation pricing and access log delivery charges apply. To get started, visit CloudFront Functions helper methods.
aws.amazon.com
July 14, 2026 at 5:10 PM
Amazon CloudFront Functions now supports logging to CloudFront access logs

You can now write custom data directly into CloudFront access logs using a new helper method available from within CloudFront Functions. CloudFront Functions run lightweight JavaScript at the edge ...

#AWS #AmazonCloudfront
Amazon CloudFront Functions now supports logging to CloudFront access logs
You can now write custom data directly into CloudFront access logs using a new helper method available from within CloudFront Functions. CloudFront Functions run lightweight JavaScript at the edge for tasks like URL rewrites, header manipulation, and request routing. Previously, you could only emit log data to Amazon CloudWatch Logs as a separate log file from your CloudFront access logs. With this launch, you no longer need to correlate function decisions with CloudFront access log data across separate logging systems. You can call cf.logCustomData() from viewer request or viewer response functions to log values such as A/B test variant assignments, authentication outcomes, or routing decisions directly into the CloudFront access log record for that request. This works with both CloudFront real time log configurations and standard logging (v2), so you can analyze function behavior and request outcomes in a single query. The existing console.log() functionality remains available and the two methods can be used together in the same function. Amazon CloudFront Functions custom log data is available today in all CloudFront edge locations. There is no additional charge for using cf.logCustomData(). Standard CloudFront Functions invocation pricing and access log delivery charges apply. To get started, visit https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/general-helper-methods.html#log-custom-data-method.
aws.amazon.com
July 14, 2026 at 5:05 PM
🆕 AWS WAF now lets content owners price AI bot access, accept payments via third-party providers like Coinbase (soon Stripe), and issue tokens. Available everywhere, it's free with no extra charges; standard WAF fees apply.

#AWS #AmazonCloudfront #AwsWaf
AWS WAF announces AI traffic monetization
Today, AWS WAF announced AI traffic monetization, a new Bot Control capability that lets you price, meter, and collect payment from AI bots and agents accessing your content and APIs. As AI agents increasingly support autonomous payments for the content and APIs they consume, AWS WAF now lets content owners and publishers set a price for that access, accept payment through third-party providers, and grant scoped access directly at the edge. When an AI bot or agent requests a protected resource like an article, a data feed, or a licensed archive, AWS WAF returns a machine-readable HTTP 402 Payment Required response using the x402 open protocol for machine-to-machine payments. The response contains your prices to access the content, accepted payment methods, and license terms. The agent presents proof of payment, AWS WAF verifies it at the edge, issues a scoped access token, and serves the response within a single request cycle. With AWS WAF AI traffic monetization, you can configure pricing through the AWS WAF console, define AI bot or agent policies based on verification status (including Web Bot Auth signatures), and receive payouts in stablecoins to your preferred wallet. AWS WAF’s integration with payment settlement and verification flows are provided by Coinbase’s x402 Facilitator. Integration with Stripe for direct account payments and Machine Payments Protocol (MPP) support is coming soon. Publishers can apply differentiated pricing based on agent identity and intent, allow verified AI search crawlers at one price while charging a different price to unverified agents or training crawlers, and validate end-to-end configuration in test mode before going live. Revenue analytics are available directly in the AWS WAF console alongside the AI traffic analysis dashboard, giving publishers a unified view of agent traffic and the revenue it generates. Publishers receive payments directly from agents and manage disbursement through their chosen payment provider. AI traffic monetization is available to AWS WAF customers at no additional charge. Standard AWS WAF charges apply. Refer to AWS WAF pricing for details.  This capability is available in all edge locations where AWS WAF Web ACLs are associated with Amazon CloudFront distributions. To get started, visit the AWS WAF console or explore the AWS WAF Developer Guide.
aws.amazon.com
June 15, 2026 at 9:10 PM
AWS WAF announces AI traffic monetization

Today, AWS WAF announced AI traffic monetization, a new Bot Control capability that lets you price, meter, and collect payment from AI bots and agents accessing your content and APIs. As AI agents increasingly support auto...

#AWS #AmazonCloudfront #AwsWaf
AWS WAF announces AI traffic monetization
Today, AWS WAF announced AI traffic monetization, a new Bot Control capability that lets you price, meter, and collect payment from AI bots and agents accessing your content and APIs. As AI agents increasingly support autonomous payments for the content and APIs they consume, AWS WAF now lets content owners and publishers set a price for that access, accept payment through third-party providers, and grant scoped access directly at the edge. When an AI bot or agent requests a protected resource like an article, a data feed, or a licensed archive, AWS WAF returns a machine-readable HTTP 402 Payment Required response using the x402 open protocol for machine-to-machine payments. The response contains your prices to access the content, accepted payment methods, and license terms. The agent presents proof of payment, AWS WAF verifies it at the edge, issues a scoped access token, and serves the response within a single request cycle. With AWS WAF AI traffic monetization, you can configure pricing through the AWS WAF console, define AI bot or agent policies based on verification status (including Web Bot Auth signatures), and receive payouts in stablecoins to your preferred wallet. AWS WAF’s integration with payment settlement and verification flows are provided by Coinbase’s x402 Facilitator. Integration with Stripe for direct account payments and Machine Payments Protocol (MPP) support is coming soon. Publishers can apply differentiated pricing based on agent identity and intent, allow verified AI search crawlers at one price while charging a different price to unverified agents or training crawlers, and validate end-to-end configuration in test mode before going live. Revenue analytics are available directly in the AWS WAF console alongside the AI traffic analysis dashboard, giving publishers a unified view of agent traffic and the revenue it generates. Publishers receive payments directly from agents and manage disbursement through their chosen payment provider. AI traffic monetization is available to AWS WAF customers at no additional charge. Standard AWS WAF charges apply. Refer to https://aws.amazon.com/waf/pricing/ for details.  This capability is available in all edge locations where AWS WAF Web ACLs are associated with Amazon CloudFront distributions. To get started, visit the http://console.aws.amazon.com/wafv2-pro or explore the AWS WAF Developer Guide.
aws.amazon.com
June 15, 2026 at 9:05 PM
🆕 Amazon CloudFront now supports OCSP revocation for viewer mTLS, enabling real-time validation of client certificate status during connection, enhancing security for regulated industries and zero-trust architectures at no extra cost.

#AWS #AmazonCloudfront
Amazon CloudFront announces support for OCSP Revocation for Mutual TLS (Viewer)
Amazon CloudFront now supports Online Certificate Status Protocol (OCSP) revocation checking for viewer mTLS, enabling you to validate client certificate revocation status in real time during connection establishment. This enables customers using mutual TLS (mTLS) on CloudFront  to verify that client certificates haven't been revoked before accepting connections—a common requirement for regulated industries and zero-trust architectures. Previously, customers implemented certificate revocation using CloudFront Functions and KeyValueStore, maintaining static revocation lists that were only as current as the last manual update. With OCSP, CloudFront queries the responder URL embedded in the client certificate at connection time, validating revocation status directly with the issuing Certificate Authority. CloudFront caches OCSP responses for up to 30 minutes to minimize latency impact on subsequent connections. The OCSP result is exposed in the connection function, enabling customers to implement custom logic—such as grace periods for certificate rotation, IP-based exceptions, or combining OCSP with their own revocation lists. OCSP revocation checking for viewer mTLS is available at no additional cost. To learn more, visit CloudFront mutual TLS (viewer).
aws.amazon.com
May 14, 2026 at 10:11 PM
🆕 Amazon CloudFront introduces passthrough mode for viewer mutual TLS, forwarding client certs to origins for validation without CloudFront verification, maintaining existing mTLS setups at no extra cost.

#AWS #AmazonCloudfront
Amazon CloudFront announces Passthrough Mode for mutual TLS (Viewer)
Amazon CloudFront now supports passthrough mode for viewer mutual TLS (mTLS) authentication, enabling customers to forward client certificates to their origin for validation without requiring CloudFront to perform certificate verification. Passthrough mode allows customers with existing mTLS implementations at their origins to use CloudFront without requiring to implement their validation logic at the edge. CloudFront viewer mTLS already supports required mode and optional mode, which offload client certificate authentication to CloudFront using trust stores. Passthrough mode is designed for customers to maintain their existing mTLS validation infrastructure at their origin without requiring any trust store configuration on CloudFront. In passthrough mode, CloudFront forwards every request to the origin along with the client's full certificate chain. Caching is not performed, ensuring each request is authenticated end-to-end by your origin. Connection functions which allow you to inspect or transform connection-level data are still invoked, enabling you to process certificate data before it reaches the origin. CloudFront Mutual TLS (viewer) in passthrough mode is available at no additional cost. To learn more, visit CloudFront mutual TLS (viewer).
aws.amazon.com
May 14, 2026 at 10:10 PM
Amazon CloudFront announces support for OCSP Revocation for Mutual TLS (Viewer)

Amazon CloudFront now supports Online Certificate Status Protocol (OCSP) revocation checking for viewer mTLS, enabling you to validate client certificate revocation status in real time during ...

#AWS #AmazonCloudfront
Amazon CloudFront announces support for OCSP Revocation for Mutual TLS (Viewer)
Amazon CloudFront now supports Online Certificate Status Protocol (OCSP) revocation checking for viewer mTLS, enabling you to validate client certificate revocation status in real time during connection establishment. This enables customers using mutual TLS (mTLS) on CloudFront  to verify that client certificates haven't been revoked before accepting connections—a common requirement for regulated industries and zero-trust architectures. Previously, customers implemented certificate revocation using CloudFront Functions and KeyValueStore, maintaining static revocation lists that were only as current as the last manual update. With OCSP, CloudFront queries the responder URL embedded in the client certificate at connection time, validating revocation status directly with the issuing Certificate Authority. CloudFront caches OCSP responses for up to 30 minutes to minimize latency impact on subsequent connections. The OCSP result is exposed in the connection function, enabling customers to implement custom logic—such as grace periods for certificate rotation, IP-based exceptions, or combining OCSP with their own revocation lists. OCSP revocation checking for viewer mTLS is available at no additional cost. To learn more, visit https://us-east-1.quicksight.aws.amazon.com/sn/account/amazonbi/start/TK.
aws.amazon.com
May 14, 2026 at 10:05 PM
Amazon CloudFront announces Passthrough Mode for mutual TLS (Viewer)

Amazon CloudFront now supports passthrough mode for viewer mutual TLS (mTLS) authentication, enabling customers to forward client certificates to their origin for validation without requiring CloudFront ...

#AWS #AmazonCloudfront
Amazon CloudFront announces Passthrough Mode for mutual TLS (Viewer)
Amazon CloudFront now supports passthrough mode for viewer mutual TLS (mTLS) authentication, enabling customers to forward client certificates to their origin for validation without requiring CloudFront to perform certificate verification. Passthrough mode allows customers with existing mTLS implementations at their origins to use CloudFront without requiring to implement their validation logic at the edge. CloudFront viewer mTLS already supports required mode and optional mode, which offload client certificate authentication to CloudFront using trust stores. Passthrough mode is designed for customers to maintain their existing mTLS validation infrastructure at their origin without requiring any trust store configuration on CloudFront. In passthrough mode, CloudFront forwards every request to the origin along with the client's full certificate chain. Caching is not performed, ensuring each request is authenticated end-to-end by your origin. Connection functions which allow you to inspect or transform connection-level data are still invoked, enabling you to process certificate data before it reaches the origin. CloudFront Mutual TLS (viewer) in passthrough mode is available at no additional cost. To learn more, visit https://us-east-1.quicksight.aws.amazon.com/sn/account/amazonbi/start/TK.
aws.amazon.com
May 14, 2026 at 10:05 PM
🆕 Amazon CloudFront Premium now offers configurable flat-rate plans with self-service monthly usage levels from 500M to 6B requests, allowing enterprises to scale without overage charges, covering content delivery, DDoS protection, and more.

#AWS #AmazonCloudfront
Amazon CloudFront Premium flat-rate plan now supports configurable usage allowances
Previously, the Amazon CloudFront Premium flat-rate plan supported a single usage allowance, and customers who outgrew it needed to contact us to discuss custom pricing options. Now, the Premium plan offers a range of self-service monthly usage levels ranging from 500 million to 6 billion requests and 50 TB to 600 TB, so customers can scale within the plan as their applications grow. Enterprises and mid-sized businesses whose baseline traffic previously made them ineligible for flat-rate plans can now adopt the Premium plan at a usage level that fits their application. You select your Premium plan usage level in the CloudFront console, see your new monthly flat-rate price instantly, and can change your usage level at any time with no commitment required. All Premium plan features are included at every usage level. Flat-rate plans provide a single monthly price covering content delivery, AWS WAF and DDoS protection, bot management, Amazon Route 53 DNS, Amazon CloudWatch Logs ingestion, serverless edge compute, and Amazon S3 storage credits — with no overage charges. To get started, visit the CloudFront console. To learn more, refer to the Launch Blog or Amazon CloudFront Developer Guide.
aws.amazon.com
May 12, 2026 at 10:10 PM
Amazon CloudFront Premium flat-rate plan now supports configurable usage allowances

Previously, the Amazon CloudFront Premium flat-rate plan supported a single usage allowance, and customers who outgrew it needed to contact us to discuss custom pricing options. Now, the P...

#AWS #AmazonCloudfront
Amazon CloudFront Premium flat-rate plan now supports configurable usage allowances
Previously, the Amazon CloudFront Premium flat-rate plan supported a single usage allowance, and customers who outgrew it needed to contact us to discuss custom pricing options. Now, the Premium plan offers a range of self-service monthly usage levels ranging from 500 million to 6 billion requests and 50 TB to 600 TB, so customers can scale within the plan as their applications grow. Enterprises and mid-sized businesses whose baseline traffic previously made them ineligible for flat-rate plans can now adopt the Premium plan at a usage level that fits their application. You select your Premium plan usage level in the CloudFront console, see your new monthly flat-rate price instantly, and can change your usage level at any time with no commitment required. All Premium plan features are included at every usage level. Flat-rate plans provide a single monthly price covering content delivery, AWS WAF and DDoS protection, bot management, Amazon Route 53 DNS, Amazon CloudWatch Logs ingestion, serverless edge compute, and Amazon S3 storage credits — with no overage charges. To get started, visit the https://us-east-1.console.aws.amazon.com/cloudfront/v4/home. To learn more, refer to the https://aws.amazon.com/blogs/networking-and-content-delivery/cloudfront-premium-flat-rate-plan-supports-configurable-usage-allowances/ or https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/flat-rate-pricing-plan.html#usage-allowance.
aws.amazon.com
May 12, 2026 at 10:05 PM
Amazon CloudFront Announces WebSocket Support for VPC Origins

Amazon CloudFront now supports WebSockets traffic through Virtual Private Cloud (VPC) origins, enabling you to use CloudFront as the single entry point for real-time applications hosted entirely in private subn...

#AWS #AmazonCloudfront
Amazon CloudFront Announces WebSocket Support for VPC Origins
Amazon CloudFront now supports WebSockets traffic through Virtual Private Cloud (VPC) origins, enabling you to use CloudFront as the single entry point for real-time applications hosted entirely in private subnets. WebSockets support extends VPC origins to applications that require persistent, bidirectional connections between clients and servers, such as chat platforms, collaborative editing tools, live dashboards, and IoT device management systems. Previously, customers running real-time applications over WebSockets had to keep their origins in public subnets and use Access Control Lists and other mechanisms to restrict access to their WebSockets-enabled servers. Customers had to spend ongoing effort to implement and maintain these solutions. Now, customers can place their Application Load Balancers (ALB), Network Load Balancers (NLB), and EC2 instances serving WebSockets traffic in private subnets accessible only through their CloudFront distributions. CloudFront serves as the single front door for both traditional HTTP traffic and real-time WebSockets connections, reducing attack surface, simplifying security management, and providing built-in DDoS protection. WebSockets support for VPC origins is available in all AWS Commercial Regions where VPC origins is supported. There is no additional cost for WebSockets traffic through VPC origins. To learn more, visit https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-vpc-origins.html.
aws.amazon.com
May 6, 2026 at 9:18 PM