4 ms·
This is super exciting. My only concern on cost relates not to CloudFront itself, but rather the burden of using your own SSL certificate, as mpetrov mentioned.
by pearkes 13y ago
This is super exciting. My only concern on cost relates not to CloudFront itself, but rather the burden of using your own SSL certificate, as mpetrov mentioned.
I wonder if this will be improved as well? I personally wouldn't want to accept user data without SSL.
> Pricing for Custom SSL Certificates is simple. We charge a fixed monthly fee of $600 for each custom SSL certificate you associate with your CloudFront distributions, pro-rated by the hour. For example, if you had your custom SSL certificate associated with at least one CloudFront distribution for just 24 hours (i.e. 1 day) in the month of June, your total charge for using the custom SSL certificate feature in June will be (1 day / 30 days) * $600 = $20. Detailed pricing information for the Custom SSL Certificate feature is available on the CloudFront Pricing Page.
http://aws.amazon.com/cloudfront/custom-ssl-domains/ http://aws.amazon.com/cloudfront/custom-ssl-domains/
- sehrope 13y agoWe use CloudFront (without SSL) for our public site (static on S3) and this definitely looks cool. Our app itself has SSL (via an ELB) but not our static WWW site. The only thing we have on there I'd consider sensitive is our PGP key for emailing us security issues and I have that also linked directly to the HTTPS S3 bucket. As there's no user input it didn't seem worth it to pay the $600/mo for CloudFront SSL. Was a no brainer to setup and honestly I never even think about it. We just update the S3 bucket for the site and CloudFront picks up the changes. Support for these new HTTP methods makes CloudFront a lot more interesting for a dynamic app. Regarding SSL, the $600 per month seems like a lot for SSL but I think (pure speculation) it's because of the individual IPs needed for each endpoint. SSL ports can't be shared with other hosts[1]. Since CloudFront has endpoints at multiple edge locations, they would need multiple IPs per SSL cert. Add CPU cost for SSL processing too and I guess that's where the $600 comes from. [1]: Well technically they can using SNI[2] but some older browsers don't support it (mainly IE on XP). [2]: http://en.m.wikipedia.org/wiki/Server_Name_Indication http://en.m.wikipedia.org/wiki/Server_Name_Indication
- thezilch 13y agoUntil we can forget about the following platforms not supporting SNI, http://en.wikipedia.org/wiki/Server_Name_Indication#No_support http://en.wikipedia.org/wiki/Server_Name_Indication#No_suppo..., CloudFront will have to consume and instrument IPs per edge per client. Maybe if they gave the option of dropping support for non-SNI and/or IPv6 finally took off...