4 ms·
We use CloudFront (without SSL) for our public site (static on S3) and this definitely looks cool. Our app itself has SSL (via an ELB) but not our static WWW si
by sehrope 13y ago
We use CloudFront (without SSL) for our public site (static on S3) and this definitely looks cool. Our app itself has SSL (via an ELB) but not our static WWW site. The only thing we have on there I'd consider sensitive is our PGP key for emailing us security issues and I have that also linked directly to the HTTPS S3 bucket. As there's no user input it didn't seem worth it to pay the $600/mo for CloudFront SSL.
Was a no brainer to setup and honestly I never even think about it. We just update the S3 bucket for the site and CloudFront picks up the changes. Support for these new HTTP methods makes CloudFront a lot more interesting for a dynamic app.
Regarding SSL, the $600 per month seems like a lot for SSL but I think (pure speculation) it's because of the individual IPs needed for each endpoint. SSL ports can't be shared with other hosts[1]. Since CloudFront has endpoints at multiple edge locations, they would need multiple IPs per SSL cert. Add CPU cost for SSL processing too and I guess that's where the $600 comes from.
[1]: Well technically they can using SNI[2] but some older browsers don't support it (mainly IE on XP).
[2]: http://en.m.wikipedia.org/wiki/Server_Name_Indication http://en.m.wikipedia.org/wiki/Server_Name_Indication