Q: What happens internally when you hit a CloudFront URL, from DNS resolution to Edge cache and origin shield?
Complete architectural journey of an HTTP request hitting an Amazon CloudFront distribution: Anycast routing, Edge Point of Presence (PoP), cache key evaluation, Regional Edge Caches, Origin Shield, and TLS termination.
🛠️ Production Runbook & Step-by-Step Resolution
Anycast DNS & Nearest Edge PoP Selection
Client resolves the CloudFront distribution domain. Route 53 returns the IP address of the closest CloudFront Edge PoP based on BGP Anycast and internet latency measurements.
TLS Handshake & CloudFront Functions / Viewer Request
TLS handshake terminates directly at the Edge PoP, eliminating round-trip latency to the origin. CloudFront Functions execute sub-millisecond URL rewrites, redirects, or header manipulations.
Cache Evaluation: Edge PoP -> Regional Edge Cache (REC) -> Origin Shield
PoP evaluates Cache Key. On miss, it queries the Regional Edge Cache (REC). If REC misses and Origin Shield is enabled, requests collapse at the Origin Shield layer before a single consolidated request reaches the origin (S3/ALB).
- Anycast DNS routes client to the geographically closest CloudFront Edge PoP.
- TLS termination occurs at the edge, dramatically accelerating connection handshakes.
- Tiered cache architecture: Edge PoP checks Regional Edge Cache (REC) before touching origin.
- Origin Shield consolidates global cache misses into a single request to protect backend APIs.