iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To serve a custom-domain static website securely on AWS, keep the S3 bucket private, use its REST endpoint as a CloudFront origin, protect that origin with Origin Access Control (OAC), and attach an AWS Certificate Manager (ACM) certificate to CloudFront for HTTPS. Route the domain to the distribution with DNS. S3 website hosting alone does not provide HTTPS.
AWS also recommends considering Amplify Hosting for static content stored in S3. It can deploy the content to a CloudFront-powered CDN and provide a public HTTPS URL. The manual setup below is useful when your goal is to understand how S3, CloudFront, certificates, and DNS fit together.
Understand what each AWS service does
These services have separate jobs. A certificate does not make an S3 bucket private, DNS does not create HTTPS, and CloudFront does not automatically make a private origin accessible. The pieces work together as follows:
- Amazon S3 stores the site’s static files, such as HTML, CSS, JavaScript, and images.
- Amazon CloudFront serves those files to visitors and can cache them. It presents the HTTPS certificate to the browser.
- Origin Access Control (OAC) lets CloudFront make authorized requests to a private S3 REST origin.
- ACM supplies the certificate CloudFront uses for the viewer-facing hostname.
- DNS maps your custom hostname to the CloudFront distribution. In Route 53, an alias record can point to the distribution.
The request path is: a browser connects to your hostname over HTTPS; CloudFront presents the certificate and either returns a cached object or requests it from S3; OAC authorizes the origin request; and S3 returns the object without being publicly readable. If Route 53 hosts your DNS zone, an alias record can direct the hostname to CloudFront.
#1 Best Overall
Choose the right S3 origin
“Hosting a static website on S3” can refer to two different endpoint patterns. Choosing between them changes the security and behavior of the setup.
| Origin pattern | What it supports | Security and HTTPS implications |
|---|---|---|
| S3 website endpoint | S3 website features such as index and error documents. | The endpoint supports HTTP only and generally requires public access. It is not the right origin for a private OAC-protected bucket. |
| S3 REST endpoint | Direct access to objects in a bucket; use CloudFront settings to provide the site’s delivery behavior. | Works with OAC so the bucket can remain private. You do not need to enable S3 static website hosting for this configuration. |
For a private bucket behind CloudFront, use the REST endpoint and OAC. AWS recommends OAC; Origin Access Identity (OAI) is the older approach. Do not confuse the connection CloudFront makes to a visitor with the connection it makes to an origin: CloudFront can serve HTTPS to visitors while an S3 website endpoint remains HTTP-only. AWS guidance calls for the REST endpoint when using HTTPS to connect to S3. See AWS’s S3 website hosting guide and its CloudFront and S3 HTTPS guidance.
If you specifically need website-endpoint behavior, weigh that requirement against the public-access model. AWS’s S3 static website tutorial disables Block Public Access and grants public reads for its website endpoint example. AWS recommends keeping Block Public Access enabled where possible and using CloudFront OAC instead. Older tutorials that make a bucket public are not equivalent to a private S3 origin behind CloudFront.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsBuild the private S3 and CloudFront path
Start with the files for your site and an S3 bucket to store them. For the private-origin design, leave S3 Block Public Access enabled and configure CloudFront to use the bucket’s S3 REST endpoint—not its website endpoint—as the origin. The precise console labels can change, so follow AWS’s current setup guidance for your account and region.
Rank #3
- Upload the static files to S3. Include the page intended to load at the site root and any assets it references.
- Create or configure a CloudFront distribution with the S3 REST origin. Set the default root object to the site’s home page so requests to the distribution root can return it.
- Enable OAC for the origin. Configure CloudFront to use OAC, then authorize the distribution to read the bucket in the S3 bucket policy. Do not make the objects public to compensate for a missing or incorrect policy.
- Choose how the site handles paths and errors. A REST origin does not automatically provide every behavior of the S3 website endpoint. If your site depends on website-specific index, error, or routing behavior, decide how CloudFront should handle those requests rather than assuming the origin types are interchangeable.
For AWS’s distinction between website hosting and private CloudFront delivery, consult the S3 hosting guide and the website setup tutorial.
Use ACM for the CloudFront HTTPS certificate
ACM manages the certificate; CloudFront uses it to establish HTTPS with visitors. The certificate must cover the hostname visitors will use, and it must be validated before it can be used. Add the hostname to the CloudFront distribution and associate the certificate with the distribution. ACM, DNS validation, and DNS routing are distinct steps: validation proves control of the name for certificate issuance, while the later DNS record directs visitor traffic to CloudFront.
Rank #4
Use AWS’s current CloudFront HTTPS and alternate domain name instructions and ACM DNS validation guide for the current certificate-region and console requirements. Do not infer those requirements from an S3 website endpoint or from a sample architecture.
Free tools Windows power users keep installed
One-click scans. No signup required.
Point your custom domain to CloudFront
After the distribution is configured for the hostname and certificate, create the DNS record that directs the hostname to CloudFront. In Route 53, use an alias record for the CloudFront distribution. The DNS record does not itself enable HTTPS; visitors reach HTTPS because the request goes to CloudFront, which presents the certificate.
Best Value
A direct HTTPS route to an S3 website endpoint is not supported because the endpoint does not support SSL/TLS. AWS’s Route 53 guide for routing to CloudFront describes the alias approach and explains why HTTPS domain traffic should go through CloudFront.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Check the result before sharing the site
Use these checks to catch configuration gaps without treating a successful CloudFront response as proof that the S3 origin is private:
- Open the intended custom hostname with
https://and confirm that the expected page loads without a certificate warning. - Confirm the CloudFront distribution includes the hostname and the intended certificate.
- Check that the DNS record points to the CloudFront distribution, not directly to an S3 website endpoint.
- Verify that the S3 bucket’s public access is blocked and that CloudFront can retrieve objects through the OAC-authorized bucket policy.
- Check the root-page and error behavior you intend visitors to receive, especially if the site relies on website-endpoint features but uses a REST origin.
Consider whether the manual setup is right for your project
The manual route exposes how object storage, private origin access, content delivery, certificates, and DNS fit together. It also leaves you responsible for configuring those connections and choosing suitable path and error behavior. AWS’s managed alternative, Amplify Hosting, can deploy content stored in S3 to a CloudFront-powered CDN and provide a public HTTPS URL. The best fit depends on whether learning and controlling the individual services matters more than having AWS manage more of the hosting workflow; usage costs vary and should be checked against current AWS pricing for your setup.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchFor an illustrative architecture, AWS provides a CloudFront secure static site sample. Its use of OAI is legacy; use AWS’s current OAC guidance for a new private-origin configuration.
Clean up a learning deployment
AWS advises deleting resources created for its S3 website tutorial when you finish so charges do not continue. Review and remove the resources you created for your own exercise, including the S3 objects and bucket, CloudFront distribution, and DNS records where appropriate. Check current AWS pricing for the services and traffic pattern you plan to use; costs depend on the resources and usage, and no universal project total applies.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

