Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To serve a custom-domain static website securely on AWS, keep the S3 bucket private, use its REST endpoint as a CloudFront origin, protect that origin with Origin Access Control (OAC), and attach an AWS Certificate Manager (ACM) certificate to CloudFront for HTTPS. Route the domain to the distribution with DNS. S3 website hosting alone does not provide HTTPS.

AWS also recommends considering Amplify Hosting for static content stored in S3. It can deploy the content to a CloudFront-powered CDN and provide a public HTTPS URL. The manual setup below is useful when your goal is to understand how S3, CloudFront, certificates, and DNS fit together.

Understand what each AWS service does

These services have separate jobs. A certificate does not make an S3 bucket private, DNS does not create HTTPS, and CloudFront does not automatically make a private origin accessible. The pieces work together as follows:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Amazon S3 stores the site’s static files, such as HTML, CSS, JavaScript, and images.
  • Amazon CloudFront serves those files to visitors and can cache them. It presents the HTTPS certificate to the browser.
  • Origin Access Control (OAC) lets CloudFront make authorized requests to a private S3 REST origin.
  • ACM supplies the certificate CloudFront uses for the viewer-facing hostname.
  • DNS maps your custom hostname to the CloudFront distribution. In Route 53, an alias record can point to the distribution.

The request path is: a browser connects to your hostname over HTTPS; CloudFront presents the certificate and either returns a cached object or requests it from S3; OAC authorizes the origin request; and S3 returns the object without being publicly readable. If Route 53 hosts your DNS zone, an alias record can direct the hostname to CloudFront.

Choose the right S3 origin

“Hosting a static website on S3” can refer to two different endpoint patterns. Choosing between them changes the security and behavior of the setup.

Origin pattern What it supports Security and HTTPS implications
S3 website endpoint S3 website features such as index and error documents. The endpoint supports HTTP only and generally requires public access. It is not the right origin for a private OAC-protected bucket.
S3 REST endpoint Direct access to objects in a bucket; use CloudFront settings to provide the site’s delivery behavior. Works with OAC so the bucket can remain private. You do not need to enable S3 static website hosting for this configuration.

For a private bucket behind CloudFront, use the REST endpoint and OAC. AWS recommends OAC; Origin Access Identity (OAI) is the older approach. Do not confuse the connection CloudFront makes to a visitor with the connection it makes to an origin: CloudFront can serve HTTPS to visitors while an S3 website endpoint remains HTTP-only. AWS guidance calls for the REST endpoint when using HTTPS to connect to S3. See AWS’s S3 website hosting guide and its CloudFront and S3 HTTPS guidance.

If you specifically need website-endpoint behavior, weigh that requirement against the public-access model. AWS’s S3 static website tutorial disables Block Public Access and grants public reads for its website endpoint example. AWS recommends keeping Block Public Access enabled where possible and using CloudFront OAC instead. Older tutorials that make a bucket public are not equivalent to a private S3 origin behind CloudFront.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build the private S3 and CloudFront path

Start with the files for your site and an S3 bucket to store them. For the private-origin design, leave S3 Block Public Access enabled and configure CloudFront to use the bucket’s S3 REST endpoint—not its website endpoint—as the origin. The precise console labels can change, so follow AWS’s current setup guidance for your account and region.

  1. Upload the static files to S3. Include the page intended to load at the site root and any assets it references.
  2. Create or configure a CloudFront distribution with the S3 REST origin. Set the default root object to the site’s home page so requests to the distribution root can return it.
  3. Enable OAC for the origin. Configure CloudFront to use OAC, then authorize the distribution to read the bucket in the S3 bucket policy. Do not make the objects public to compensate for a missing or incorrect policy.
  4. Choose how the site handles paths and errors. A REST origin does not automatically provide every behavior of the S3 website endpoint. If your site depends on website-specific index, error, or routing behavior, decide how CloudFront should handle those requests rather than assuming the origin types are interchangeable.

For AWS’s distinction between website hosting and private CloudFront delivery, consult the S3 hosting guide and the website setup tutorial.

Use ACM for the CloudFront HTTPS certificate

ACM manages the certificate; CloudFront uses it to establish HTTPS with visitors. The certificate must cover the hostname visitors will use, and it must be validated before it can be used. Add the hostname to the CloudFront distribution and associate the certificate with the distribution. ACM, DNS validation, and DNS routing are distinct steps: validation proves control of the name for certificate issuance, while the later DNS record directs visitor traffic to CloudFront.

Use AWS’s current CloudFront HTTPS and alternate domain name instructions and ACM DNS validation guide for the current certificate-region and console requirements. Do not infer those requirements from an S3 website endpoint or from a sample architecture.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Point your custom domain to CloudFront

After the distribution is configured for the hostname and certificate, create the DNS record that directs the hostname to CloudFront. In Route 53, use an alias record for the CloudFront distribution. The DNS record does not itself enable HTTPS; visitors reach HTTPS because the request goes to CloudFront, which presents the certificate.

A direct HTTPS route to an S3 website endpoint is not supported because the endpoint does not support SSL/TLS. AWS’s Route 53 guide for routing to CloudFront describes the alias approach and explains why HTTPS domain traffic should go through CloudFront.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check the result before sharing the site

Use these checks to catch configuration gaps without treating a successful CloudFront response as proof that the S3 origin is private:

  • Open the intended custom hostname with https:// and confirm that the expected page loads without a certificate warning.
  • Confirm the CloudFront distribution includes the hostname and the intended certificate.
  • Check that the DNS record points to the CloudFront distribution, not directly to an S3 website endpoint.
  • Verify that the S3 bucket’s public access is blocked and that CloudFront can retrieve objects through the OAC-authorized bucket policy.
  • Check the root-page and error behavior you intend visitors to receive, especially if the site relies on website-endpoint features but uses a REST origin.

Consider whether the manual setup is right for your project

The manual route exposes how object storage, private origin access, content delivery, certificates, and DNS fit together. It also leaves you responsible for configuring those connections and choosing suitable path and error behavior. AWS’s managed alternative, Amplify Hosting, can deploy content stored in S3 to a CloudFront-powered CDN and provide a public HTTPS URL. The best fit depends on whether learning and controlling the individual services matters more than having AWS manage more of the hosting workflow; usage costs vary and should be checked against current AWS pricing for your setup.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For an illustrative architecture, AWS provides a CloudFront secure static site sample. Its use of OAI is legacy; use AWS’s current OAC guidance for a new private-origin configuration.

Clean up a learning deployment

AWS advises deleting resources created for its S3 website tutorial when you finish so charges do not continue. Review and remove the resources you created for your own exercise, including the S3 objects and bucket, CloudFront distribution, and DNS records where appropriate. Check current AWS pricing for the services and traffic pattern you plan to use; costs depend on the resources and usage, and no universal project total applies.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.