To stream video through Amazon CloudFront, store your video or packaged stream at an origin such as Amazon S3, create a CloudFront distribution for that origin, and play the CloudFront URL. For adaptive streaming, encode the video into a manifest and media segments first: CloudFront delivers the files but does not encode or package a source video. Amazon Web Services (AWS) states that an encoder must package video content before CloudFront can distribute it.
Choose the right CloudFront video workflow
Start by deciding whether viewers will choose an on-demand video or watch a live broadcast. The origin, encoding process, and playback URL depend on that choice.
| Use case | What happens before CloudFront | Typical origin |
|---|---|---|
| Video on demand (VOD) | Upload a source video. To support adaptive streaming, encode it into a manifest and media segments, optionally at multiple resolutions and bitrates. | Amazon S3 is AWS’s straightforward VOD example. |
| Live streaming | An encoder compresses and formats the live input; a packaging or origin service prepares outputs for delivery. | AWS describes MediaStore or MediaPackage as possible origins after encoding with MediaLive. |
AWS lists MPEG-DASH, HLS, Smooth Streaming, and CMAF as common streaming formats. Choose based on your target players, devices, and packaging workflow; the AWS materials cited here do not establish one format as best for every audience. AWS defines VOD as content stored on a server that viewers can watch at any time.
Set up VOD from S3 through CloudFront
1. Choose a format and prepare the video
For basic playback, the AWS S3 tutorial demonstrates delivering a video file through CloudFront. For adaptive bitrate playback, use an encoder such as AWS Elemental MediaConvert to create a manifest and referenced media segments. You can create multiple resolution-and-bitrate versions so a compatible player can adjust viewing quality to available bandwidth. Upload the resulting output files to S3 while preserving the paths the manifest references.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
A single MP4 served through CloudFront is a video file, not an adaptive bitrate package. If your intended player expects HLS or DASH, provide the corresponding manifest and segments and test the manifest URL in that player.
2. Create a bucket and upload your files
- In the Amazon S3 console, create a bucket in a Region that suits your expected users, cost considerations, and regulatory requirements.
- Upload either the video file for basic delivery or the complete packaged output, including manifests and segments, for adaptive streaming.
3. Create a CloudFront distribution with S3 as the origin
In the CloudFront console, create a distribution and select the S3 bucket as its origin. Follow AWS’s current S3-origin setup instructions and restrict direct access to the bucket so viewers retrieve objects through CloudFront. Use Origin Access Control (OAC) for an S3 origin encrypted with SSE-KMS: AWS notes that Origin Access Identity (OAI) does not support SSE-KMS. Do not treat OAI as the universal current choice.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
4. Set the delivery behavior and HTTPS
Configure a cache behavior whose path pattern matches your video files or packaged output, and use HTTPS for viewer delivery. Keep the object paths and behavior patterns aligned with the files your player requests. Some packaging workflows need distinct behaviors for manifests and segments; AWS’s MediaPackage-specific patterns are not a template for a simple S3 bucket unless your paths and requirements actually match.
5. Test playback using the CloudFront URL
After the distribution is available, test an object through a URL shaped like https://<distribution-domain>/<path-to-video>. For a packaged stream, give the player the manifest URL; the player should then request the referenced segments. Verify the response and playback with the actual player and client devices you intend to support.
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
6. Add a custom domain only if you need one
AWS’s tutorial describes using Route 53 for DNS and custom-domain setup. Domain registration, hosted zones, and DNS queries can incur fees. The total depends on your configuration and usage, so calculate it for your deployment rather than assuming a fixed setup cost.
Use a separate architecture for live streaming
CloudFront can deliver live video, but it does not turn a camera or live input into a stream by itself. AWS describes a workflow in which MediaLive encodes and formats the live output, then MediaStore serves as an origin or MediaPackage converts the output into delivery formats. Configure CloudFront to use the chosen origin.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
For MediaPackage endpoints, AWS provides format-specific cache behavior examples matching manifest and segment extensions. The examples redirect viewer HTTP requests to HTTPS and forward only query strings needed by endpoint features. For Low-Latency HLS (LL-HLS), AWS names _HLS_msn and _HLS_part. AWS also recommends header-based CDN authorization between MediaPackage endpoints and CloudFront. These settings are specific to MediaPackage; confirm the requirements of your chosen origin and endpoint rather than applying them to every CloudFront setup.
Keep private video private
Restrict access to the origin
Origin protection prevents viewers from bypassing CloudFront to fetch objects directly from S3. Configure the applicable CloudFront origin access mechanism and bucket permissions. For SSE-KMS-encrypted S3 origins, use OAC rather than OAI.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
Authorize viewers separately
For private playback, configure signed URLs or signed cookies on the viewer-facing cache behavior. A trusted key group lets CloudFront verify signed URLs. Your application remains responsible for deciding whether someone is entitled to watch and issuing the signed URL or cookie.
A canned signed URL policy supports expiration. A custom policy can also specify a not-before time or an IP range. If a request uses query parameters, include them in the signature; AWS warns that otherwise the request can return HTTP 403. Be careful when enabling trusted signers on an existing behavior: viewers whose requests match that path must then use signed URLs. Enable that requirement only when your application is ready to issue them.
Troubleshoot common setup problems
- The source video plays, but there is no adaptive quality switching: A single file does not provide an adaptive bitrate package. Encode multiple renditions and create the appropriate manifest and segments, then test them with a compatible player.
- The manifest loads but playback fails: Check that every segment path referenced by the manifest exists in S3 and that the CloudFront behavior matches those object paths. Test through the intended player, not only by opening the manifest URL.
- CloudFront returns an access error for S3 content: Check the bucket policy and CloudFront origin access configuration. If the bucket uses SSE-KMS, confirm OAC is configured; OAI does not support that encryption case.
- Private playback returns HTTP 403: Confirm the viewer is authorized, the signed URL or cookie is valid for the behavior, and any query parameters are covered by the URL signature.
- Existing viewers lose access after enabling signed URLs: Trusted signers make signed URLs necessary for requests matching that behavior. Restore access by having the application issue valid signed URLs or by revisiting the behavior’s access configuration.
- A MediaPackage live stream does not behave as expected: Verify manifest and segment path patterns, the required endpoint query strings, HTTPS redirection, and the endpoint’s CDN authorization configuration. Do not assume MediaPackage-specific behavior settings apply to another origin.
Plan costs around your actual delivery
There is no defensible single CloudFront video-streaming total without assumptions about region, stored and transcoded volume, requests, and viewer data transfer. Include encoding and storage as well as delivery when estimating a VOD workflow. If you add a Route 53 domain, account separately for domain registration, hosted-zone, and DNS-query fees.
Or let it run in the cloud
CloudFront is a delivery component for a video architecture; StreamNeo is a separate option for keeping uploaded videos playing as a 24/7 YouTube live stream. Upload your recording or build a playlist, add your YouTube stream key, and go live. It runs from the cloud, so nothing has to stay on at home. The uploaded video streams as made, at any quality up to 4K 60fps for one flat price per slot; there are no quality tiers. StreamNeo can automatically recover if YouTube drops the stream. The first day is free with no card. Monthly billing is $9.99 per month. This is for uploaded video streamed to YouTube, not live camera input. Learn about StreamNeo or start the free first day.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

