To host a static portfolio on AWS with HTTPS and a custom domain, store the built site files in a private Amazon S3 bucket, serve them through an Amazon CloudFront distribution that reads the bucket with origin access control (OAC), attach an AWS Certificate Manager (ACM) certificate, and point your domain at CloudFront with Amazon Route 53. Docker is not part of that delivery path. It is useful for previewing or building the site, and it becomes necessary only if the site needs a server-side runtime.
What each service does in this setup
Most confusion about this stack comes from treating every service as a hosting option. Each one has a separate job, and a plain portfolio needs only some of them.
| Service | Role in a static portfolio | Needed for a plain static portfolio? |
|---|---|---|
| Amazon S3 | Stores HTML, CSS, JavaScript, and image files. Serves static files and client-side scripts only; it does not run server-side code. | Yes |
| Amazon CloudFront | Delivers the site over HTTPS, caches objects at edge locations, and reads the private bucket through OAC. | Yes, for HTTPS and a custom domain |
| AWS Certificate Manager | Issues the TLS certificate for your domain. CloudFront requires certificates to be requested in US East (N. Virginia). | Yes, with a custom domain |
| Amazon Route 53 | Hosts DNS records that send your domain to the CloudFront distribution. You can also keep DNS with another provider. | Optional if you manage DNS elsewhere |
| Docker | Packages and runs an application environment as a container image. Useful for local preview or a build pipeline. | No |
| AWS Amplify Hosting | A managed static-site hosting workflow that replaces the manual S3, CloudFront, and certificate setup. | No, it is an alternative path |
Before you start
- An AWS account with permission to create S3 buckets, CloudFront distributions, ACM certificates, and Route 53 records.
- A folder of built static files with an
index.htmlat its root. A portfolio built with a static site generator usually produces this in abuildordistfolder. - A domain name. You can register it through Route 53 or another registrar. Registration fees are covered in the cost section below.
- The AWS region you use for the bucket can be any region. The certificate must be in US East (N. Virginia) regardless of where the bucket is.
Build the secure S3 and CloudFront setup
Follow these steps in order. Console labels change over time, so match the wording to what you see and treat the labels below as a guide to the purpose of each screen.
- Create a private bucket. Open the S3 console and choose Create bucket. Pick a globally unique name and a region. Leave Block Public Access turned on. Do not add a public bucket policy.
- Upload the build output. Open the bucket, choose Upload, and add the contents of your build folder. Upload the files themselves, not the parent folder, so that
index.htmlsits at the bucket root. - Create the CloudFront distribution. Open the CloudFront console and choose Create distribution. For the origin, select your bucket from the browser and use the bucket’s REST endpoint rather than the static website endpoint. OAC is not used with the website endpoint.
- Attach origin access control. In the origin settings, create a new OAC with the default signing options and attach it to the origin.
- Set viewer and root options. Set the viewer protocol policy to redirect HTTP to HTTPS. Set the default root object to
index.html. - Apply the bucket policy CloudFront provides. After the distribution is created, CloudFront shows the bucket policy that grants it read access. Copy it, then open the bucket’s Permissions tab and paste it into the bucket policy. Confirm the bucket still has Block Public Access enabled.
- Request the certificate. Switch the ACM console to US East (N. Virginia) and request a public certificate for your domain, plus
wwwif you use it. Validate it with DNS records. Wait until the status shows Issued. - Attach the domain and certificate. In the distribution settings, add your domain as an alternate domain name and select the issued certificate as the custom SSL certificate.
- Point DNS at CloudFront. In your Route 53 hosted zone, create an A record with alias enabled and select the CloudFront distribution as the target. Add an AAAA record if you want IPv6 access.
- Test. Open
https://yourdomainand confirm the portfolio loads over HTTPS. Then open the bucket’s object URL directly. An AccessDenied response there is the expected result, because the bucket accepts requests only from CloudFront.
How caching affects updates
CloudFront serves cached copies of your files and fetches from S3 when it needs a fresh object. This speeds up delivery for many visitors, but it does not guarantee a particular speed for every visitor or configuration. After you upload a new version, visitors may still see old files until the cache expires. To force an update, open the distribution, choose Invalidations, and create an invalidation for the path /*.
Recommended Free Tools
#1 Best Overall
- MADE FOR THE MAKERS: Create; Explore; Store; The T7 Portable SSD delivers fast speeds and durable features to back up any endeavor; Build your video editing empire, file your photographs or back up your blogs all in an instant
- SHARE IDEAS IN A FLASH: Don’t waste a second waiting and spend more time doing; The T7 is embedded with PCIe NVMe technology that brings fast read and write speeds up to 1,050/1,000 MB/s¹, making it almost twice as fast as the T5
- ALWAYS MAKE THE SAVE: Compact design with massive capacity; With capacities up to 4TB, save exactly what you need to your drive – from large working files to game data and everything in between
- ADAPTS TO EVERY NEED: Whether using a PC or mobile phone, count on the T7 for extensive compatibility²; It’s a true team player when it comes to heavy-duty application usage or file-saving
- HI RESOLUTION VIDEO RECORDING: Record Ultra High Resolution (4K 60fs) videos directly onto the T7 Portable SSD with your favorite camera or mobile devices; Supports iPhone 15 Pro Res 4K at 60fps video and more³
Why not use the S3 website endpoint?
S3 static website hosting is the path shown in AWS’s introductory tutorial. It creates a website endpoint, lets you set index and error documents, and is useful for learning. The tutorial’s public endpoint procedure relies on turning off Block Public Access and adding a public bucket policy. AWS documentation recommends keeping Block Public Access enabled and using CloudFront with origin access control for a secure static site.
The website endpoint also serves only HTTP. For a portfolio on a custom domain, you need CloudFront in front of the bucket to provide HTTPS. Use the tutorial to learn how S3 website settings work, then switch to the CloudFront setup above for a live site.
Where Docker fits
Docker builds container images from Dockerfiles and runs them as isolated environments. Its quickstart uses an Nginx container to serve a simple static website, which shows that containers can serve static files. That does not mean a container is needed when the production architecture is S3 plus CloudFront.
Rank #2
- Get NVMe solid state performance with up to 1050MB/s read and 1000MB/s write speeds in a portable, high-capacity drive(1) (Based on internal testing; performance may be lower depending on host device & other factors. 1MB=1,000,000 bytes.)
- Up to 3-meter drop protection and IP65 water and dust resistance mean this tough drive can take a beating(3) (Previously rated for 2-meter drop protection and IP55 rating. Now qualified for the higher, stated specs.)
- Use the handy carabiner loop to secure it to your belt loop or backpack for extra peace of mind.
- Help keep private content private with the included password protection featuring 256‐bit AES hardware encryption.(3)
- Easily manage files and automatically free up space with the SanDisk Memory Zone app.(5). Non-Operating Temperature -20°C to 85°C
Preview the site locally in a container
If you want your local environment to match a web server, create a Dockerfile next to your build folder:
FROM nginx:alpine
COPY build/ /usr/share/nginx/html/
Then build and run it:
docker build -t portfolio-preview .
docker run --rm -p 8080:80 portfolio-preview
Open http://localhost:8080 to check the site. This runs only on your machine and is not the production host.
Use Docker in a build pipeline
Docker can also run your static site generator in a consistent environment, so builds produce the same output on your laptop and in a CI job. Upload the resulting files to S3 with the steps above. The container is a build tool here, not the server.
Rank #3
- Capacity Display Variance: 250GB external ssd often appears as around 232GB on Windows. MacOS can show full 250 GB capacity. This is binary calculation difference and doesn’t affect SSD hard drive actual physical storage
- 1050 MB/s Speed: Instantly access to your files with blazing-fast 10Gbps external SSD read up to 1050MB/s and write up to 1000MB/s. LED Light indicates USB SSD instant activity
- Data Security: Solid state drives S.M.A.R.T. health diagnostics and adaptive TRIM optimizing data block management ensures consistent write speeds and extends the longevity of the portable SSD
- USB-C & USB-A Cable: Both cables featuring rapid USB 3.2 Gen2, this USB SSD effortlessly bridges devices, enabling seamless cross-platform file transfers and backup between computers, smartphones, tablets and iPhone
- Always Fast: No slowdowns for large file transfers. With SLC caching (25% of current available capacity allocated as high-speed cache), this external SSD delivers steady 10Gbps for transfers within the cache capacity
When a container becomes the hosting target
A container is the right deployment unit when the site needs server-side code, such as a backend that renders pages, handles form submissions, or talks to a database. In that case, S3 and CloudFront alone cannot run the application, and you need a service that runs containers. This guide does not cover that architecture.
Managed alternative: Amplify Hosting
AWS presents Amplify Hosting as a managed way to host static sites. It is a different trade-off from the manual setup, so compare the two on the factors that matter for your portfolio.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute| Factor | S3 plus CloudFront (manual) | Amplify Hosting (managed) |
|---|---|---|
| Setup effort | Several consoles: S3, CloudFront, ACM, and Route 53, with the steps above | Managed workflow positioned by AWS as the simpler static-site option |
| Control | Direct control over origins, caching, bucket policies, and certificates | Less hands-on control. This guide does not compare individual Amplify options. |
| Security configuration | You set OAC, the bucket policy, Block Public Access, and HTTPS redirects yourself | Handled by the managed service. Check the settings in your account. |
| Pricing model | Usage-based S3 storage, requests, and transfer, plus CloudFront requests, edge locations, and transfer | Usage-based. Current rates are not compared in this guide. Check Amplify pricing before deciding. |
Choose the manual S3 and CloudFront path if you want to learn the components or need fine-grained control. Choose Amplify Hosting if you want the fastest route to a live static site and do not need to tune delivery yourself.
Rank #4
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
What the hosting costs
AWS does not publish a single fixed monthly cost for a portfolio, because charges depend on storage size, traffic, region, and configuration. Check current pricing with the AWS Pricing Calculator before you commit. The main cost drivers are:
- Domain registration: an annual fee that varies by top-level domain. AWS’s Route 53 onboarding documentation gives example ranges, but that page is undated. Check current Route 53 domain pricing for your TLD.
- S3: charges for stored data, requests, and data transfer.
- CloudFront: charges for requests, edge locations, and data transfer.
- Route 53 DNS: charges for hosted zones and DNS queries, if you use Route 53 for DNS.
A small portfolio with low traffic generally sees usage charges that are small relative to the domain fee, but the exact amount depends on your own usage and current rates.
Troubleshooting
CloudFront returns 403 AccessDenied
The most common cause is that the bucket policy from CloudFront was not saved, or Block Public Access and the origin configuration do not match the steps above. Confirm that the origin uses the REST endpoint with OAC attached, that the bucket policy is present, and that index.html is at the bucket root.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchBest Value
- NEARLY 2X FASTER THAN OUR PREVIOUS GENERATION(8) – move 1,000 high-res photos in under 60 seconds(6) with up to 2000MB/s transfer speeds(2).
- IP65 RATING AND UP TO 3M DROP PROTECTION(3) – protects against spills and drops.
- POCKET-SIZED – fits easily in pockets and small bags.
- SPACE TO OWN YOUR AI CONTENT – speed and capacity to download your high-res clips and photo edits.
- 256-BIT AES ENCRYPTION(4) – helps keep private files secure with password protection.
The root URL shows an error or a blank page
Check that the default root object is set to index.html in the distribution settings.
Sub-page links fail on refresh
Multi-page sites with real files for each page work without changes. A single-page app that handles routes in JavaScript needs custom error responses in CloudFront that return index.html for missing paths.
The custom domain does not appear in the certificate list
The certificate must be issued in US East (N. Virginia). Check that its status is Issued and that the domain names on the certificate match the alternate domain names you added.
Visitors still see old content
Create a CloudFront invalidation for /* after uploading changes, as described in the caching section.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

