DNS and CDN: Route 53 and CloudFront

Translate names to addresses with Route 53, and serve content from edge locations with CloudFront.

What is it?

DNS (Domain Name System) turns a name like www.example.com into an IP address. A resolver asks a chain of servers: the root, then the top-level domain (.com), then the domain's authoritative name server, and caches the answer for the record's TTL.

Amazon Route 53 is AWS's DNS service. It registers domains, hosts DNS zones, and checks the health of endpoints. Its routing policies decide which answer to return:

  • Simple: one answer.
  • Weighted: split traffic by percentage (canary releases).
  • Latency-based: send users to the Region with the lowest latency.
  • Failover: primary/secondary, switching on failed health checks.
  • Geolocation / Geoproximity: route by where the user or resource is.
  • Multivalue answer: return several healthy records.

Amazon CloudFront is a content delivery network (CDN). It caches copies of your content (static files, video, even API responses) in edge locations near users, fetching from your origin (S3, an ALB, any HTTP server) only on a cache miss. It also provides TLS termination, DDoS absorption, and integration with AWS WAF.

Explain like I'm 10

DNS is a phone book that you consult before every call. The CDN is a chain of local libraries that keep copies of popular books, so most readers borrow from the branch around the corner instead of ordering from the central archive across the world.

Examples

A weighted DNS record (canary)

{
  "Comment": "Send 10% to the new version",
  "Changes": [
    {
      "Action": "UPSERT",
      "ResourceRecordSet": {
        "Name": "api.example.com",
        "Type": "CNAME",
        "SetIdentifier": "new-version",
        "Weight": 10,
        "TTL": 60,
        "ResourceRecords": [{ "Value": "api-v2.example.com" }]
      }
    }
  ]
}

Apply with aws route53 change-resource-record-sets --hosted-zone-id Z123 --change-batch file://change.json. A second record with Weight 90 pairs with it.

Inspect what a CDN returned

curl -sI https://d111111abcdef8.cloudfront.net/logo.png | grep -iE "x-cache|age|cache-control|via"
# x-cache: Miss from cloudfront     <- first request fetched from the origin
# x-cache: Hit from cloudfront      <- later requests served from the edge

Paste the headers into the HTTP headers tool to learn what Cache-Control and Age mean.

How it works

A browser asks its resolver for the address of your name. Route 53, as the authoritative server, evaluates the routing policy and health checks and returns an answer, which the resolver caches until the TTL expires. The browser then connects to that address.

With CloudFront, the name resolves to a nearby edge location. If the edge has a fresh copy it responds immediately (a cache hit). Otherwise it fetches from the origin, stores the result according to cache headers and policies, and responds. You can invalidate cached objects when content changes.

  Browser -> Resolver -> Root -> .com TLD -> Route 53 (authoritative)
                                                |
                    answer: nearest edge IP <---+
  Browser -> Edge location --hit--> response
                   |
                  miss
                   v
               Origin (S3 / ALB)

Why does it exist?

People remember names, computers use numbers, and DNS bridges them. Distance adds latency, and the speed of light is not negotiable; copying content near users is the only way to make far-away users feel close.

When to use it

Use Route 53 for domains, failover, and traffic shifting. Use CloudFront for global static assets, media streaming, accelerating dynamic sites, and shielding origins from load.

When not to use it

A CDN adds little for audiences in one location that is already next to the origin, or for content that is unique per request and uncacheable. Very low TTLs everywhere increase DNS query cost and latency.

Common mistakes

  • Setting a long TTL, then needing to repoint quickly during an incident.

  • Caching personalised responses by accident.

  • Forgetting that DNS changes are not instant because of resolver caching.

  • Using a CNAME at the zone apex (use a Route 53 alias record).

  • Not setting cache headers, so CloudFront cannot cache effectively.

Practice exercises

  1. Easy:

    Describe each step of DNS resolution for shop.example.com starting from an empty cache.

  2. Medium:

    Pick a Route 53 routing policy for: (a) blue/green rollout, (b) users nearest their Region, (c) automatic standby site.

  3. Medium:

    Look at a real site's response headers in the HTTP headers tool and determine whether a CDN served it.

  4. Hard:

    Design caching rules for a site with static assets, a logged-in dashboard, and a public API. What do you cache, for how long, and how do you invalidate?

Interview questions

What is Route 53?

AWS's scalable DNS service, which also supports domain registration, health checks, and routing policies.

What is an edge location used for?

Caching and delivering content close to users, as CloudFront does.

What is TTL?

How long a DNS answer (or cached object) may be reused before being fetched again.

Exam-style: Which service reduces latency for global users by caching content at edge locations?

Amazon CloudFront.

Exam-style: Which Route 53 routing policy sends users to the lowest-latency Region?

Latency-based routing.