origin cache refresh.md

Migrate CloudFront distribution: Origin cache refresh

Summary

Move CDN delivery from CloudFront distribution to Ample, one component at a time. Destination verified on Ample: a no-cache object overwritten in the published bucket and the CDN URL serving the new content on the next fetch (refresh=ok before=v1 after=v2), verified by the app fetching its own public URL. Source procedure: Record the distribution's origins, cache behaviors, TTLs and the object keys the app references. Not migrated automatically: CloudFront cache behaviors, Lambda@Edge and CloudFront Functions, signed URLs and custom TTLs are not migrated; Ample verifies delivery of published bucket objects only. Cutover: Redeploy the app with the new asset base URL, verify delivery from the CDN URL, keep the distribution until confirmed, then disable it. Rollback: keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.

Infrastructure requirements

Prerequisites

Exact tested configuration

Steps

  1. Inventory the source. List what CloudFront distribution provides beyond the component you are moving. Out of scope here: CloudFront cache behaviors, Lambda@Edge and CloudFront Functions, signed URLs and custom TTLs are not migrated; Ample verifies delivery of published bucket objects only.
  2. Source step 1. Record the distribution's origins, cache behaviors, TTLs and the object keys the app references.
  3. Source step 2. Copy the public assets into a published Ample bucket under versioned keys with immutable Cache-Control.
  4. Source step 3. Update the app to build asset URLs from the Ample public URL.
  5. Publish the destination bucket. Create and publish the asset bucket, upload versioned assets with immutable Cache-Control, and point the app at the public URL.
   ample bucket publish <bucket-name>
  1. Validate before cutover. Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/origin-cache-refresh).
  2. Cut over. Redeploy the app with the new asset base URL, verify delivery from the CDN URL, keep the distribution until confirmed, then disable it.
  3. Rollback. Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.

Tested examples

Success checks

Limitations

Cost estimate

Estimated 5.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).

Verification evidence

Execution binding

No execution binding. This recipe is documentation only; nothing is executed automatically.