Networking & Content Delivery
Category: Uncategorized
Building Multi-Region Active-Active Architectures with CloudFront VPC origins and Advanced Routing
Introduction Building a multi-region active-active architecture with Amazon CloudFront requires careful coordination of traffic routing to address performance, traffic management, and session consistency requirements, along with automated failover to maintain availability during regional events. In November 2024, AWS released Amazon CloudFront VPC origins, which provides direct connectivity to private resources within your Amazon VPC without […]
Shared DNS views for multi-account environments with Amazon Route 53 Global Resolver
DNS views in Amazon Route 53 Global Resolver give networking teams centralized control over shared name resolution, but application teams still need the freedom to manage their own DNS records. Striking that balance gets harder with multi-account architecture and as services grow. Amazon Route 53 Global Resolver addresses centralized resolution piece by delivering a single […]
How Amazon CloudFront delivered traffic for the FIFA World Cup 2026
When Spain broke the deadlock in extra time during the Final of the FIFA World Cup on July 19, tens of millions of streams surged at the same instant: replay requests, second-screen clips, viewers who had stepped away rushing back. At that moment, Amazon CloudFront was delivering over 117 Tbps of traffic for the FIFA […]
Centralized VPC inspection with Amazon VPC Route Server and AWS Transit Gateway
Centralized VPC inspection with Amazon VPC Route Server and AWS Transit Gateway helps you route traffic from multiple virtual private clouds (VPCs) through a shared firewall for security enforcement. Spoke VPCs send traffic through AWS Transit Gateway to a dedicated inspection VPC, where firewall appliances examine it before forwarding. The challenge is making this inspection […]
How Magnite uses Amazon VPC Route Server and Border Gateway Protocol (BGP) to build dynamic hybrid-cloud routing
Magnite, the largest independent sell-side advertising company, runs an engineering team that processes more than a trillion ad requests each day across Amazon Web Services (AWS) and its own data centers. In Magnite’s hybrid-cloud environment, network behavior is not background infrastructure. It’s part of the application. The team needs deterministic traffic steering, fast failover, and […]
Introducing the LBC Ingress-to-Gateway API migration toolkit
Migrating your AWS Load Balancer Controller (LBC) Ingress resources to the Gateway API by hand is tedious and error prone. You need to rewrite annotations, path rules, and TLS configuration, and a mistake can disrupt the production traffic. The Ingress-to-Gateway API migration toolkit for LBC removes that risk by giving you a guided, validated path […]
Prevent VPN traffic leaks with Client VPN Route Enforcement in AWS Client VPN
Unintended traffic leaks are a real risk when you rely on remote connectivity to access cloud resources, so maintaining VPN routing integrity on connected devices is essential. When a device connects through a VPN, the administrator-defined routes instruct the operating system to direct specific traffic through the encrypted tunnel. However, those routes can be altered […]
Intelligent failover using AWS Lambda@Edge and Amazon DynamoDB
Modern applications increasingly require seamless user experiences and high availability, especially in scenarios where regional disruptions or outages could impact critical workloads. Businesses frequently face challenges when dynamically allocating users to specific endpoints or regions while providing persistent user-endpoint relationships and implementing robust failover mechanisms. To address these complex scenarios, this post describes a solution […]
Amazon CloudFront Premium flat-rate pricing plan now supports higher, configurable usage allowances
Running an internet-facing application means estimating and managing costs across many services and features: content delivery, web application firewall (WAF), DNS, logging, and DDoS protection. Each has its own pricing model, its own metering, its own line item on the bill. Traffic from successful launches, organic growth, and AI bots can spike without warning, increasing […]
Selecting the Right AWS VPN Solution: A Decision Framework
Introduction This post is intended for networking engineers and architects evaluating AWS VPN options (200-level content). It assumes familiarity with basic AWS networking concepts such as virtual private clouds (VPCs), virtual private gateways (VGWs), and transit gateways (TGWs). If you are new to AWS VPN, the AWS VPN User Guide provides foundational context. Organizations implementing […]









