← Back to projects
IaCActiveOpen source

AWS Static Site (S3 + CloudFront)

A secure static-site stack: a private S3 bucket served only through CloudFront via Origin Access Control, an ACM TLS certificate, Route 53 DNS, and a GitHub Actions workflow for content sync + cache invalidation.

Highlights

  • Private bucket + OAC (no public S3)
  • TLS + custom domain done right
  • Terraform CI validated

Tech Stack

AWSS3CloudFrontACMRoute 53Terraform

Reactions & comments