Restrict access to an Amazon origin - Amazon CloudFront
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Restrict access to an Amazon origin

You can configure CloudFront and some Amazon origins in a way that provides the following benefits:

  • Restricts access to the Amazon origin so that it's not publicly accessible

  • Makes sure that viewers (users) can access the content in the Amazon origin only through the specified CloudFront distribution—preventing them from accessing the content directly from the bucket, or through an unintended CloudFront distribution

To do this, configure CloudFront to send authenticated requests to your Amazon origin, and configure the Amazon origin to only allow access to authenticated requests from CloudFront. For more information, see following topics for compatible types of Amazon origins.