Hosting your entire web application using S3 and CloudFront
sankalpjonna.com
sankalpjonna.com
So, if we don't make our websites available in languages used by oppressed peoples, if we don't make sure it's very low latency, and if we try to filter out abusive users, we're making the world a worse place. Not just leaving the world in a bad state, but actively increasing the harm done to the world, just by making a website that not everyone can or wants to use.
Not only do I not buy this argument, it makes me want to support Tor less, if for no other reason than blatantly ignoring why the captchas were put up in the first place.
The part you have a problem with, that it actively increases harm done in the world, wasn't even an assertion made by Tor.
If you use TOR to access services that can be directly correlated to your identity you are simply using a slow VPN at that point.
I don't care how many points of presence Cloudflare has if the performance is worse.
Do you have any data that supports your claims?
[1] https://goldfirestudios.com/cdn-benchmarks-cloudflare-vs-clo...
[2] https://www.bizety.com/2018/05/01/network-performance-benchm...
Cloudflare free tier can serve terabytes of bandwidth for free. Add some cheap hosting or free tier EC2 or GCP and you are good to go.
I am in New Zealand and a company I worked for used Cloudflare and we found out that our site was being served from Japan most of the time (8800 km away). This meant a request would go: Auckland -> Japan -> Sydney (our data center)
The fix was to upgrade to their $200/mo plan and we found we would be served from AKL or SYD most of the time, occasionally still Japan.
Also Cloudflare "protected" 8chan during the Christchurch terrorist shooting last year which makes them unpopular in some quarters. I have heard that given as a reason our largest telco won't peer with them.
You do know The Daily Stormer is a far-right neo-Nazi, white supremacist, and Holocaust denial commentary and message board website that advocates for the genocide of Jews, right?
There's a certain subset of the tech community that entirely doesn't get that words result in real-world harm. It isn't just bytes in a database we can be indifferent to because it doesn't affect anything.
Government is different from the private sector but as we rapidly move towards a future ruled by megacorporations, the application of rules and laws becomes ever more important.
That only covers how government is supposed to act, right? I mean, a hosting company is free to pick how their service is used. If a client insists in abusing and breaking the law by, say, repeatedly publishing hate speech, doesn't the company has the right to act? I mean, just the reputation hit makes this a business liability.
CF themselves have raised similar concerns about due process in the way they handled this particular case, but I can understand why they dropped a customer against whom they had a pretty strong case for suing.
https://blog.cloudflare.com/why-we-terminated-daily-stormer/
If I was a business, I would want to pay for support. That doesn't apply to all businesses I know.
Free
Cloudflare for Individuals is built on our global network.
This package is ideal for people with personal or hobby projects that aren’t business-critical.At such a low amount, cost is not the main concern for most websites. Speed, reliability, and ease of development are.
Why not dump these static files into a shared hosting? It shouldn't cost you more than couple of bucks a month.
You get SSL, Email, sub-domains, SSL, logs and much more for couple of bucks a month.
Not knowing something doesn't mean its complicated, it just means it is unfamiliar, for you. Once you did this several dozen times, its the simplest thing ever.
The second thing is AWS is very expensive for what it does. Do you need to add DNS records? There is Route 53 which costs extra. Do you need emails? There is AWS Simple Email which costs extra. Do you need logs? The storage cost (although little) is added to your bill. Do you need databases? Do you need support?
All I am saying is that shared hosting should be first considered for static websites.
Flip it around. AWS let's you not pay for things you don't need. Then, if there's a biz requirement for something else, you make that _investment_.
Of course there are alternatives. But shared hosting is a roll of the dice. For a hobby project or POC? Sure, start with shared. But if you're certain shared is not a semi-longer term option don't wasteyour time. Shared is cheap for a reason. Saving a couple dollars will dry up quickly in downtime and headache time.
If you look at the free tier limits, and monthly costs. Putting a simple rest app behind API gateway with a few buckets and a little lambda gives you a whole lot of bang for very little cost.
If you're a person in a region and your website is going to get bursty use by people in your region then it's a pretty cheap deal.
Monthly costs < 1 coffee for a blog or some non trivial page.
I must add that AWS makes it easy to use WAF (web application firewall) to protect you from this.
Route53 cost is ridicule. Not an issue at all.
A few missed orders can cost you more.
This is a very stable architecture for such websites and it's great to see it being widely adopted.
I've written more details about the Rain Radar application in this blog post: https://yuv.al/blog/an-architecture-for-periodically-updatin...
No real reason to archive them in the long term, but one day I might start training some neural network on those images :)
Still a nice guide for static website owner.
The only downside is that it can get quite messy maintaining.
Could you elaborate on what part of the maintenance would be messy? I was under the impression that maintaining this would be quite easy because there is no physical server present anywhere in this setup.
My bad for not giving a more appropriate title for the post. You re right this setup does not take the backend APIs into account. In our case we use Lambda for the backend APIs so that is also serverless but I failed to mention it in the post.
It's so nice to be able to review a PR not only based on its code, but also by having a look at the built website.
(For the author of this article, it looks like the combination of CLoudFront's default document and custom error handling did the job for their site - just flagging this as something to look out for in cases where it doesn't work :-) )
AWS suggest a workaround using Lambda@Edge (https://aws.amazon.com/blogs/compute/implementing-default-di...) to rewrite the requests at the CloudFront layer - but at that point I decided that actually getting the site published was more important than adding more to the technology stack, so it's now happily hosted on Netlify's free tier.
I looked at that approach at the time but didn't go down that route because, as far as I understood (unless I missed something), that would involve having the S3 bucket directly publicly accessible over HTTP (not HTTPS) with the S3-style URLs, including public access. And my main motivation for adding CloudFront to the mix was to support/enforce TLS - I certainly didn't have traffic levels requiring it!
(But, pragmatically, the key risks of someone going to the effort of finding and using the unpublished S3 URL would seem to be be that (a) the site could stop working if I change the hosting and (b) they, through their own choice, aren't using TLS - which, for a static, low-traffic, personal blog, could be considered pretty low.)
Thanks for the information. I guess we never encountered this because our application is in react js framework, so once the build is done it creates just one index.html file and there are no subdirectories.
But this is duly noted
Subject to fair use (which is fair). https://webmasters.stackexchange.com/questions/88659/how-can...
I know many people who are saving 5+TB per month of their free tier without any problems.
Behind the scenes you’re still running on s3/cloudfront so you don’t need to worry about scalability, but you’ll get automatic https, build and deploy pipeline hooked into your github repo, per branch environments, etc.
For fullstack websites, I created https://github.com/tobilg/aws-fullstack-website which will additionally create a API based on API Gateway and its HTTP API feature
Bad title. Should say "how to host the frontend to your SPA for pennies on CloudFront + S3"
Ideally something practical (as opposed to theoretical) or something from personal experience.
I generally agree but I feel that more details could be useful.
A practical example that happened to my employer recently : we migrated to Microsoft Azure when they opened two datacenters in our country. We didn't have to change any code because we don't use vendor locked solutions.
https://dev.to/shane/how-to-create-an-aws-s3-hosted-angular-...
Did I miss something or is this a real problem?