Lesson 171 · AWS Learning Path

AWS 171: Architecture: choose Route 53, CloudFront, Global Accelerator, WAF, and Shield

· Published · 8 min read

Labelled process diagram for AWS 171: User and protocol to DNS and edge entry to Protection, cache, or acceleration to Healthy regional origin and evidence, with decision, proof and rejection evidence.

Why this lesson matters

Choose Route 53, CloudFront, Global Accelerator, WAFV2, and Shield as complementary controls instead of treating them as direct substitutes.

These services are usually layers, not alternatives: Route 53 publishes/discovers names, CloudFront proxies and caches HTTP, Global Accelerator accelerates TCP/UDP behind static anycast IPs, WAF filters supported HTTP requests and Shield mitigates DDoS. Use only the layers whose measurable requirement exceeds their cost and failure complexity.

What you will be able to do

By the end, you can:

  • explain architecture: choose route 53, cloudfront, global accelerator, waf, and shield in plain language;
  • locate the current service controls in the AWS Management Console;
  • run the matching CloudShell or AWS CLI queries and explain every important field;
  • draw the identity, network, data, failure, and monitoring path;
  • choose the service from requirements and reject it when those requirements are absent;
  • diagnose a failed or misleading result from evidence;
  • state the cost owner and prove cleanup or a no-create result.

Before you start

  • Use a personal AWS account only when its owner has approved the lesson. Do not use the root user for daily work.
  • CloudShell is the default command environment. AWS028 explains CloudShell; AWS029 and AWS030 explain local AWS CLI installation and profiles.
  • The course example Region is ap-south-1. Global services and services with a required control Region are called out in their commands.
  • Run aws sts get-caller-identity privately. Redact the account number before sharing evidence.
  • Never paste access keys, passwords, secret values, private object data, presigned URLs, or full account-specific ARNs into a submission.
  • This is a no-create lesson. Every Console action and AWS CLI command is read-only. Create the practical artifact locally.
  • Console wording can change. Use the Console service search if a menu label has moved, then confirm the current field in the official documentation.

The core model

QuestionWhat it means in this lesson
PurposeChoose Route 53, CloudFront, Global Accelerator, WAFV2, and Shield as complementary controls instead of treating them as direct substitutes.
Scope and boundaryThe learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for Global delivery architecture decision.
Evidence of successSuccess means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for Global delivery architecture decision.
Cost modelRequests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design.
Safe rejection ruleAvoid product stacking without a requirement or claiming DNS, cache, acceleration, and firewall controls do the same job.

How the request flows

+----------------------+
|  User and protocol   |
+----------------------+
           |
           v
+----------------------+
|  DNS and edge entry  |
+----------------------+
           |
           v
+--------------------------------------+
|  Protection, cache, or acceleration  |
+--------------------------------------+
                   |
                   v
+----------------------------------------+
|  Healthy regional origin and evidence  |
+----------------------------------------+

For Global delivery architecture decision, the important boundary is this: The learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for Global delivery architecture decision. Success means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for Global delivery architecture decision. That is why the lesson pairs the Console with CLI output and a practical artifact. One interface may hide a field, use a cached view, or be scoped differently. Matching evidence is stronger than a screenshot alone.

Architecture decision table

SituationDirectionReason
Requirement matchesCombine only the layers required by protocol, latency, caching, address, security, and recovery needs.Select only after scope, behavior, security, recovery, operations, and price evidence agree.
Requirement does not matchAvoid product stacking without a requirement or claiming DNS, cache, acceleration, and firewall controls do the same job.Rejecting an attractive service is a valid architecture result.
No create permission or cost approvalUse supplied evidence and local design workLearning does not depend on creating an hourly resource.
Existing resource is unknown or unownedInspect only, then stopNever change or delete a resource merely because it resembles a course example.

Layer selector

RequirementControlWhat it does not do
domain delegation, records, policy-based DNS answer, hybrid resolutionRoute 53 authoritative/Resolverproxy traffic, cache HTTP objects or terminate application TLS
global HTTP(S) proxy/cache, origin protection, edge logicCloudFrontprovide arbitrary TCP/UDP acceleration or replicate origin truth
fixed global IP and optimized TCP/UDP path to healthy Regional endpointsGlobal Accelerator Standardcache content, host DNS or protect every application-layer exploit
deterministic user-to-game-server mappingGA custom routinghealth-check/fail over destinations automatically
managed L7 request filtering/rate/bot rules on supported resourcesWAFV2secure direct origin bypass, inspect arbitrary L4 traffic or fix app authorization
baseline DDoS mitigationShield Standardprovide DRT/cost protection or enroll every advanced resource
enhanced DDoS detection/response/cost protection for enrolled resourcesShield Advancedeliminate capacity/health/runbook responsibilities

A common static site path is Route 53 alias → CloudFront + WAF/Shield → OAC-protected S3. A dynamic API can use Route 53 → CloudFront + WAF → Regional ALB/API origins with safe caching or no caching. A TCP game service can use Route 53 name → Global Accelerator → NLB/EC2, with application TLS and Shield/endpoint controls. Active-passive DNS may use Route 53 health; fast new-connection IP routing may use GA; neither synchronizes databases.

Define where DNS, viewer/application TLS, authentication, WAF, DDoS, cache, health and origin authorization terminate. Hide origins from direct access. Decide IPv4/IPv6, client-IP preservation, data residency and log location. Cross-border edge processing/caching can have compliance implications even when the origin Region is fixed.

Availability calculations include DNS TTL/resolver, edge/accelerator health detection, connection lifetime, endpoint capacity, origin data RPO and application failback. Test all-unhealthy behavior and secondary capacity. Cost includes hosted zones/queries/health checks/Resolver endpoints, CloudFront requests/egress/functions/logs/invalidation/Origin Shield, GA hourly/data premium, WAF ACL/rules/requests/managed groups/logs and Shield Advanced subscription/data/resource charges.

AWS Management Console, step by step

Sign in with the normal non-root learning identity. Write the expected starting state before opening the service.

  1. Use the Console service search and open Route 53, CloudFront, Global Accelerator, WAF, and Shield inventories; confirm the account and Region before reading the page.
  2. Inspect the supplied or owned resource's status, configuration, permissions, networking, encryption, monitoring, tags, and dependencies without changing it.
  3. Open the related metrics, logs, events, or history view and record one timestamped signal that would prove or disprove the expected behavior.
  4. Return to the resource list, clear filters, and record the final inventory. On the read-only track, do not choose Create, Save, or Delete.

CloudShell and AWS CLI, step by step

Start with a known caller and Region:

export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws configure list

Redact the account part of the ARN in shared evidence. Now run the topic queries:

aws route53 list-hosted-zones --query 'HostedZones[].Name' --output text
aws cloudfront list-distributions --query 'DistributionList.Items[].DomainName' --output text
aws globalaccelerator list-accelerators --region us-west-2 --query 'Accelerators[].Name' --output text
aws wafv2 list-web-acls --scope REGIONAL --region ap-south-1 --query 'WebACLs[].Name' --output text

Expected interpretation

The services sit at different layers: DNS answer, HTTP edge cache, network acceleration, HTTP filtering, and DDoS protection. A design may use several but must justify each.

Practical work

Submit a global-delivery ADR for static assets, dynamic API, gaming TCP, and active-passive recovery. Map each packet, DNS, TLS, health, security, logging, failover, and charge boundary.

For each workload reject two plausible layers, draw normal/bypass/failure paths and calculate latency/cost. Tabletop origin bypass, stale cache/private-data leak, WAF false positive, DDoS/flash crowd, unhealthy Region, all endpoints unhealthy, DNS cache delay and database lag. Include rollout/rollback for DNS, distribution, accelerator dial and WAF Count→Block.

Diagnose this topic from its own evidence

Locate the first service that saw the request: authoritative DNS answer/TTL, GA flow/endpoint health, CloudFront request/cache/WAF action, origin log. If no layer has evidence, investigate client DNS/network/TLS. Avoid adding layers to mask the fault. A cache hit cannot prove origin health; healthy GA endpoint cannot prove business correctness; WAF block cannot appear in origin logs.

Cost and cleanup

Requests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design.

Knowledge check

  1. What operational purpose is this lesson solving?

Expected direction: Choose Route 53, CloudFront, Global Accelerator, WAFV2, and Shield as complementary controls instead of treating them as direct substitutes.

  1. Which scope or ownership boundary must be proved first?

Expected direction: The learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for Global delivery architecture decision.

  1. What evidence is strong enough to accept the result?

Expected direction: Success means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for Global delivery architecture decision.

  1. Which tempting design or shortcut must be rejected?

Expected direction: Avoid product stacking without a requirement or claiming DNS, cache, acceleration, and firewall controls do the same job.

  1. Which cost dimensions and retained resources need an owner?

Expected direction: Requests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design.

Lesson acceptance

Pass when every selected layer has one explicit requirement, cost and owner; packet/DNS/TLS/identity/cache/health paths are accurate; origin bypass and recovery are tested; and two attractive but unnecessary services are rejected. Fail if products are direct synonyms, failover implies data replication, or security relies on a public bypassable origin.

Official sources

Advertisement