How to use CloudFront with object storage buckets
Coming from another cloud?
▸AWS·Amazon S3
This Quake AI feature maps to AWS’s Amazon S3.
▸Azure·Blob Storage
This Quake AI feature maps to Azure’s Blob Storage.
▸DigitalOcean·Space (bucket)
Space (bucket)
- Naming differs: users create a “Space” that is a bucket, and each bucket has a unique URL (virtual-hosted or path style), whereas Swift uses containers within an account namespace. ().
- Bucket addressing uses S3-style endpoints such as `${BUCKET}.${REGION}.digitaloceanspaces.com` (and `${REGION}.digitaloceanspaces.com/${BUCKET}`), which differs from Swift’s account/container/object path conventions. (, ).
- Access keys can be scoped to high-level permission tiers (Read, Read/Write/Delete, All) applied across buckets/objects, which differs from Swift’s typical tenant/user + container ACL model. ().
▸Google Cloud·Storage
This Quake AI feature maps to Google Cloud’s Storage.
▸Hetzner·Buckets
Buckets
- S3 API (PUT Bucket requires specific headers like x-amz-acl limited to private/public-read, LocationConstraint); Swift uses POST/PUT Container with broader ACLs via X-Container-Read/Write.
- Public access via https://bucket.location.your-objectstorage.com/object; Swift public via temp URLs or ACLs.
- Up to 100 buckets per account; Swift has no hard limit.
How to use CloudFront with object storage buckets
Configure a Quake AI bucket as a CloudFront custom origin to cache objects at AWS edge locations.
Prerequisites#
- A Quake AI object storage bucket with an object to test
- Your Quake AI tenant ID and bucket name
- S3 credentials that can update the bucket policy
- An AWS account with permission to create a CloudFront distribution
Make the bucket readable by CloudFront#
CloudFront treats the Quake AI S3-compatible endpoint as a custom origin. Start by applying the public read bucket policy. You can restrict direct origin access after the distribution works.
Test the tenant-prefixed object URL before you configure CloudFront:
curl -I "https://object.REGION.rumble.cloud/TENANT_ID:BUCKET_NAME/OBJECT_KEY"Expect a 200 OK response.
Create the CloudFront distribution#
- In the AWS console, open CloudFront and choose Create distribution.
- Under Origin, enter your regional Quake AI object storage hostname in Origin domain. For example, use
object.us-east-1.rumble.cloud. Enter the hostname withouthttps://. - Select HTTPS only for Protocol.
- Set Origin path to
/TENANT_ID:BUCKET_NAME. Do not add a trailing slash. - Configure the default cache behavior for the methods and cache policy your objects require.
GETandHEADcover static downloads. - Choose Create distribution, then wait for the distribution status to become Deployed.
CloudFront appends each viewer request path to the origin path. A request for /photo.jpg becomes:
https://object.us-east-1.rumble.cloud/TENANT_ID:BUCKET_NAME/photo.jpgVerify the distribution#
Request the same object through the CloudFront domain:
curl -I "https://DISTRIBUTION_DOMAIN/OBJECT_KEY"Expect 200 OK. The X-Cache response header reports whether CloudFront served a cached response or fetched the object from the origin. Repeat the request to check for a cache hit.
Restrict direct origin access#
After the distribution works, add a custom origin header in CloudFront and require the same value in the bucket policy. CloudFront overwrites a viewer-supplied header with the configured value before it sends the origin request.
Replace $tenant, $bucket, and ORIGIN_HEADER_VALUE in this policy:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "CloudFrontReadGetObject",
"Principal": "*",
"Effect": "Allow",
"Action": [
"s3:GetObject"
],
"Resource": [
"arn:aws:s3::$tenant:$bucket/*"
],
"Condition": {
"StringEquals": {
"aws:Referer": "ORIGIN_HEADER_VALUE"
}
}
}
]
}Apply the policy with your S3-compatible client. In the CloudFront distribution:
- Edit the Quake AI origin.
- Under Add custom header, set Header name to
Referer. - Set Value to the value in the bucket policy.
- Save the origin and wait for the distribution status to return to Deployed.
Verify that the CloudFront URL still returns 200 OK. A direct request to the tenant-prefixed origin URL without the header should return 403 Forbidden.
If viewers need time-limited access, configure CloudFront signed URLs. Signed URLs control viewer access to CloudFront, while the custom origin header controls direct access to the bucket.
Use origin failover during a migration#
To keep a legacy object store available during migration, create a second CloudFront origin and place both origins in an origin group. Set the Quake AI bucket as the primary origin and the legacy store as the secondary origin. CloudFront sends eligible read requests to the secondary origin when the primary returns a configured failure status.
See also#
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
For the full policy, see Usage Guidelines.
Last validated: 01.09.2026