New feature

Amazon CloudFront now supports Origin Access Control for Amazon S3 Multi-Region Access Points

Amazon CloudFront adds Origin Access Control for S3 Multi-Region Access Points, enabling secure access without custom SigV4a headers

Starting today, Amazon CloudFront supports Origin Access Control (OAC) for Amazon S3 Multi-Region Access Points (MRAP), allowing only designated CloudFront distributions to access origins. Previously, customers had to compute and forward Asymmetric Signature Version 4 (SigV4a) Authorization headers using custom Lambda@Edge functions. Now, CloudFront natively signs requests to S3 MRAP origins, providing faster cache-miss fills from the nearest region and secured MRAP access without custom header computation. This feature is available worldwide except in the China region, with no additional fees.

Why it matters

Developers and deployment managers seeking improved cache performance and security for globally distributed content delivery are the primary audience

Read the original AWS announcement