SEC GUY / EXPERIENCE BUILDER / PROJECT 04

Build a site.
Prove the architecture.

Turn a résumé website into a cloud portfolio project. Publish a static site through HTTPS, keep the storage origin private, and document the decisions you can defend in an interview.

01 / PLANChoose a simple static site
02 / DEPLOYConnect S3 and CloudFront
03 / VALIDATETest HTTPS and origin access
04 / EXPLAINPublish the proof of work
THE PROJECT BRIEF

A portfolio piece with an engineering story.

Build a small public résumé or project site and explain how its delivery path protects the origin. The goal is not a flashy landing page; it is a working site, a defensible architecture, and evidence that you tested your assumptions.

THE BUILD

One static site

HTML, CSS, and optional client-side JavaScript. No server-side app or database is required for this project.

THE CONTROL

One private origin

Keep S3 Block Public Access enabled and let only your CloudFront distribution read the site files through origin access control.

THE PROOF

One clear narrative

Show the live HTTPS URL, a redacted architecture diagram, test results, and a short explanation of why you chose this design.

THE BUILD PLAN

Four stages. A real outcome.

Follow the official AWS documentation at each stage. Use an isolated learning account or environment that you control, and keep credentials and private data out of the site and your screenshots.

01 / DESIGN

Make the site purposeful.

  • Write a concise résumé or portfolio page with accessible headings and a contact route you are comfortable making public.
  • Keep the site static; do not embed API keys, secrets, personal IDs, or private documents.
  • Sketch the request path: visitor → CloudFront → S3.
02 / DEPLOY

Protect the origin.

  • Create an S3 bucket and keep Block Public Access enabled.
  • Upload the static files, then configure CloudFront with the S3 bucket origin—not the S3 website endpoint.
  • Use CloudFront origin access control with Sign requests (recommended) and a bucket policy scoped to your distribution.
03 / SECURE

Use HTTPS end to end.

  • Set CloudFront viewer protocol policy to redirect HTTP to HTTPS or require HTTPS.
  • Use the CloudFront domain initially. A custom domain is optional; if you use one, follow AWS certificate and DNS guidance.
  • Review default root object, cache behavior, and any custom error response your site needs.
04 / VERIFY

Test what you claim.

  • Open the live site on desktop and mobile and confirm the expected pages and assets load.
  • Confirm HTTP redirects to HTTPS and direct S3 object access is denied.
  • Record the CloudFront URL, your configuration decisions, and redacted evidence in a portfolio README.
PORTFOLIO OUTPUT

Show the work behind the link.

A live site alone is easy to miss. Pair it with a short architecture note that explains the objective, constraints, controls, tests, and tradeoffs. That is the story to bring to an interview.

Keep screenshots free of account IDs, bucket names you consider sensitive, personal contact details, credentials, and billing information. Redact before sharing.

YOUR PROOF-OF-WORK CHECKLIST
  • A working public HTTPS site and its URL
  • A simple diagram of visitor → CloudFront → private S3 origin
  • Evidence that HTTP redirects to HTTPS
  • Evidence that the S3 origin is not publicly readable
  • A README with decisions, validation, costs, and lessons learned
  • A teardown note for resources you no longer need
THE INTERVIEW STORY

Explain why it works.

Use these prompts to turn the project into a conversation, not a checklist of services.

DECISION 01

Why CloudFront?

Explain HTTPS delivery, caching, and how it sits between visitors and the origin.

DECISION 02

Why a private bucket?

Explain why the public site does not require public read access to every S3 object.

DECISION 03

How did you verify?

Describe your HTTPS, direct-origin, mobile, and missing-page tests—and what each proved.

BUILD WITH PRIMARY SOURCES

Use the current AWS guidance.

AWS services and pricing change. Check the official documentation before configuring or paying for anything.

QUESTIONS BEFORE YOU BUILD

Know the boundaries.

Can I use the S3 website endpoint?

Not for this private-origin pattern. The S3 website endpoint is HTTP-only and cannot use CloudFront origin access control as an S3 bucket origin. Choose the S3 bucket origin in CloudFront.

Do I need a custom domain?

No. The CloudFront domain is enough to demonstrate this project. A custom domain adds DNS and certificate work; if you choose one, CloudFront requires an AWS Certificate Manager certificate in us-east-1.

Is this a free AWS lab?

No cost is guaranteed. AWS charges depend on account eligibility, services, traffic, storage, and optional features. Review current pricing and set a budget alert before creating resources.

Build the site. Keep the receipts.

Return to Experience Builder when you are ready for the next portfolio path.

Back to Experience Builder