A North American OTT streaming media operator
AWS-validated reference — full details available to AWS Partner Validation or on request. (Customer name held on file with VeUP.)
VeUP operates A the customer Media Co.'s OTT estate — Kidoodle.TV (safe-kids AVOD) and Victory+ (FAST sports) — on Amazon CloudFront with AWS Elemental MediaTailor server-side ad insertion. FinOps, AWS Backup DR, Config, and Security Hub run the ~$5.9M/yr estate at Green account health.
The challenge
A the customer Media Co. delivers two over-the-top consumer streaming properties — Kidoodle.TV, a safe-streaming kids' ad-supported (AVOD) service, and Victory+, a free ad-supported streaming TV (FAST) sports service — whose business depends on reliable, low-latency video delivery at internet scale and on targeted server-side ad insertion to monetize AVOD/FAST inventory. At ~$5.9M/yr of recurring AWS spend, the estate needed cost matched to actual audience demand (rightsizing + committed-use coverage), a defined Backup-and-Restore DR strategy, continuous configuration drift detection, and centralized security-finding aggregation — a governed, auditable posture appropriate to a children's streaming brand.
The solution
A production OTT streaming estate on Amazon CloudFront for global edge delivery of HLS/DASH segments and manifests, with AWS Elemental MediaTailor performing server-side ad insertion at the manifest layer (device-consistent, ad-blocker-resistant monetization). Cache behaviors are tuned for OTT — long-lived caching for immutable media segments, short-TTL for the MediaTailor-personalized manifest path — fronted by AWS WAF, ACM HTTPS, and Amazon Route 53. Around the delivery plane: a documented two-phase FinOps program (rightsizing/modernization, then Reserved-capacity/commitment analysis) backed by an EC2 waste-analysis workbook; AWS Backup Backup-and-Restore DR to the customer's RTO/RPO; AWS Config continuous drift detection; AWS Security Hub centralized posture; Amazon CloudWatch operational metrics; AWS Organizations + IAM Identity Center governance.
Architecture
AWS Well-Architected view of the OTT delivery and governance estate — from the pre-FinOps/governance baseline through to the production CloudFront + MediaTailor edge, VPC compute, and the AWS Backup / Config / Security Hub governance plane.
Production outcomes
| KPI | Result |
|---|---|
| Production outcomes | Both OTT properties run in production on a shared AWS OTT stack at ~$5.9M/yr recurring AWS spend with a Green account-health rating; a two-phase FinOps engagement (rightsizing + Reserved-Instance/committed-use analysis) identified and captured cost reductions protecting streaming margin; a Backup-and-Restore DR strategy on AWS Backup deployed to the RTO/RPO target; AWS Config drift detection and AWS Security Hub centralized findings moved the estate to a governed, auditable operational posture. Granular per-service savings held in the customer's Cost Explorer / EC2 waste-analysis workbook and provided via the customer-reference channel. |
| Engagement window | 2024 (Ignite/EDP engagement; CloudFront/MediaTailor + FinOps + DR workstreams across 2024-2026) → Ongoing (production; Customer Live) |
| Cost / TCO posture | Cost optimization was a primary workstream: a two-phase FinOps program modeled CloudFront data-transfer and request volume, MediaTailor ad-insertion volume, and the supporting compute/storage footprint against the growth trajectory, producing (1) a rightsizing/modernization analysis backed by an EC2 waste-analysis workbook and (2) a Reserved-capacity/committed-use analysis — with the delivery-layer commitment formalized via the CloudFront + MediaTailor PPA uplift, tying delivery spend to AVOD unit economics (sustainable cost-per-stream as audience and catalog scale). |
| Lessons & continuation | For an AWS-native OTT operator, CloudFront's native MediaTailor integration makes server-side ad insertion device-consistent and origin-efficient (vs client-side ad insertion or a CDN-only approach); OTT cache behaviors must split immutable-segment caching from the short-TTL personalized-manifest path; native managed services (AWS Backup + Config + Security Hub) give a governed, auditable resilience/security posture without bespoke tooling — the right bar for a children's streaming brand. |
Amazon CloudFront · AWS Elemental MediaTailor · AWS WAF · AWS Certificate Manager · Amazon Route 53 · Amazon S3 · AWS Backup · AWS Config · AWS Security Hub · Amazon CloudWatch · AWS Organizations · IAM Identity Center