VeUP
← All case studies
Production Engagement · Anonymized
Amazon CloudFront CDN rebuild for a CG/VFX marketplace, cutting third-party search cost
Staffing & Recruiting (CG/VFX talent marketplace)
Amazon CloudFrontAmazon LightsailAWS WAFRoute 53
Amazon CloudFront · CloudFront CDN Rebuild

A CG/VFX talent marketplace

AWS-validated reference — full details available to AWS Partner Validation or on request. (Customer name held on file with VeUP.)

VeUP rebuilt the customer content-delivery plane on Amazon CloudFront, migrating the customer.com off Strapi on AWS Amplify to WordPress on Amazon Lightsail — DNS/SSL cutover with rollback, WordPress-tuned edge caching, AWS WAF hardening, improved Core Web Vitals, and reduced third-party (Algolia) cost.

The challenge

the customer, a CG/VFX talent marketplace, ran the customer.com on a Strapi frontend on AWS Amplify and needed to modernize onto a maintainable WordPress platform without losing public-site performance — while controlling third-party (Algolia) search cost and hardening the edge — through a controlled cutover with a safe rollback path.

The solution

A two-phase Amazon CloudFront CDN rebuild and modernization. Phase 1 cut the frontend over to a new/updated Amazon CloudFront distribution with a WordPress origin on Amazon Lightsail and WordPress-appropriate cache behaviors, provisioned AWS Certificate Manager SSL with Amazon Route 53 DNS validation, and executed a controlled Route 53 DNS/SSL cutover retaining AWS Amplify as a rollback buffer. Phase 2 hardened the edge — dynamic page caching to mitigate Algolia cost, a caching-architecture review, Lambda@Edge response handling, Core Web Vitals performance optimization, AWS WAF security hardening against bots/abuse, and CDN usage/cost control — monitored with Amazon CloudWatch.

Architecture

Previous-state Strapi-on-Amplify stack modernized to a WordPress-on-Lightsail origin behind a rebuilt Amazon CloudFront edge, annotated against the AWS Well-Architected Framework.

Previous-state architecture: Strapi frontend on AWS Amplify with Route 53 DNS and direct, uncached per-request calls to third-party Algolia search.
Previous state
Target-state architecture on AWS: Amazon CloudFront distribution over a WordPress-on-Lightsail origin, with AWS WAF, Lambda@Edge, ACM/Route 53, an Amplify rollback buffer, and CloudWatch observability.
Target state on AWS
Layer-by-layer build-up of the target-state architecture: network and edge foundation, compute and application, data, then security and observability, with numbered request and data flows.
Layer-by-layer build-up
AWS Well-Architected annotated architecture diagram: previous-state Strapi frontend on AWS Amplify migrating to a WordPress-on-Lightsail origin behind a rebuilt Amazon CloudFront distribution, with AWS WAF, Lambda@Edge, ACM/Route 53, an Amplify rollback buffer, and CloudWatch observability, plus the six Well-Architected pillar bullets.
Full Well-Architected overview

Production outcomes

KPIResult
Production outcomesthe customer.com is served in production through the rebuilt Amazon CloudFront distribution over a WordPress on Lightsail origin, with AWS WAF protection and HTTPS-only delivery. Core Web Vitals improved via the rebuilt edge and WordPress-tuned caching, and dynamic page caching reduced third-party (Algolia) search request volume and cost. The granular before/after Core Web Vitals and Algolia-cost series are customer-tenant artifacts provided to AWS Partner Validation via the standard customer-reference channel.
Engagement window2024-10-01 (Resell Customer Live; migration delivery 2024–2025) → 2025 (CloudFront rebuild + Phase 2 hardening delivered); ongoing
Cost / TCO postureCost levers: dynamic page caching at the CloudFront edge cut third-party (Algolia) request volume and cost; Lightsail capacity right-sizing and CDN usage/cost control kept infra spend (~$30k/yr, ~$2,525/mo) in line. Realized $/% figures are held in the customer's AWS account / billing.
Lessons & continuationA CloudFront rebuild with an Amplify rollback buffer makes a CMS migration cutover low-risk; absorbing repeat requests at the edge (dynamic page caching) is a direct lever on third-party search cost; WAF managed rules belong in front of a public marketplace from the cutover.
AWS services in production

Amazon CloudFront · Amazon Lightsail · AWS Certificate Manager · Amazon Route 53 · AWS WAF · Amazon CloudWatch · Lambda@Edge