CloudFront OAC Adds Native Support for S3 MRAP
🔒 Starting today, CloudFront can use Origin Access Control (OAC) to restrict access to Amazon S3 Multi-Region Access Points (MRAP), allowing only designated CloudFront distributions to reach MRAP origins. This native integration removes the need for customers to compute and forward SigV4a Authorization headers via custom Lambda@Edge functions. CloudFront now signs requests to S3 MRAP origins, improving cache-miss fill performance from the nearest replicated region and enforcing OAC-secured access. The feature is available globally except in the CloudFront China region and can be enabled via Console, SDK, CLI, or CloudFormation with no additional fees.
