<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>S3 failover &#8211; Blog of Kliment Andreev &#8211; A place so I won&#039;t forget things</title>
	<atom:link href="https://blog.andreev.it/tag/s3-failover/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.andreev.it</link>
	<description></description>
	<lastBuildDate>Mon, 02 Nov 2020 13:56:11 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>AWS: S3 bucket failover using CloudFront and Route 53</title>
		<link>https://blog.andreev.it/2019/12/aws-s3-bucket-failover-using-cloudfront-and-route-53/</link>
					<comments>https://blog.andreev.it/2019/12/aws-s3-bucket-failover-using-cloudfront-and-route-53/#respond</comments>
		
		<dc:creator><![CDATA[Kliment Andreev]]></dc:creator>
		<pubDate>Sun, 29 Dec 2019 16:28:33 +0000</pubDate>
				<category><![CDATA[AWS]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[CloudFront]]></category>
		<category><![CDATA[Route 53]]></category>
		<category><![CDATA[S3 failover]]></category>
		<guid isPermaLink="false">https://blog.andreev.it/?p=6312</guid>

					<description><![CDATA[There are many articles on how to failover a site to S3 bucket or&#8230;]]></description>
										<content:encoded><![CDATA[<div id="bsf_rt_marker"></div><p>There are many articles on how to failover a site to S3 bucket or failover a site to different servers using Route 53 health checks and ELBs, but a failover from an S3 bucket in one region to an S3 bucket in a different region is a little bit more complex. The reason being that if you want to host a site in S3, the bucket name must be the same as the your site. E.g. if you plan to host a site named something.com, your bucket name must be something.com. There are other restrictions. First and foremost, your domain must be hosted in Route 53. Also, the site name that you will use for your bucket can&#8217;t be the APEX domain (e.g. something.com), because Route 53 can&#8217;t create a CNAME for the apex domain. On top of that, there were some recent <a href="https://aws.amazon.com/about-aws/whats-new/2019/04/amazon-cloudfront-enhances-the-security-for-adding-alternate-domain-names-to-a-distribution/" rel="noopener noreferrer" target="_blank">changes </a>in CloudFront so if you want to host a site in S3 behind a CloudFront distribution using an alternate domain name, you must have a valid SSL certificate.<br />
This is my scenario. I have a site called <strong>bucket.nanocloud.org</strong> that serves static content in the east region. I&#8217;ll create another bucket in the west region and I&#8217;ll use the cross region replication, so the bucket content is exactly the same. Then, I&#8217;ll use CloudFront to be on top of my original bucket (I&#8217;ll need a valid SSL certificate for this). The backup bucket in west region won&#8217;t be behind a CloudFront distribution, but I&#8217;ll still be able to fail over using the Route 53 failover health checks.<br />
Again, make sure you host your domain in Route 53, have a valid certificate for your domain, the domain that you&#8217;ll host can&#8217;t be the apex domain (e.g. no something.com, it has to be anything.something.com) and hopefully you can create the bucket with your domain name (e.g. if I create a bucket called www.yourdomain.com, you won&#8217;t be able to create the failover because the S3 buckets are unique).<br />
And this is how that looks like step-by-step.</p>
<h1>S3 buckets</h1>
<p>Go to S3 console and create a bucket. I&#8217;ll name mine <strong>bucket.nanocloud.org-primary</strong>. Don&#8217;t use the original domain, you&#8217;ll see later why. As a matter of fact, you can name this bucket whatever you want, it will be behind a CloudFront distribution. Choose a region and click <strong>Next</strong>. Make sure you check the <strong>Versioning</strong>, it is required for bucket replication.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-01.png"><img decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-01.png" alt="" width="466" height="85" class="aligncenter size-full wp-image-6320" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-01.png 466w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-01-300x55.png 300w" sizes="(max-width: 466px) 100vw, 466px" /></a><br />
On the next screen, uncheck <strong>Block all public access</strong> and click <strong>Next</strong> and then proceed to create the bucket.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-02.png"><img decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-02.png" alt="" width="271" height="81" class="aligncenter size-full wp-image-6323" /></a><br />
Select the bucket, click on the <strong>Properties </strong>tab and click on <strong>Static website hosting</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-03.png"><img fetchpriority="high" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-03.png" alt="" width="330" height="273" class="aligncenter size-full wp-image-6324" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-03.png 330w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-03-300x248.png 300w" sizes="(max-width: 330px) 100vw, 330px" /></a><br />
Click on <strong>Use this bucket to host a website</strong> and under <strong>Index document</strong> type <strong>index.html</strong>. Before you click <strong>Save</strong> copy the endpoint URL, in my case it is <strong>http://bucket.nanocloud.org-primary.s3-website-us-east-1.amazonaws.com</strong>. Copy this URL in notepad or somewhere.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-04.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-04.png" alt="" width="538" height="644" class="aligncenter size-full wp-image-6326" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-04.png 538w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-04-251x300.png 251w" sizes="(max-width: 538px) 100vw, 538px" /></a><br />
Click on <strong>Permissions </strong>tab and then <strong>Bucket Policy</strong> button.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-05.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-05.png" alt="" width="527" height="217" class="aligncenter size-full wp-image-6327" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-05.png 527w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-05-300x124.png 300w" sizes="(max-width: 527px) 100vw, 527px" /></a><br />
Paste the following JSON file. Make sure you replace your bucket name in line 12.</p>
<pre class="brush: xml; highlight: [12]; title: ; notranslate">
{
    &quot;Version&quot;: &quot;2012-10-17&quot;,
    &quot;Statement&quot;: &#x5B;
        {
            &quot;Sid&quot;: &quot;PublicReadGetObject&quot;,
            &quot;Effect&quot;: &quot;Allow&quot;,
            &quot;Principal&quot;: &quot;*&quot;,
            &quot;Action&quot;: &#x5B;
                &quot;s3:GetObject&quot;
            ],
            &quot;Resource&quot;: &#x5B;
                &quot;arn:aws:s3:::bucket.nanocloud.org-primary/*&quot;
            ]
        }
    ]
}
</pre>
<p>Click <strong>Save </strong>and AWS will warn you that you have a public access to this bucket. It&#8217;s OK.<br />
Now from the <strong>Overview </strong>tab, <strong>Upload </strong>an <strong>index.html</strong> file like this. Please follow up the tutorial as it will be easier to troubleshoot later. You can dump your files once everything checks out. Just accept the defaults for the upload.</p>
<pre class="brush: xml; highlight: [3]; title: ; notranslate">
&lt;html&gt;
	&lt;head&gt;
		&lt;title&gt;Region 1&lt;/title&gt;
	&lt;/head&gt;
	&lt;body&gt;
		&lt;p&gt;Current time is : &lt;span id=&quot;datetime&quot;&gt;&lt;/span&gt;&lt;/p&gt;
	&lt;/body&gt;
	&lt;script&gt;
		var dt = new Date();
		document.getElementById(&quot;datetime&quot;).innerHTML = dt.toLocaleTimeString();
	&lt;/script&gt;
&lt;/html&gt;
</pre>
<p>OK, now that we have everything in place, test the URL from the endpoint above. You wrote it down, didn&#8217;t you?<br />
You should get something like this. The title of the tab says Region 1 and it prints the current time from your computer. The reason I am using JavaScript is that you can test the failover later. If the failover doesn&#8217;t work, make sure you get the current time and not a cached page because you are behind a bad proxy.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-06.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-06.png" alt="" width="577" height="150" class="aligncenter size-full wp-image-6334" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-06.png 577w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-06-300x78.png 300w" sizes="(max-width: 577px) 100vw, 577px" /></a><br />
If everything checks out, proceed with the creation of the second bucket. You have to take the same steps, but this time make sure the bucket&#8217;s name is your domain name, in my case <strong>bucket.nanocloud.org</strong>. It should be exactly as your domain name but in a different region. Also, you have to modify the same properties, enable <strong>Versioning</strong>, uncheck <strong>Block all public access</strong>, enable <strong>Static website hosting</strong>, get the endpoint URL, paste it in notepad, add a <strong>Bucket Policy </strong>but remember to change line 12 so it says <strong>bucket.nanocloud.org</strong> or whatever your domain is. Also, upload a slightly modified <strong>index.html</strong> file. Just change line 3 to say Region 2. If you done all these steps, go to the endpoint URL and you&#8217;ll see your current time but with a different title.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-10.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-10.png" alt="" width="529" height="134" class="aligncenter size-full wp-image-6342" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-10.png 529w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-10-300x76.png 300w" sizes="(max-width: 529px) 100vw, 529px" /></a></p>
<h1>SSL certificate</h1>
<p>Go to <strong>Certificate Manager</strong> console and here you can either buy a cert from AWS or if you like something cheaper, go to any cheap cert sites and get your certificate. In my case, I imported a certificate that I&#8217;ve purchased from one of the cheap SSL resellers. It doesn&#8217;t matter, just import a certificate so it looks similar to this. A valid certificate in AWS certificate manager.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-08.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-08.png" alt="" width="1373" height="362" class="aligncenter size-full wp-image-6338" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-08.png 1373w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-08-300x79.png 300w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-08-1024x270.png 1024w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-08-768x202.png 768w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-08-1170x308.png 1170w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-08-585x154.png 585w" sizes="(max-width: 1373px) 100vw, 1373px" /></a></p>
<h1>CloudFront distribution</h1>
<p>Go to the <strong>CloudFront </strong>console and click on <strong>Create Distribution</strong>. Choose the first one that says <strong>Web</strong>, click <strong>Get Started</strong>. Once you click on the first field, <strong>Origin Domain Name</strong>, AWS will give you an option to choose the bucket name. <strong>STOP!!!</strong><br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-07.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-07.png" alt="" width="607" height="178" class="aligncenter size-full wp-image-6337" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-07.png 607w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-07-300x88.png 300w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-07-585x172.png 585w" sizes="(max-width: 607px) 100vw, 607px" /></a><br />
Ignore what AWS offers, that&#8217;s for RTMP. Instead paste the URL for your original bucket but remove <strong>http://</strong>, so this is what you should paste (in my case) &#8211; <strong>bucket.nanocloud.org-primary.s3-website-us-east-1.amazonaws.com</strong>. Scroll down and ignore until you reach <strong>Compress Objects Automatically</strong>. Select <strong>Yes</strong>, but it&#8217;s optional. It&#8217;s pretty much <strong>mod_gzip</strong>, it compresses the content on the server level, but it&#8217;s not beneficial if you serve a lot of JPG/PNG images. It&#8217;s up to you. Also, you can change the <strong>Price Class</strong> if you don&#8217;t want to pay the full price.  Strictly optional, this is just for demo purposes only.<br />
What&#8217;s important is the field where it says <strong>Alternate Domain Names (CNAMEs)</strong>.<br />
Enter your domain here in my case <strong>bucket.nanocloud.org</strong>, then click on <strong>Custom SSL Certificate</strong> and select the cert that you just imported/requested from AWS.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-09.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-09.png" alt="" width="689" height="426" class="aligncenter size-full wp-image-6340" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-09.png 689w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-09-300x185.png 300w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-09-585x362.png 585w" sizes="(max-width: 689px) 100vw, 689px" /></a><br />
Scroll all the way down and click <strong>Create Distribution</strong>. Once the CF distribution is created click on it and from the <strong>General </strong>tab look for <strong>Domain Name</strong>. Copy this value as you will need it now.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-11.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-11.png" alt="" width="829" height="299" class="aligncenter size-full wp-image-6348" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-11.png 829w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-11-300x108.png 300w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-11-768x277.png 768w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-11-585x211.png 585w" sizes="(max-width: 829px) 100vw, 829px" /></a></p>
<h1>Route 53</h1>
<p>Go to Route 53 console and create a CNAME record for your domain. In my case, I am creating a CNAME record for <strong>bucket.nanocloud.org</strong>. This is how it looks like.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-12.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-12.png" alt="" width="910" height="523" class="aligncenter size-full wp-image-6349" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-12.png 910w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-12-300x172.png 300w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-12-768x441.png 768w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-12-585x336.png 585w" sizes="(max-width: 910px) 100vw, 910px" /></a><br />
Try to access <strong>bucket.nanocloud.org</strong> or <strong>whatever.domain.youhave</strong>. You should get the current time and Region 1 as a title in the browser. If everything is OK, let&#8217;s proceed to the health checks.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-15.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-15.png" alt="" width="460" height="154" class="aligncenter size-full wp-image-6353" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-15.png 460w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-15-300x100.png 300w" sizes="(max-width: 460px) 100vw, 460px" /></a><br />
Just below the <strong>Hosted zones</strong> on the right side, click on <strong>Health checks</strong>. Click on <strong>Create health check</strong>. Enter some description for the <strong>Name </strong>field and under <strong>Specify endpoint by</strong> click on <strong>Domain name</strong>, HTTP for <strong>Protocol </strong>and paste the S3 domain name for the primary bucket. Remove http://, just the endpoint URL, in my case <strong>bucket.nanocloud.org-primary.s3-website-us-east-1.amazonaws.com</strong>. Under <strong>Advanced configuration</strong> you can change the <strong>Request interval</strong> from 30 to 10 seconds, but I wouldn&#8217;t recommend that. You&#8217;ll get bombarded with health checks every second. Just leave it as-is, but you&#8217;ll have to wait about 1 min 30 seconds for the failover.<br />
This is how my config looks like.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-13.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-13.png" alt="" width="908" height="826" class="aligncenter size-full wp-image-6350" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-13.png 908w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-13-300x273.png 300w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-13-768x699.png 768w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-13-585x532.png 585w" sizes="(max-width: 908px) 100vw, 908px" /></a><br />
On the next screen, you can create an SNS notification so you&#8217;ll get alerted when a failover occurs. I strongly recommend this in production environment, but I&#8217;ll skip it so we can focus on the actual failover. Your health-check will look like this. Wait for about 30 seconds and the status will change to healthy.<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-14.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-14.png" alt="" width="866" height="80" class="aligncenter size-full wp-image-6351" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-14.png 866w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-14-300x28.png 300w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-14-768x71.png 768w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-14-585x54.png 585w" sizes="(max-width: 866px) 100vw, 866px" /></a><br />
Then create another health check. Name this health-check <strong>bucket.nanocloud.org-backup</strong> or however you like and for the domain name enter the S3 bucket name in the west region, in my case it&#8217;s <strong>bucket.nanocloud.org.s3-website-us-west-2.amazonaws.com</strong>. You can add an alarm as well if you want. So, the only difference between the checkups are the names (of course) and the domain names. Both should be in healthy state.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-20.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-20.png" alt="" width="1306" height="125" class="aligncenter size-full wp-image-6364" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-20.png 1306w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-20-300x29.png 300w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-20-1024x98.png 1024w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-20-768x74.png 768w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-20-1170x112.png 1170w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-20-585x56.png 585w" sizes="(max-width: 1306px) 100vw, 1306px" /></a><br />
Go back to the <strong>Hosted zones</strong> and select the CNAME record that you&#8217;ve just created. Change the <strong>TTL (Seconds)</strong> to 60 so you have a faster failover, then <strong>Routing Policy</strong> to <strong>Failover</strong>, <strong>Failover Record Type</strong> should be <strong>Primary </strong>and click <strong>Yes </strong>under <strong>Associate with Health Check</strong>. Then select <strong>bucket.nanocloud.org</strong> or whatever you named your health-check under <strong>Health Check to Associate</strong>. Looks like this.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-16.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-16.png" alt="" width="403" height="807" class="aligncenter size-full wp-image-6355" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-16.png 403w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-16-150x300.png 150w" sizes="(max-width: 403px) 100vw, 403px" /></a><br />
Click on <strong>Save Record Set</strong> once done.<br />
Now, click on <strong>Create Record Set</strong> button again. This time we are creating the backup record. Use the same name under <strong>Name</strong>, <strong>Type </strong>is CNAME, <strong>TTL (Seconds)</strong> is again 60, <strong>Routing Policy</strong> is <strong>Failover</strong>, but this time the <strong>Failover Record Type</strong> is <strong>Secondary</strong>. Associate the backup health check, not the primary one.<br />
Looks like this.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-17.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-17.png" alt="" width="402" height="638" class="aligncenter size-full wp-image-6366" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-17.png 402w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-17-189x300.png 189w" sizes="(max-width: 402px) 100vw, 402px" /></a><br />
This is how your DNS should look like for these two records.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-18.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-18.png" alt="" width="1069" height="91" class="aligncenter size-full wp-image-6359" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-18.png 1069w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-18-300x26.png 300w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-18-1024x87.png 1024w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-18-768x65.png 768w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-18-585x50.png 585w" sizes="(max-width: 1069px) 100vw, 1069px" /></a><br />
OK, you are good. Let&#8217;s test the failover. The easiest way to test it is to disable the <strong>Static website hosting</strong> in S3. For the primary bucket, disable it.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-019.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-019.png" alt="" width="668" height="420" class="aligncenter size-full wp-image-6362" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-019.png 668w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-019-300x189.png 300w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-019-585x368.png 585w" sizes="(max-width: 668px) 100vw, 668px" /></a><br />
If you try to access the original S3 URL, you&#8217;ll get error 404. The bucket is down hard. But, if you go to your web site <strong>bucket.nanocloud.org</strong>, the site will be up. CloudFront will serve cached content. Once the health check is marked as unhealthy after 90 seconds, the DNS will failover. The easiest way is to go to your command prompt, do a couple of <strong>ipconfig /flushdns</strong> and <strong>nslookup bucket.nanoclod.org</strong> queries. You&#8217;ll see how the DNS will change. From the CloudFront URL to S3 west URL. At this point, your secondary bucket will serve the content. The only thing left is to make sure that the bucket content is exactly the same. We can use the Cross-Region Replication for this.</p>
<h1>S3 Cross-Region Replication</h1>
<p>Go to your first primary bucket in the console and select the bucket. Click on the <strong>Management </strong>tab, then the <strong>Replication </strong>button and <strong>Add rule</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-21.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-21.png" alt="" width="591" height="248" class="aligncenter size-full wp-image-6368" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-21.png 591w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-21-300x126.png 300w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-21-585x245.png 585w" sizes="(max-width: 591px) 100vw, 591px" /></a><br />
On the first screen (<strong>1 Set Source</strong>) click<strong> Entire bucket</strong> and then <strong>Next</strong>. Select the bucket in the west region. The backup bucket. Leave the other options as-is.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-22.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-22.png" alt="" width="645" height="271" class="aligncenter size-full wp-image-6369" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-22.png 645w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-22-300x126.png 300w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-22-585x246.png 585w" sizes="(max-width: 645px) 100vw, 645px" /></a><br />
Create and name a new role and let AWS take care of the policy. Review and click <strong>Save</strong>.<br />
<a href="https://blog.andreev.it/wp-content/uploads/2019/12/P141-23.png"><img loading="lazy" decoding="async" src="https://blog.andreev.it/wp-content/uploads/2019/12/P141-23.png" alt="" width="703" height="502" class="aligncenter size-full wp-image-6370" srcset="https://blog.andreev.it/wp-content/uploads/2019/12/P141-23.png 703w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-23-300x214.png 300w, https://blog.andreev.it/wp-content/uploads/2019/12/P141-23-585x418.png 585w" sizes="(max-width: 703px) 100vw, 703px" /></a><br />
If you try to access the second bucket, you&#8217;ll see that it still shows a different page than the first one. That&#8217;s because the replication works for the files that were added after it was created. If you want to sync the files before the replication was created, you&#8217;ll have to copy them manually using AWS CLI (<strong>aws s3 sync s3://source s3://destination</strong>).</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.andreev.it/2019/12/aws-s3-bucket-failover-using-cloudfront-and-route-53/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
