October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk8 min

My AWS Learning Journey: CloudWatch, Lambda, IAM & CloudFront

A hands-on AWS learning path that connects Lambda, CloudWatch Logs, IAM execution roles and CloudFront with an S3 origin, plus cleanup and billing checks.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Four AWS services form one learning chain. A Lambda function runs your code and writes its output to CloudWatch Logs. The function’s IAM execution role decides what it is allowed to do. CloudFront can serve a private S3 bucket to the public through origin access control (OAC), and CloudFront publishes its operational metrics back to CloudWatch. Working through these pieces in order, with small exercises you can inspect, shows how they connect without requiring any prior AWS background.

The learning order at a glance

The sequence below follows the order AWS’s own beginner material builds concepts. Each step depends on the one before it, so skip ahead only if you already understand the earlier concept.

Step Service What you should see when it works Cost note
1. Create and invoke a function Lambda A test run returns the result you defined Review current Lambda pricing before you run it repeatedly
2. Inspect the logs CloudWatch Logs A log group named after the function contains one entry per invocation Log storage can accumulate; delete the log group during cleanup
3. Read the execution role IAM A role whose permissions cover writing to CloudWatch Logs and nothing else IAM itself has no charge
4. Serve an S3 origin through CloudFront S3, CloudFront The distribution’s domain name returns your private file, and direct S3 URLs are refused Storage, requests and data transfer are billed; check the pricing pages for your Region and usage
5. Inspect CloudFront metrics CloudWatch Request and error metrics appear for the distribution after traffic reaches it Default CloudFront metrics incur no additional cost; additional metrics can cost extra
6. Remove tutorial resources All Nothing remains in the console for the exercise Check the Billing and Cost Management console afterward

Step 1: Create and invoke a Lambda function

AWS’s “Create your first Lambda function” tutorial uses the Lambda console and accepts Python or Node.js for its simple interpreted-language workflow. It teaches three things: the event object that carries input into the function, returning a result from the function, and viewing invocation output in CloudWatch Logs. Runtime versions change over time, so select the newest offered runtime in the console rather than copying a version number from an older guide.

  1. Sign in to the AWS Management Console as an IAM user or through IAM Identity Center, not as the root user, and open the Lambda console.
  2. Choose Create function, keep Author from scratch selected, and enter a function name.
  3. Select a Python or Node.js runtime, then choose Create function. Accept the default execution role for now; Step 3 explains it.
  4. In the code editor, write a handler that reads a value from the event object and returns a short message that includes it.
  5. Choose Deploy, then open the Test tab, create a test event with a sample key and value, and choose Test.

A successful run shows the returned value and a status of succeeded. If the run fails, the error message in the execution results usually points to the line that caused it, so fix the code and test again before moving on.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Step 2: See how Lambda sends logs to CloudWatch

Lambda does not need you to configure logging for a basic function. Each invocation writes its output to a log stream inside a log group named /aws/lambda/ followed by your function name. The function’s Monitor tab links to those logs, and you can also open CloudWatch directly and choose Logs then Log groups.

  • Run the test two or three times with different event values so you see several log streams or entries.
  • Open a log stream and compare the lines to the event you passed in. Anything your handler prints appears there.
  • Notice that the log group exists even when you have not written any logging code of your own. The write permission that makes this possible comes from the execution role.

Step 3: Understand the IAM execution role

An execution role is an IAM role that grants a Lambda function permission to access AWS services and resources. AWS creates one when you create a function in the console. For a first function, the generated role includes basic permission to write to CloudWatch Logs, which is why Step 2 worked without extra setup.

It helps to separate two identities that are easy to confuse:

Identity Who or what uses it What it controls
Root user The account owner, for account-level tasks only Full account control; AWS advises against using it for everyday work
IAM user or Identity Center user You, when you sign in to the console or run the CLI Whether you can open the Lambda console, create functions, or read logs
Execution role The Lambda function while it runs Which other AWS services the function’s code can call

Your sign-in permissions and the function’s runtime permissions are independent. Adding a permission to your user does not give the function that permission, and the reverse is also true. When you later add a line that reads from S3 or writes to DynamoDB, add that permission to the execution role itself, scoped to the specific resource, instead of attaching broad managed policies. A role limited to one bucket or one table keeps a mistake in one function from reaching the rest of the account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Step 4: Put CloudFront in front of an S3 bucket

AWS’s “Get started with CloudFront” material includes a basic distribution that uses origin access control to send authenticated requests from CloudFront to an S3 origin. The point of this exercise is that the bucket can stay private: viewers reach the content only through CloudFront.

  1. In the S3 console, create a bucket with a globally unique name. Leave Block all public access turned on.
  2. Upload a simple index.html file to the bucket root.
  3. Open the CloudFront console and choose Create distribution. Select the S3 bucket as the origin.
  4. In the origin settings, choose the option to create a new origin access control, and keep its default signing behavior unless you have a reason to change it.
  5. After the distribution is created, CloudFront displays a bucket policy you must copy. Apply it in the S3 bucket’s Permissions tab under Bucket policy. Without it, CloudFront cannot read the object.
  6. Open the distribution’s domain name in a browser. You should see your page. Then open the S3 object URL directly; it should be refused, which confirms the bucket is not public.

Distributions take several minutes to deploy. If the domain name returns an access-denied error, the most common cause is a bucket policy that was not saved or was copied from an older distribution.

AWS also offers a secure static website tutorial and a CLI path for the same kind of setup. The console path shows each setting, and the CLI path makes the same settings visible as commands, which is useful once you want to repeat the setup.

Step 5: Inspect CloudFront metrics in CloudWatch

Yes, CloudWatch can monitor CloudFront. CloudFront publishes operational metrics for distributions and edge functions to CloudWatch automatically. Open the CloudWatch console, choose Metrics, and look for the CloudFront namespace, then filter by your distribution ID. Load your page several times and refresh the graphs to see request activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AWS’s monitoring guide draws a line between two kinds of metrics:

Metric type Cost treatment stated by AWS Practical meaning for a learner
Default CloudFront metrics Do not count against CloudWatch quotas and incur no additional cost Enough to see requests and error rates for this exercise
Additional metrics Can be enabled and incur an additional cost Finer detail; enable them only after you know what you need

The statement about default metrics covers CloudWatch metric charges for CloudFront only. Your distribution still generates request and data-transfer charges, and the Lambda and S3 resources from earlier steps may bill separately.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When to consider Lambda@Edge

Lambda@Edge runs Lambda functions at CloudFront edge locations, so it can change requests or responses close to viewers. It is a later extension, not a prerequisite for anything above. AWS’s Lambda@Edge console guide sets requirements that make it more advanced than the first function:

  • Create the function in the US East (N. Virginia) Region, regardless of where your viewers are.
  • Publish a numbered version of the function. The edge trigger uses the version, not the unpublished code.
  • Associate the version with a CloudFront distribution and a cache behavior, and choose the request or response event that triggers it.
  • Expect Lambda to create replicas in AWS locations around the world when the trigger is created, which makes the deployment heavier than a console test.

Add Lambda@Edge only when you need logic such as header changes, redirects, or request routing that must happen at the edge. A static site served from S3 does not need it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Clean up and check billing

AWS’s first-function tutorial explicitly says to delete the function, its log group, and its execution role after the exercise. The other resources need their own cleanup. Use this order so nothing is blocked by a dependency:

  1. In the CloudFront console, select the distribution, choose Disable, and wait for the status to finish updating. Then delete it. CloudFront will not delete an enabled distribution.
  2. In the S3 console, empty the bucket, then delete it.
  3. In the Lambda console, delete the function.
  4. In the CloudWatch console, delete the log group /aws/lambda/ plus your function name.
  5. In the IAM console, delete the execution role that Lambda generated, which is named with the function name as a prefix.
  6. Open the Billing and Cost Management console and review the current month’s charges by service. Confirm that CloudFront, S3, Lambda and CloudWatch show no unexpected usage.

Deleting a function does not remove its log group in every case, so check the CloudWatch log groups list after deleting the function. Keeping the exercise resources small and removing them when you finish is the simplest way to keep the learning path inexpensive.

Choosing between the console and the CLI

Both routes exist for CloudFront, and the Lambda tutorial is console-first. The choice depends on your goal rather than on which route is better:

Route Setup friction How much configuration you see Best fit
Console Lowest; no local tools needed Each setting appears on a labelled screen First pass through each service
CLI Higher; requires installed tools and configured credentials Every setting is written out as a command you can repeat Repeating or scripting the setup after you understand it

AWS’s material establishes that both paths exist for CloudFront. It does not rank them, so pick the one that matches how much you want to see at each step.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Once these six steps are familiar, the next useful question is how to observe your own code in production. The same logs, metrics and role concepts carry over, and they become the foundation for alarms and dashboards.

In practice, the pieces make the most sense when you can trace one request through them. A viewer requests a page, CloudFront fetches the object from S3 using its authorized origin access control, the distribution records the request as a metric in CloudWatch, and a Lambda function you invoke separately writes its own entries to a log group using its execution role. Each service has its own permissions and its own bill, which is why the cleanup list above names every one of them.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.