Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Four AWS services form one learning chain. A Lambda function runs your code and writes its output to CloudWatch Logs. The function’s IAM execution role decides what it is allowed to do. CloudFront can serve a private S3 bucket to the public through origin access control (OAC), and CloudFront publishes its operational metrics back to CloudWatch. Working through these pieces in order, with small exercises you can inspect, shows how they connect without requiring any prior AWS background.
The learning order at a glance
The sequence below follows the order AWS’s own beginner material builds concepts. Each step depends on the one before it, so skip ahead only if you already understand the earlier concept.
| Step | Service | What you should see when it works | Cost note |
|---|---|---|---|
| 1. Create and invoke a function | Lambda | A test run returns the result you defined | Review current Lambda pricing before you run it repeatedly |
| 2. Inspect the logs | CloudWatch Logs | A log group named after the function contains one entry per invocation | Log storage can accumulate; delete the log group during cleanup |
| 3. Read the execution role | IAM | A role whose permissions cover writing to CloudWatch Logs and nothing else | IAM itself has no charge |
| 4. Serve an S3 origin through CloudFront | S3, CloudFront | The distribution’s domain name returns your private file, and direct S3 URLs are refused | Storage, requests and data transfer are billed; check the pricing pages for your Region and usage |
| 5. Inspect CloudFront metrics | CloudWatch | Request and error metrics appear for the distribution after traffic reaches it | Default CloudFront metrics incur no additional cost; additional metrics can cost extra |
| 6. Remove tutorial resources | All | Nothing remains in the console for the exercise | Check the Billing and Cost Management console afterward |
Step 1: Create and invoke a Lambda function
AWS’s “Create your first Lambda function” tutorial uses the Lambda console and accepts Python or Node.js for its simple interpreted-language workflow. It teaches three things: the event object that carries input into the function, returning a result from the function, and viewing invocation output in CloudWatch Logs. Runtime versions change over time, so select the newest offered runtime in the console rather than copying a version number from an older guide.
- Sign in to the AWS Management Console as an IAM user or through IAM Identity Center, not as the root user, and open the Lambda console.
- Choose Create function, keep Author from scratch selected, and enter a function name.
- Select a Python or Node.js runtime, then choose Create function. Accept the default execution role for now; Step 3 explains it.
- In the code editor, write a handler that reads a value from the event object and returns a short message that includes it.
- Choose Deploy, then open the Test tab, create a test event with a sample key and value, and choose Test.
A successful run shows the returned value and a status of succeeded. If the run fails, the error message in the execution results usually points to the line that caused it, so fix the code and test again before moving on.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
Step 2: See how Lambda sends logs to CloudWatch
Lambda does not need you to configure logging for a basic function. Each invocation writes its output to a log stream inside a log group named /aws/lambda/ followed by your function name. The function’s Monitor tab links to those logs, and you can also open CloudWatch directly and choose Logs then Log groups.
- Run the test two or three times with different event values so you see several log streams or entries.
- Open a log stream and compare the lines to the event you passed in. Anything your handler prints appears there.
- Notice that the log group exists even when you have not written any logging code of your own. The write permission that makes this possible comes from the execution role.
Step 3: Understand the IAM execution role
An execution role is an IAM role that grants a Lambda function permission to access AWS services and resources. AWS creates one when you create a function in the console. For a first function, the generated role includes basic permission to write to CloudWatch Logs, which is why Step 2 worked without extra setup.
It helps to separate two identities that are easy to confuse:
Rank #2
| Identity | Who or what uses it | What it controls |
|---|---|---|
| Root user | The account owner, for account-level tasks only | Full account control; AWS advises against using it for everyday work |
| IAM user or Identity Center user | You, when you sign in to the console or run the CLI | Whether you can open the Lambda console, create functions, or read logs |
| Execution role | The Lambda function while it runs | Which other AWS services the function’s code can call |
Your sign-in permissions and the function’s runtime permissions are independent. Adding a permission to your user does not give the function that permission, and the reverse is also true. When you later add a line that reads from S3 or writes to DynamoDB, add that permission to the execution role itself, scoped to the specific resource, instead of attaching broad managed policies. A role limited to one bucket or one table keeps a mistake in one function from reaching the rest of the account.
Step 4: Put CloudFront in front of an S3 bucket
AWS’s “Get started with CloudFront” material includes a basic distribution that uses origin access control to send authenticated requests from CloudFront to an S3 origin. The point of this exercise is that the bucket can stay private: viewers reach the content only through CloudFront.
- In the S3 console, create a bucket with a globally unique name. Leave Block all public access turned on.
- Upload a simple
index.htmlfile to the bucket root. - Open the CloudFront console and choose Create distribution. Select the S3 bucket as the origin.
- In the origin settings, choose the option to create a new origin access control, and keep its default signing behavior unless you have a reason to change it.
- After the distribution is created, CloudFront displays a bucket policy you must copy. Apply it in the S3 bucket’s Permissions tab under Bucket policy. Without it, CloudFront cannot read the object.
- Open the distribution’s domain name in a browser. You should see your page. Then open the S3 object URL directly; it should be refused, which confirms the bucket is not public.
Distributions take several minutes to deploy. If the domain name returns an access-denied error, the most common cause is a bucket policy that was not saved or was copied from an older distribution.
Rank #3
AWS also offers a secure static website tutorial and a CLI path for the same kind of setup. The console path shows each setting, and the CLI path makes the same settings visible as commands, which is useful once you want to repeat the setup.
Step 5: Inspect CloudFront metrics in CloudWatch
Yes, CloudWatch can monitor CloudFront. CloudFront publishes operational metrics for distributions and edge functions to CloudWatch automatically. Open the CloudWatch console, choose Metrics, and look for the CloudFront namespace, then filter by your distribution ID. Load your page several times and refresh the graphs to see request activity.
Recommended Free Tools
AWS’s monitoring guide draws a line between two kinds of metrics:
| Metric type | Cost treatment stated by AWS | Practical meaning for a learner |
|---|---|---|
| Default CloudFront metrics | Do not count against CloudWatch quotas and incur no additional cost | Enough to see requests and error rates for this exercise |
| Additional metrics | Can be enabled and incur an additional cost | Finer detail; enable them only after you know what you need |
The statement about default metrics covers CloudWatch metric charges for CloudFront only. Your distribution still generates request and data-transfer charges, and the Lambda and S3 resources from earlier steps may bill separately.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.When to consider Lambda@Edge
Lambda@Edge runs Lambda functions at CloudFront edge locations, so it can change requests or responses close to viewers. It is a later extension, not a prerequisite for anything above. AWS’s Lambda@Edge console guide sets requirements that make it more advanced than the first function:
- Create the function in the US East (N. Virginia) Region, regardless of where your viewers are.
- Publish a numbered version of the function. The edge trigger uses the version, not the unpublished code.
- Associate the version with a CloudFront distribution and a cache behavior, and choose the request or response event that triggers it.
- Expect Lambda to create replicas in AWS locations around the world when the trigger is created, which makes the deployment heavier than a console test.
Add Lambda@Edge only when you need logic such as header changes, redirects, or request routing that must happen at the edge. A static site served from S3 does not need it.
Best Value
Clean up and check billing
AWS’s first-function tutorial explicitly says to delete the function, its log group, and its execution role after the exercise. The other resources need their own cleanup. Use this order so nothing is blocked by a dependency:
- In the CloudFront console, select the distribution, choose Disable, and wait for the status to finish updating. Then delete it. CloudFront will not delete an enabled distribution.
- In the S3 console, empty the bucket, then delete it.
- In the Lambda console, delete the function.
- In the CloudWatch console, delete the log group
/aws/lambda/plus your function name. - In the IAM console, delete the execution role that Lambda generated, which is named with the function name as a prefix.
- Open the Billing and Cost Management console and review the current month’s charges by service. Confirm that CloudFront, S3, Lambda and CloudWatch show no unexpected usage.
Deleting a function does not remove its log group in every case, so check the CloudWatch log groups list after deleting the function. Keeping the exercise resources small and removing them when you finish is the simplest way to keep the learning path inexpensive.
Choosing between the console and the CLI
Both routes exist for CloudFront, and the Lambda tutorial is console-first. The choice depends on your goal rather than on which route is better:
| Route | Setup friction | How much configuration you see | Best fit |
|---|---|---|---|
| Console | Lowest; no local tools needed | Each setting appears on a labelled screen | First pass through each service |
| CLI | Higher; requires installed tools and configured credentials | Every setting is written out as a command you can repeat | Repeating or scripting the setup after you understand it |
AWS’s material establishes that both paths exist for CloudFront. It does not rank them, so pick the one that matches how much you want to see at each step.
Free tools Windows power users keep installed
One-click scans. No signup required.
Once these six steps are familiar, the next useful question is how to observe your own code in production. The same logs, metrics and role concepts carry over, and they become the foundation for alarms and dashboards.
In practice, the pieces make the most sense when you can trace one request through them. A viewer requests a page, CloudFront fetches the object from S3 using its authorized origin access control, the distribution records the request as a metric in CloudWatch, and a Lambda function you invoke separately writes its own entries to a log group using its execution role. Each service has its own permissions and its own bill, which is why the cleanup list above names every one of them.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




