Integration
Streamwake + Amazon CloudFront

Streamwake + Amazon CloudFront.
Don't replace Amazon CloudFront — we correlate its cache-miss, edge-PoP, and origin-shield signals and drive remediation on top.

Don't replace Amazon CloudFront — we correlate the CacheMiss / CacheHit / origin-shield / Lambda@Edge / edge-population signals CloudFront already surfaces, drive remediation on the AWS-native CDN, and explicitly pair AWS MediaLive (the encoder origin) and Amazon CloudFront (the delivery CDN) so a viewer-side cache-miss is never collapsed with an origin-side encoder regression into one symptom.

Amazon CloudFront aws-native global cdn + lambda@edge + origin shield. Streamwake doesn't replace Amazon CloudFront— we correlate its signals and drive remediation on the anomalies it already surfaces.

Where each layer sits

What Amazon CloudFront owns. What Streamwake runs on top.

Honest framing of the surface the vendor owns and the surface Streamwake runs on top of it. Both layers run together in production — same signal bus, different obligations.

What Amazon CloudFront owns

Edge delivery + caching

The global AWS edge PoP mesh, the CacheControl / CachePolicy / OriginRequestPolicy JSON definitions that govern origin-shield tier + cache-key composition, the viewer → edge → regional edge → origin handoff, and the per-edge / per-pop CloudFront metrics (Requests / CacheHitRate / 4xxRate / 5xxRate / OriginLatency) CloudWatch surfaces as first-class signals — owned end to end inside the AWS account.

Lambda@Edge + origin shield + cache invalidations

Lambda@Edge function lifecycle (publish → replicate to edge → pin to viewer-request / origin-request triggers), origin-shield tier assignments, the invalidation API + per-path invalidation lag, the field-level + path-pattern invalidation queues, and the per-edge / per-distribution CloudFront access logs CloudWatch logs group ships as first-class signals.
What Streamwake runs on top

Detect → Classify → Fix

The autonomous loop on top of the CloudFront + AWS MediaLive signal bus — every cache-miss latency overshoot, edge-PoP population gap, regional origin-shield miss, and Lambda@Edge-side fault gets classified, ranked with a typed confidence (cloudfront.<metric_name> → <classification_slug>), and matched to the smallest safe remediation (re-route egress off a brown-out PoP, retune an origin-shield tier, re-issue an invalidation with corrected path-pattern, warm a cold Lambda@Edge replica).

Postmortems

A structured writeup — what happened, what was tried, what changed — lands in Slack, Linear, or PagerDuty the moment the incident closes. CloudFront surfaces the chart; Streamwake closes the loop and writes it up. The MediaLive + CloudFront pair is explicit on the timeline so a chart that started at the origin and a chart that started at the edge never blob into one symptom.
How it works

An incident closed
before your viewers notice.

Four steps from a Amazon CloudFrontanomaly to a closed incident with a typed postmortem. Read top to bottom — the loop is closed end to end.

  1. 1

    Ingest CloudFront + MediaLive signals

    CloudFront per-edge + per-distribution metrics (Requests / CacheHitRate / 4xxRate / 5xxRate / OriginLatency), CloudFront access logs, Lambda@Edge execution traces, invalidation API responses, and the AWS MediaLive channel-state / input-attach / encoder-profile signals (the origin pair) land on the Streamwake signal bus via a single REST POST.

  2. 2

    Correlate and rank across CDN + origin

    The agent joins CloudFront signals against the AWS MediaLive encoder-profile + input-attach signals on the same bus, then ranks root cause with a typed confidence score (viewer_cache_miss_latency vs edge_population_gap vs regional_origin_shield_failure vs cloudfront_vs_origin_classification_drift) — so a viewer-side cache miss is never pinned to an encoder-side regression that started three minutes earlier.

  3. 3

    Recommend or run a fix

    The agent picks the smallest safe remediation — reroute egress off a brown-out PoP, retune an origin-shield cache-key to recover hit-rate, re-issue a field-level invalidation with the corrected path-pattern, warm a cold Lambda@Edge replica, retune the AWS MediaLive encoder profile (only when the classification flags origin-side) — and verifies recovery before closing out.

  4. 4

    Write the postmortem

    A structured incident writeup — what happened (CloudFront-side vs MediaLive-side vs both), what was tried, what changed — lands in the team's inbox the moment the incident resolves. The dual-dashboard distinction survives into the writeup.

What Streamwake catches

Four failure modes Amazon CloudFront alerts alone miss.

Each one is something the Amazon CloudFrontsignal exposes but the agent loop names and acts on — so a chart becomes a closed incident rather than a triage queue.

viewer-cache-miss-latency

Viewer-cache-miss-latency

A CloudFront CacheMiss surges on a specific edge PoP — manifest pulls 200 from the regional edge, but the CacheMiss latency budget (cache_miss_latency_p95_ms) overshoots the player rebuffer threshold, so viewers stall between the regional edge and the origin. CloudFront surfaces the CacheMiss volume; Streamwake catches the latency overshoot on the same bus AND the matching MediaLive encoder-profile drift on the origin side, and routes egress off the affected PoP before the second wave hits.

edge-population-gap

Edge-population-gap

A CloudFront regional edge PoP fails to fully populate when AWS MediaLive cuts over to a new encoder profile — the CacheMiss rate spikes on the affected edge while the rest of the network stays quiet. CloudFront reports the regional skew; Streamwake catches the CloudFront-side CacheMiss skew AND the AWS MediaLive encoder_profile.target_kbps drift the same window (the origin pair) and warms the affected edge with a paired invalidation + a MediaLive side retune so the cutover doesn't strand viewers on a half-populated PoP.

regional-origin-shield-failure

Regional-origin-shield-failure

A regional origin-shield tier miss — the shield PoP that fronts the AWS MediaLive origin goes degraded, so the CacheMiss fallback path now hits the origin directly, doubling request volume and pushing OriginLatency above the player rebuffer threshold. CloudFront surfaces the per-region CacheMiss / OriginLatency skew; Streamwake catches the origin-shield miss on the same bus, retunes the origin-shield tier assignment, and queues a paired invalidation to short-circuit the worst-affected paths.

cloudfront-vs-origin-classification

Cloudfront-vs-origin-classification

A symptom that looks the same from the outside — viewer rebuffer rate spike — that started upstream at the AWS MediaLive encoder (channel-state flip, encoder-profile overshoot, input-attach fault) rather than at the CloudFront edge. CloudFront reports it as a CacheHitRate / 5xxRate dip; Streamwake reads the same bus, joins it against the MediaLive signals, classifies one as cloudfront_side and the other as origin_side with a typed confidence, and never collapses a CloudFront-distinct failure into an origin-side regression. The two dashboards stay distinct through the incident.

See the loop run

Monitor your CloudFront pipeline free.
Next to Amazon CloudFront.

Paste your CloudFront playback URL — /stream-check runs the same five checks (manifest, segments, bitrate ladder, CDN response, playback errors) in under a minute. No login. Pair it with the Book-a-demo block below for a guided walkthrough of the CloudFront-vs-origin classification probe lane alongside your AWS MediaLive encoder profile.

Worked incident

Edge cache-miss latency kept distinct from origin-side encoder drift.

Primetime
Posted to the Incident Library

cloudfront.cache_miss_latency_p95_ms drifted to 2,184 ms vs 812 ms baseline — a 169% overshoot on the iad / cmh regional edge PoPs, paired against AWS MediaLive aws_medialive.encoder_profile.target_kbps drift on the origin side.

The agent classified the viewer-side symptom as cloudfront_edge_cache_miss_latency_vs_origin_classification at 87% confidence— kept distinct from the AWS MediaLive encoder drift it tried not to fold in — emitted a CloudFront-side PoP reroute + origin-shield cache-key retune, and the cache-miss latency cleared within 9 minutes.

Direct mapping to the Streamwake CloudFront-vs-origin classification probe lane — every signal that fired the cache-miss-latency hypothesis on the CloudFront side was the same signal that an AWS MediaLive encoder-profile regression tried to push onto the bus, and the agent split them into two typed classifications rather than collapsing them into one symptom. The dual-dashboard distinction survives into the postmortem.

Read the full postmortem
Talk to engineering

Book a 20-minute walkthrough on your CloudFront distribution.

We're happy to walk through how the viewer-cache-miss-latency, edge-population-gap, regional-origin-shield-failure, and CloudFront-vs-origin-classification probes map onto your existing CloudFront + AWS MediaLive setup. Drop your details below and we'll follow up within 1 business day.