Skip to main content
rightsizing · aws

CloudFront distributions whose cache hit rate averages below 80% over 30 days

rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight reads the CloudFront `CacheHitRate` metric and flags distributions averaging below 80% over 30 days. The saving it would report is the measured cache-miss origin traffic priced at the per-GB rate, and because that byte count is not collected yet, ZopNight currently raises no finding rather than estimate a share of the bill.

Signal and threshold

How ZopNight evaluates CloudFront distributions whose cache hit rate averages below 80% over 30 days.
Field Value
Rule IDsRC-1511
Categoryrightsizing
Severitylow
MetricCacheHitRate
Threshold< 80% average
Evaluation window30d
SourceZopNight
Permissions usedcloudfront:ListDistributions · cloudfront:GetMonitoringSubscription · cloudwatch:GetMetricStatistics

Every cache miss is a trip back to your origin

CloudFront defines the cache hit rate as the share of cacheable requests served from its own cache; POST and PUT requests and errors do not count as cacheable. Each miss makes CloudFront fetch the object from the origin, which adds origin load, latency for the viewer, and for origins outside AWS the egress your host bills you for.

AWS lists the usual causes on its cache hit ratio page: short cache durations, cache keys that include query strings, cookies or headers that vary per request, and no Origin Shield layer in front of the origin. The shorter the max-age, the more often CloudFront has to go back to check or refetch the object.

Turning on and reading CacheHitRate

CacheHitRate is one of the additional distribution metrics, which cost extra and are off until you enable them per distribution. CloudWatch charges a fixed monthly rate for each of the up to 8 extra metrics. CloudFront metrics are only returned from us-east-1, with the Region dimension set to Global:

Terminal window
aws cloudfront get-monitoring-subscription --distribution-id EDFDVBD6EXAMPLE
aws cloudfront create-monitoring-subscription --distribution-id EDFDVBD6EXAMPLE \
--monitoring-subscription RealtimeMetricsSubscriptionConfig={RealtimeMetricsSubscriptionStatus=Enabled}
aws cloudwatch get-metric-statistics --region us-east-1 --namespace AWS/CloudFront \
--metric-name CacheHitRate \
--dimensions Name=DistributionId,Value=EDFDVBD6EXAMPLE Name=Region,Value=Global \
--statistics Average --period 86400 \
--start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z

What ZopNight checks on each distribution

  1. A CacheHitRate series exists. With additional metrics off there is no series, and ZopNight treats that as unknown, never as a 0% hit rate.
  2. The series covers at least 7 days of hourly data.
  3. The 30-day average is below 80%.
  4. The distribution has a known monthly cost, and a measured dollar figure for the origin traffic its misses caused is available.

Why the rule is silent on every distribution today

The fourth input is missing. The request count and hit rate ZopNight collects do not say how many bytes the misses pulled from the origin, and without that number any saving would be a guess. So no recommendation appears, even for a distribution with a poor hit rate, until origin byte counts per distribution are collected. A distribution that serves no traffic at all is a different case, covered by Idle CloudFront Distribution.

How the saving will be priced

Terminal window
saving = cache-miss origin traffic in GB x CloudFront per-GB data transfer rate
capped at the distribution's monthly cost

No flat percentage of the bill is ever used in place of the measured bytes.

Raising the hit rate

  1. Set a long Cache-Control: max-age at the origin for static objects, and raise the cache policy’s minimum and default TTLs to match.
  2. Trim the cache key: forward only the query strings, cookies and headers that change the response.
  3. Turn on Origin Shield in the Region with the lowest latency to the origin so every caching layer goes through one extra cache. Origin Shield carries its own charge, so weigh it against the origin load it removes.
  4. Recheck CacheHitRate a week later, since the average needs fresh traffic to move.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·