Skip to main content
rightsizing · aws

CloudFront distributions where a sub-80% cache hit ratio pushes traffic to the origin

rule IDs covered
1
severity
low

What does ZopNight detect here?

CacheHitRate below 80% over 30 days means a fifth or more of requests bypass the edge and bill origin data transfer instead. ZopNight will only attach a dollar figure derived from measured cache-miss egress, and since no producer supplies that figure yet, the rule currently abstains on every distribution.

Signal and threshold

How ZopNight evaluates CloudFront distributions where a sub-80% cache hit ratio pushes traffic to the origin.
Field Value
Rule IDsRC-1511
Categoryrightsizing
Severitylow
Metricnone — pure configuration read
Sourcecloudfront_optimization.go

Every cache miss is a paid round trip

A CDN’s economics live in its hit ratio. Requests answered at the edge cost CloudFront transfer rates; misses travel to the origin and back, adding origin data-transfer charges and latency on top. A distribution sitting below the 80% threshold is routing a fifth or more of its traffic the expensive way, usually for fixable reasons: cache keys fragmented by irrelevant query strings or headers, TTLs set to zero by a nervous default, or content that was never marked cacheable at all.

A metric that exists only when you ask for it

CacheHitRate is one of CloudFront’s additional CloudWatch metrics, published only for distributions with the paid real-time metrics subscription enabled. An absent series therefore means “not measured”, never “0% hit rate”, and the rule abstains on it. When present, the decision gates on the sustained 30-day average with a minimum-coverage requirement, so one bad hour on a fresh subscription cannot trip it.

Why it abstains on every distribution today

The honest dollar figure for this finding is the origin egress attributable to cache misses (miss gigabytes times the per-GB data-out rate), capped at the distribution’s actual bill. Nothing in the current pipeline measures miss-attributable gigabytes: the harvested metrics yield percentages and request counts, not origin bytes, and the distribution’s total bill is not a miss-attributable delta. Rather than multiply the bill by an invented fraction, the rule keeps its savings gate closed, which means it fires on no distribution until that producer lands. The threshold logic above still describes what it will fire on.

Measure your own hit ratio

Terminal window
aws cloudwatch get-metric-statistics \
--namespace AWS/CloudFront --metric-name CacheHitRate \
--dimensions Name=DistributionId,Value=E1234EXAMPLE Name=Region,Value=Global \
--start-time "$(date -u -v-30d +%Y-%m-%dT%H:%M:%SZ)" \
--end-time "$(date -u +%Y-%m-%dT%H:%M:%SZ)" \
--period 86400 --statistics Average --region us-east-1

Raising the ratio, in order of leverage

Normalise the cache key first by stripping query strings and headers that do not change the response, since key fragmentation is the most common silent killer. Then raise TTLs where content allows, enable compression, and consider Origin Shield to collapse regional misses into one origin fetch. Each point of hit ratio gained is origin egress you stop buying.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·