Use Lambda@Edge with a CloudFront distribution to change a video request or response at a chosen point in delivery—for example, to route a cache miss to the right MediaPackage endpoint or apply access checks. It does not encode or package video: a video workflow still needs an origin and packaged content, such as an HLS or DASH manifest with its media segments.
How CloudFront and Lambda@Edge fit into video delivery
A player typically requests a manifest that describes playback and then requests the media segments listed in it. AWS identifies MPEG-DASH, Apple HLS, Microsoft Smooth Streaming, and CMAF among common streaming formats. In a video-on-demand workflow, content can be encoded and packaged, stored on a server or in S3, and delivered through CloudFront. In a live workflow, MediaLive can encode a feed, while services such as MediaStore or MediaPackage can provide an origin or delivery formats. AWS’s CloudFront video guide describes these roles.
Lambda@Edge is a CloudFront extension point. When a configured CloudFront event occurs, the function can customize a request or response before CloudFront continues processing it. The function runs synchronously in the request path, so work that delays its completion also delays that request. Keep its logic focused and fast. See the Lambda@Edge guide and CloudFront trigger event reference.
Choose the CloudFront event that matches the decision
| Event | Where it runs | Video-delivery use |
|---|---|---|
| Viewer request | When CloudFront receives a viewer request, before cache lookup. | Make a request-time decision that must happen before CloudFront checks its cache, such as handling viewer-specific request information. |
| Origin request | When CloudFront forwards a request to the origin; it does not run on a cache hit. | Choose or customize the origin for a cache miss, such as mapping a path value to a MediaPackage endpoint. |
| Origin response | When CloudFront receives a response from the origin. | Customize an origin response before CloudFront continues delivery. |
| Viewer response | When CloudFront is preparing a response for the viewer. | Customize a response at the viewer-facing end of the request path. |
The event names describe different points in the request lifecycle, not interchangeable places to run the same logic. In particular, origin-request logic cannot make a new decision for a request served from cache. AWS documents the event behavior in its event reference.
Recommended Free Tools
#1 Best Overall
- HD streaming made simple: With America’s number 1 TV streaming platform,* exploring popular apps—plus tons of free movies, shows, and live TV—is as easy as it is fun. *Based on hours streamed—Hypothesis Group
- Compact without compromises: The sleek design of Roku Streaming Stick won’t block neighboring HDMI ports, and it even powers from your TV alone, plugging into the back and staying out of sight. No wall outlet, no extra cords, no clutter.
- No more juggling remotes: Power up your TV, adjust the volume, and control your Roku device with one remote. Use your voice to quickly search, play entertainment, and more.
- Shows on the go: Take your TV to-go when traveling—without needing to log into someone else’s device.
- TV, simplified: With setup that only takes minutes, a simple-to-navigate Home Screen, and an uncluttered remote control that does all you need—Roku makes it easier to watch the TV you love.
Plan a Lambda@Edge video customization
- Define what must vary. Decide whether the behavior depends on the viewer request, an origin destination, an authorization token, or a response. Identify whether the request is for a manifest or a media segment, and which playback formats your workflow serves.
- Choose the event based on cache behavior. Use a viewer event if the decision must occur before cache lookup. Use origin request for decisions needed only when CloudFront forwards a cache miss to the origin. Do not rely on an origin-request function to run for every viewer request.
- Design cache keys and forwarding together. If routing or content varies by query string, ensure the relevant request values are forwarded and represented appropriately in the cache design. AWS requires the cache policy or origin request policy to forward all query strings when an origin-request Lambda@Edge function accesses query strings. A cache key that collapses requests that should receive different content can undermine otherwise correct routing or access logic. See the Lambda@Edge restrictions.
- Keep the synchronous function narrow. Use the function for request/response customization or routing, not video encoding. Encoding and packaging belong in services such as MediaConvert, MediaLive, or MediaPackage, as described in AWS’s video delivery guide. If the function calls another service or performs additional work, account for that in request latency and failure handling.
- Deploy the supported Lambda@Edge form. AWS’s setup guidance says to create the function in US East (N. Virginia), publish a numbered version, and associate that version with the relevant CloudFront distribution and cache behavior. Check the current getting-started guidance, restrictions, and quotas before choosing dependencies or deployment design.
- Verify both cache paths. Test a request that reaches the origin and one that is served from cache. Confirm the selected origin, manifest and segment behavior, and that different viewers or query values do not accidentally share a cached response when they should not.
Pattern: route HLS requests to dynamic MediaPackage endpoints
MediaPackage endpoint prefixes can be randomized, making static origin registration inconvenient. In an AWS Media & Entertainment walkthrough published on 2023-08-23, the viewer URL path carries the changing prefix; an origin-request Lambda@Edge function uses it to reconstruct the origin domain and route the request. Because origin-request functions run on cache misses, the example’s function runs for a manifest or segment request only when that object is not already served from CloudFront’s cache.
The walkthrough is an implementation pattern, not a guarantee that any endpoint can be routed safely without configuration review. Confirm the current endpoint format, request mapping, cache behavior, and origin security for your distribution. AWS says the same mapping process can apply to DASH or Smooth Streaming manifests. Read the dynamic MediaPackage origin-mapping walkthrough.
Rank #2
- Ultra-speedy streaming: Roku Ultra is 30% faster than any other Roku player, delivering a lightning-fast interface and apps that launch in a snap.
- Cinematic streaming: This TV streaming device brings the movie theater to your living room with spectacular 4K, HDR10+, and Dolby Vision picture alongside immersive Dolby Atmos audio.
- The ultimate Roku remote: The rechargeable Roku Voice Remote Pro offers backlit buttons, hands-free voice controls, and a lost remote finder.
- No more fumbling in the dark: See what you’re pressing with backlit buttons.
- Say goodbye to batteries: Keep your remote powered for months on a single charge.
Pattern: customize an HLS manifest for on-demand conversion
An AWS sample architecture checks from an origin-request Lambda@Edge function whether a generated HLS manifest exists in S3. If it does not, the function invokes MediaConvert and returns a temporary manifest referencing an intro segment; a subsequent manifest request can retrieve the generated result. This is an example for infrequently viewed or on-demand conversions, not a promise of instantaneous conversion or a blanket production recommendation.
Before adopting this pattern, assess conversion delay, repeat requests, cache behavior, and the way the temporary and generated manifests relate. The sample is described in AWS’s on-the-fly video conversion walkthrough.
Rank #3
- Stunning 4K and Dolby Vision streaming made simple: With America’s number 1 TV streaming platform,* exploring popular apps—plus tons of free movies, shows, and live TV—is as easy as it is fun. *Based on hours streamed—Hypothesis Group
- Breathtaking picture quality: Stunningly sharp 4K picture brings out rich detail in your entertainment with four times the resolution of HD. Watch as colors pop off your screen and enjoy lifelike clarity with Dolby Vision and HDR10+.
- Seamless streaming for any room: With Roku Streaming Stick 4K, watch your favorite entertainment on any TV in the house, even in rooms farther from your router thanks to the long-range Wi-Fi receiver.
- Shows on the go: Take your TV to-go when traveling—without needing to log into someone else’s device.
- Compact without compromises: Our sleek design won’t block neighboring HDMI ports, so you can switch from streaming to gaming with ease. Plus, it’s designed to stay hidden behind your TV, keeping wires neatly out of sight
Pattern: restrict access to private video
For private media, access control needs to cover both viewer authorization and the path to the origin. CloudFront use cases describe signed URLs or signed cookies and restricting direct origin access. AWS’s Secure Media Delivery implementation guide describes token validation using viewer-specific attributes for HLS, DASH, and CMAF.
Adding a Lambda@Edge function by itself does not secure an origin. Validate credentials at an appropriate point in the request flow and configure the origin so viewers cannot bypass the CloudFront policy by requesting the origin directly. Review the CloudFront use cases and Secure Media Delivery implementation guide.
Rank #4
- Advanced 4K streaming - Elevate your entertainment with the next generation of our best-selling 4K stick, with improved streaming performance optimized for 4K TVs.
- The newest Fire TV experience (2026) – Our biggest update to Fire TV has a new, modern design that gets you to your entertainment fast. Browse dedicated content categories, pin more of your favorite apps, and get personalized recommendations from Alexa+. Spend less time scrolling, and more time watching.
- Cloud gaming, no console required – Stream Call of Duty: Black Ops 7, Hogwarts Legacy, Outer Worlds 2, Ninja Gaiden 4, and hundreds of games on your Fire TV Stick 4K Select with Xbox Game Pass and Luna via cloud gaming. Xbox Game Pass subscription and compatible controller required. Each sold separately.
- Smarter picks with Alexa+ – Getting to what you love has never been easier. Press the voice remote button and talk naturally to find what to watch across your apps, manage your smart home, or dive into virtually any topic.
- Wi-Fi 6 support - Enjoy smooth 4K streaming, even when other devices are connected to your router.
Compare the patterns before choosing one
| Pattern | Function’s role | Cache and request considerations | Key design concern |
|---|---|---|---|
| Dynamic origin mapping | Origin-request function maps request-path information to an origin. | Runs only when CloudFront forwards a cache miss. Manifest and segment requests may each encounter the logic if they are not cached. | Validate endpoint reconstruction, cache behavior, and origin security. |
| On-demand HLS conversion | Origin-request function checks for a generated manifest, can invoke MediaConvert, and can return a temporary manifest in the sample architecture. | Conversion and later manifest retrieval must work with the cache and request sequence. | Plan for conversion timing and operational behavior; the sample does not establish a universal production design. |
| Private-content validation | Validate viewer credentials in an appropriate part of the request flow; CloudFront also supports signed URLs or cookies. | Viewer-specific authorization must not be defeated by shared cache behavior. | Protect the origin against direct access that bypasses the CDN policy. |
Across all three, the right event depends on whether logic must run before cache lookup or only when CloudFront contacts the origin. Cache keys and forwarding policies must reflect any viewer- or query-specific variation. Also account for synchronous latency and Lambda@Edge’s feature and deployment restrictions.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Live-stream cache behavior needs format-specific care
Live manifests and segments do not necessarily have the same caching needs. AWS’s live-streaming guidance describes format-specific behaviors and recommends a minimum TTL of five seconds or less for the MediaPackage live workflow covered there. Treat that value as scoped to that documented setup, not a universal TTL for every live stream. Check the manifest and segment behavior in your own workflow against the CloudFront live-streaming setup guide.
Best Value
- Essential 4K streaming – Get everything you need to stream in brilliant 4K Ultra HD with High Dynamic Range 10+ (HDR10+).
- The newest Fire TV experience (2026) – Our biggest update to Fire TV has a new, modern design that gets you to your entertainment fast. Browse dedicated content categories, pin more of your favorite apps, and get personalized recommendations from Alexa+. Spend less time scrolling, and more time watching.
- Make your TV even smarter – Fire TV gives you instant access to a world of content, tailor-made recommendations, and Alexa, all backed by fast performance.
- All your favorite apps in one place – Experience endless entertainment with access to Prime Video, Netflix, YouTube, Disney+, Apple TV+, HBO Max, Hulu, Peacock, Paramount+, and thousands more. Easily discover what to watch from hundreds of thousands of movies and TV episodes (subscription fees may apply), including free, ad-supported content.
- Getting set up is easy – Plug in and connect to Wi-Fi for smooth streaming.
Lambda@Edge constraints to check before deployment
- Create the function in US East (N. Virginia), publish a numbered version, and associate that version with the CloudFront distribution and cache behavior, as described in the Lambda@Edge setup guidance.
- Lambda@Edge does not support several standard Lambda features, including VPC access, layers, X-Ray, provisioned concurrency, and ordinary environment variables. Consult the current restrictions and quotas before relying on any feature.
- The function blocks CloudFront from continuing the request until it finishes, so avoid unnecessary work on a path serving frequent segment requests.
- For origin-request logic that reads query strings, forward all query strings as AWS requires, and ensure the cache design preserves any distinctions that affect routing or content.
Or let it run in the cloud
Lambda@Edge customizes CloudFront delivery for an engineered video platform; StreamNeo solves a different problem: keeping uploaded videos live on a YouTube channel. It is not a CloudFront integration, video encoder, or camera-streaming service. To use it, upload a recording or build a playlist, add your YouTube stream key once, and go live. StreamNeo loops the uploaded video from the cloud, so nothing has to stay on at home. It streams the uploaded quality up to 4K 60fps at one flat price per slot, with automatic recovery if YouTube drops the stream. The first day is free with no card. Monthly service is $9.99 per month. Visit StreamNeo or start the free day.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




