Skip to main content
An origin group is a reusable set of one or more content sources. A distribution retrieves cache misses from its origin group.

Origin fields

Use a Host header override when the origin is a shared virtual host, load balancer, or object-storage endpoint that routes by hostname.

Upstream failover

Enable Use next upstream and choose which results permit another origin:
  • Connection error or timeout.
  • Invalid upstream header.
  • HTTP 403, 404, 429, 500, 502, 503, or 504.
Retrying non-idempotent requests can repeat an origin-side action. Limit allowed HTTP methods and failover conditions when the distribution accepts writes.

Object storage

Object-storage origins can include a storage endpoint, bucket name, region, and AWS Signature Version 4 credentials. Some S3-compatible providers do not require a region. Credentials are write-only secrets; omit them on an update unless you intend to replace them.

API example

An origin group cannot be deleted while a distribution still depends on it.