RockCloud vs AWS: CloudFront billing and the China problem
CloudFront splits one stream of traffic across geographic tiers, request types and transfer directions, producing a bill nobody can forecast at the start of the month or explain at the end of it. The global partition also has no CN2 route home, so mainland visitors ride ordinary international transit. RockCloud quotes a flat, predictable tier, connects back over bidirectional CN2 GIA, and ships terabit mitigation inline with acceleration on a single bill.
Send a bill, get a comparisonKey differences at a glance
| Dimension | RockCloud | AWS |
|---|---|---|
| Billing structure | Flat bandwidth or traffic tier, attributed per hostname, ceiling known before you sign | Priced per geographic tier, then split by request type, transfer direction and volume bands |
| Total cost | One fee covers CN2 acceleration plus terabit DDoS and CC mitigation — no add-ons | Premium per-GB pricing, with advanced mitigation, WAF, real-time logs and edge functions billed separately |
| Mainland China performance | Bidirectional CN2 GIA back into China from a filing-free edge, near-domestic latency | No CN2 route in the global partition; mainland traffic rides congested international transit |
| China accounts | One account and one configuration serve both domestic and overseas visitors | China is an isolated partition: separate account, separate ICP filing, separate console and bill |
| DDoS mitigation | 7T+ scrubbing and up to 3 Tbps per IP, inline with acceleration, uptime first under attack | Shield Standard covers basic network-layer attacks; anything beyond needs a committed Shield Advanced subscription |
| Learning curve and onboarding | Console organised around business objects, live five minutes after a DNS change, free 24-hour trial | IAM, distributions, behaviours and layered cache policies demand a dedicated in-house specialist |
| Support and market fit | Direct 24/7 Chinese-speaking engineers who understand filing, cross-border and China-facing traffic | Ticket-first English support; named engineers require a higher support plan, across a timezone gap |
Four differences that decide cost and experience
None of this shows up in a staging environment. All of it shows up once real traffic scales, mainland users grow, or an attack lands.
The bill is not a number, it is forty line items
CloudFront prices the same traffic differently across a dozen geographic tiers, then splits it again by transfer direction (egress versus origin fetch), request type (HTTPS costs more than HTTP), request count, invalidation paths and edge function invocations, all layered on volume bands. The result: you cannot forecast the month and you cannot explain it afterwards. When one region jumps 40 percent, finding which hostname and which request class caused it means digging through dozens of usage types. We quote a flat bandwidth or traffic tier with a ceiling you know before signing, and the invoice lists one line per hostname — engineering and finance finally read the same sheet.
Mitigation as an add-on versus mitigation inline
Most teams discover on the day they get hit that the bundled Shield Standard only covers common network and transport layer attacks. Advanced volumetric protection, expert response during an incident and cost protection against traffic surges require a Shield Advanced subscription — a separate paid product with a commitment term. Layer-7 CC and business-logic abuse then need AWS WAF on top, billed per web ACL, per rule and per request. Signing a committed subscription to survive one attack is bad economics; not signing is worse. We include 7T+ of scrubbing capacity and up to 3 Tbps per IP of DDoS and CC mitigation on the same request path as acceleration, on one fee.
Without CN2, no cache tuning fixes mainland latency
The AWS global partition offers no CN2 route into China, so mainland users reach an overseas origin over ordinary international transit, where evening peaks and cross-border congestion inflate queueing delay and packet loss. Pages stall, APIs time out, streams take longer to render a first frame — and no cache rule fixes it, because the bottleneck is the path, not the configuration. Solving it inside AWS means moving to the China partition (Beijing and Ningxia, run by local operators): a separate account and contract, a mandatory ICP filing, a separate console and bill. That is one business maintained as two. We put the edge in the filing-free ring around China and haul back over bidirectional CN2 GIA — one configuration, both audiences.
A console built for cloud architects, or for the people running the business
Changing one cache rule in CloudFront means obtaining the right IAM permissions, opening the distribution, working out the precedence of behaviour path patterns, then deciding which of the cache policy, origin request policy and response headers policy actually needs editing — followed by a deployment wait, and often a production surprise. That knowledge lives in one person, and when they leave, a routine change becomes a week-long ticket. Our console is organised by business object: hostnames, origins, cache rules, protection policies and certificates each get their own screen, so operations staff can self-serve. When judgement is needed, 24/7 Chinese-speaking engineers are one message away, not a ticket queue in another timezone.
Why customers move over from AWS
The reasons teams leaving CloudFront cite most often.
- The monthly bill never reconciles — dozens of region and request-type line items, no way to say which hostname drove the increase, and no defensible forecast.
- Mainland users kept reporting slowness — with no CN2 in the global partition, cross-border congestion timed out APIs and stalled streams no matter how the cache was tuned.
- They learned mid-attack that real mitigation was a separate subscription — Shield Advanced carries a commitment term, which is a poor trade for one incident and no defence without it.
- Serving mainland users meant opening the China partition, which turned out to require a separate account, a separate ICP filing, a separate console and a separate bill.
- The one engineer who understood CloudFront left — nobody would touch behaviour precedence or the three policy layers, so routine changes queued for a week.
Migrating takes four steps
No application changes, gradual rollout, and one DNS record away from rolling back.
Reproduce the distribution
Export origins, behaviour path patterns, cache policies and response header policies from CloudFront; we rebuild equivalent semantics in our console and walk through them with you rule by rule.
Run in parallel
Point a low-traffic hostname or a single region at us and compare hit ratio, mainland and overseas latency, origin fetch volume and status code distribution.
Full cutover
Repoint the main CNAME — effective within five minutes. Leave the CloudFront distribution untouched so rollback is just a DNS change.
Close it out
Once stable, disable the old distribution to stop the meter, rotate the origin IP and allow only our fetch ranges so nobody reaches historical addresses directly.
RockCloud vs AWS FAQ
CloudFront prices the same traffic separately per geographic tier, then splits it by transfer direction (egress versus origin fetch), request type (HTTPS costs more than HTTP), request count, invalidation paths and edge function invocations, all on volume bands. That is how one month becomes dozens of usage types with no obvious mapping back to a hostname. Cost Explorer grouped by usage type and region helps you triage; fixing it properly means moving to a flat tier attributed per hostname, where the monthly ceiling is known before you sign.
The per-GB rate alone sits in the premium bracket, but what really inflates the invoice is the add-ons: advanced DDoS protection, WAF rules, real-time logs, edge functions and invalidations are all billed separately. We charge one fee covering CN2 acceleration plus terabit DDoS and CC mitigation. Your actual saving depends on where your traffic lands — the higher your mainland and APAC share, the wider the gap. Send last month’s CloudFront bill and your peak bandwidth and we will return a directly comparable quote.
Yes. The AWS China regions (Beijing and Ningxia) are operated by local partners as a partition isolated from the global one: a separate account and contract, a mandatory ICP filing for your domain, and a separate console, bill and service catalogue. In practice that means running one business as two. Our approach differs — the edge sits in Hong Kong, Japan, Korea and Singapore with no filing required, then hauls back over bidirectional CN2 GIA, so a single account and configuration serves visitors on both sides of the border.
No code changes — migration happens at the DNS layer. We first reproduce your CloudFront origins, behaviour path patterns and cache policies with equivalent semantics in our console, then validate with a low-traffic hostname or one region, comparing hit ratio, latency and status code distribution. Once they match, repoint the main CNAME and it is live within five minutes. The CloudFront distribution stays untouched throughout, so rollback is a DNS change; disable it only after the new path has run clean.
Partly. Shield Standard is included at no cost and covers common network and transport layer attacks. Advanced volumetric protection, expert response during an incident and cost protection against attack-driven traffic surges require Shield Advanced, a separate paid subscription with a commitment term. Layer-7 CC and business-logic abuse then need AWS WAF on top, billed per web ACL, per rule and per request. With us, 7T+ of scrubbing capacity and up to 3 Tbps per IP of DDoS and CC mitigation ship with acceleration — not as an upgrade.
Yes. Ours is organised by business object — hostnames, origins, cache rules, protection policies and certificates each get a dedicated screen — so changing caching does not require understanding behaviour path precedence or deciding which of three policy layers to edit. Operations staff handle routine changes without an engineer. When a call is genuinely hard, 24/7 Chinese-speaking engineers are directly reachable rather than behind an English ticket queue in another timezone, and they already understand filing, cross-border routing and how mainland networks behave.
Still haven't found what you're looking for? Talk to our team.
Third-party trademarks belong to their respective owners. Products and pricing may change — refer to the latest official information.
Send us your CloudFront bill and we will run the numbers
Share last month’s traffic mix, peak bandwidth and visitor geography, and we will return a directly comparable flat-tier quote plus a free 24-hour trial so you can measure mainland performance on your own traffic.
