How to clear (invalidate) a CloudFront cache

Updated · 2 min read

You updated a file in S3, or redeployed your site, and visitors still get the old version. CloudFront keeps copies of your files at its edge locations around the world and serves those until they expire. To make it fetch fresh copies sooner, you create an invalidation: a list of paths CloudFront should forget.

In the AWS console

  1. Open CloudFront → Distributions and click the one for your site. The Domain name and Alternate domain names columns help you find it.
  2. Open the Invalidations tab and click Create invalidation.
  3. Enter the paths to clear, one per line, each starting with /. For example /index.html, /css/*, or /* for everything. Click Create invalidation.

The status goes from In progress to Completed, usually within a few minutes.

With the AWS CLI

Find the distribution's ID:

aws cloudfront list-distributions \
  --query 'DistributionList.Items[].[Id, DomainName, Aliases.Items[0]]' --output text

Clear everything:

aws cloudfront create-invalidation --distribution-id E1ABCDEFGHIJKL --paths "/*"

Or only some paths:

aws cloudfront create-invalidation --distribution-id E1ABCDEFGHIJKL \
  --paths "/index.html" "/css/*"

Keep the quotes, so your shell doesn't try to expand the * itself.

The output includes the invalidation's Id. To wait until it's finished, in a deploy script for example:

aws cloudfront wait invalidation-completed \
  --distribution-id E1ABCDEFGHIJKL --id I2J0I21PCUYOIK

Good to know

  • Cost. The first 1,000 paths you invalidate each month are free, and after that each path costs half a cent. A wildcard like /* counts as one path, however many files it covers.
  • Paths are case-sensitive. /Index.html and /index.html are different files to CloudFront.
  • Browsers keep copies too. An invalidation clears CloudFront, not the copy already in someone's browser. That one lasts as long as the file's Cache-Control header said it could.
  • You can avoid most invalidations. Put a version or a hash in file names (app.3f9c2a.js), so every deploy produces new URLs, and give the HTML that points at them a short cache time. Many build tools already do this. Then there's nothing old to clear.

Or in Cloud GUI

Cloud GUI's Websites page lists each of your domains with the CloudFront distribution that serves it, where that distribution fetches from, how many days its certificate has left, and whether Route 53 points the name at it. A distribution's page says in plain words how long each path is cached, which is where you'd start if you want to stop clearing by hand.

That page also has Clear cache: type the paths, one per line (/* is filled in), and it shows the clear's progress until CloudFront reports it done. Clearing is part of Pro and needs editing turned on for the account. If editing was set up before its role's version 2, the page links to a one-time update of that role first. AWS's pricing is the same as above: 1,000 paths a month free, then $0.005 per path.

See your whole AWS account in one calm view

Cloud GUI shows your files and functions from every region at once, in plain English, with what's failing up front. It connects with a read-only role you create and can delete any time. Free for one AWS account.

More guides

Free tool
IAM policy explainer

Paste an IAM policy and read it in plain English, with the risky parts flagged. It runs in your browser; nothing is sent anywhere.