VeUP
← All case studies
AWS Config · Config drift detection
A Parent Media Co. (APMC) logo

Two OTT brands on one governed estate: CloudFront + MediaTailor at multi-$M scale

Made an acquisitionQuadri portfolioCDN & edge delivery architectureWeb application firewall & bot mitigationRightsizing & instance-family modernizationCommitment & RI optimizationCost-optimization deep divePreventive controlsCentralized workforce identityManaged billing & resellStanding cost-optimization mechanismCommitted-spend procurement enablementPer-service spend attribution
2
streaming brands live on one governed estate
600 million
MediaTailor ad insertions committed per contract year
Multi-$M
annual AWS scale, held at Green account health
AWS ConfigAWS Security HubAWS BackupAmazon CloudFront

Behind Kidoodle.TV’s CloudFront + MediaTailor delivery plane sits a high-scale AWS estate that must stay exactly as designed while operating around the clock. Within VeUP’s operational-efficiency engagement for APMC, AWS Config was deployed as the estate’s configuration-governance layer: continuous recording and drift detection across the platform’s resources, with AWS Security Hub centralizing security findings and an AWS Backup disaster-recovery strategy completing the posture.

The challenge

A streaming service for children carries a compounding governance burden: the estate is large, changes continuously under operations and cost optimization, and its configuration state has safety and compliance weight — encryption, access scoping, and delivery settings are commitments, not defaults. At OTT scale, drift happens in small increments nobody notices: a security-group change during an incident, a bucket policy adjusted for a one-off, a setting that never got rolled back. The platform needed the drift found by machinery, continuously, rather than by the next audit or the next outage.

The solution

VeUP delivered configuration governance as a workstream of the broader operational program. AWS Config records the configuration of the estate’s resources and evaluates them continuously, so every deviation from intended state becomes a timestamped, attributable finding rather than latent risk — covering the resources behind the CloudFront/MediaTailor delivery layer as well as the application and data services around them. Findings flow into AWS Security Hub, which centralizes security management for the estate into one queue, and the AWS Backup-based disaster-recovery strategy ensures the platform’s recovery posture is itself governed and testable. The result folds into the same operating rhythm VeUP runs for APMC’s whole account: measured account health, drift caught while it is one resource instead of one hundred, and configuration evidence continuously accumulating for compliance conversations.

Production outcomes

KPIResult
Continuous governanceAWS Config recording and drift detection live across the OTT estate — configuration deviations surfaced as findings in near real time, on a platform that changes daily under active FinOps and operations.
Centralized postureSecurity findings consolidated in AWS Security Hub alongside the drift signal — one triage surface for an estate serving a global kids’ audience.
Recovery readinessAWS Backup disaster-recovery design in place as part of the same governance workstream — intended state protected in depth: detected when it drifts, restorable when it breaks.
Lessons & continuationCost optimization and configuration governance belong in one program — every rightsizing change is a config change, and Config is what proves the estate ended up where the program intended; drift detection is cheapest before the drift compounds.
AWS services in production
AWS ConfigAWS Security HubAWS BackupAmazon CloudFrontAWS Elemental MediaTailorAmazon CloudWatch