
Two OTT brands on one governed estate: CloudFront + MediaTailor at multi-$M scale
Behind Kidoodle.TV’s CloudFront + MediaTailor delivery plane sits a high-scale AWS estate that must stay exactly as designed while operating around the clock. Within VeUP’s operational-efficiency engagement for APMC, AWS Config was deployed as the estate’s configuration-governance layer: continuous recording and drift detection across the platform’s resources, with AWS Security Hub centralizing security findings and an AWS Backup disaster-recovery strategy completing the posture.
The challenge
A streaming service for children carries a compounding governance burden: the estate is large, changes continuously under operations and cost optimization, and its configuration state has safety and compliance weight — encryption, access scoping, and delivery settings are commitments, not defaults. At OTT scale, drift happens in small increments nobody notices: a security-group change during an incident, a bucket policy adjusted for a one-off, a setting that never got rolled back. The platform needed the drift found by machinery, continuously, rather than by the next audit or the next outage.
The solution
VeUP delivered configuration governance as a workstream of the broader operational program. AWS Config records the configuration of the estate’s resources and evaluates them continuously, so every deviation from intended state becomes a timestamped, attributable finding rather than latent risk — covering the resources behind the CloudFront/MediaTailor delivery layer as well as the application and data services around them. Findings flow into AWS Security Hub, which centralizes security management for the estate into one queue, and the AWS Backup-based disaster-recovery strategy ensures the platform’s recovery posture is itself governed and testable. The result folds into the same operating rhythm VeUP runs for APMC’s whole account: measured account health, drift caught while it is one resource instead of one hundred, and configuration evidence continuously accumulating for compliance conversations.
Production outcomes
| KPI | Result |
|---|---|
| Continuous governance | AWS Config recording and drift detection live across the OTT estate — configuration deviations surfaced as findings in near real time, on a platform that changes daily under active FinOps and operations. |
| Centralized posture | Security findings consolidated in AWS Security Hub alongside the drift signal — one triage surface for an estate serving a global kids’ audience. |
| Recovery readiness | AWS Backup disaster-recovery design in place as part of the same governance workstream — intended state protected in depth: detected when it drifts, restorable when it breaks. |
| Lessons & continuation | Cost optimization and configuration governance belong in one program — every rightsizing change is a config change, and Config is what proves the estate ended up where the program intended; drift detection is cheapest before the drift compounds. |