VeUP
← All case studies
Media & Entertainment Competency · Safe-Kids AVOD Streaming
Kidoodle.TV wordmark

Kidoodle.TV streams safe-kids AVOD on Amazon CloudFront + Elemental MediaTailor

Live
safe-kids AVOD streaming in production
Margin protected
waste hunted first, then committed coverage
Governed
DR, drift detection, and security posture — the kids'-brand bar
Amazon CloudFrontElemental MediaTailorAWS BackupAWS Config

Kidoodle.TV is A Parent Media Co.’s safe-streaming, ad-supported (AVOD) video service for kids — the property at the heart of the APMC estate VeUP operates on AWS. It runs on Amazon CloudFront with AWS Elemental MediaTailor stitching ads server-side, with a two-phase FinOps program, AWS Backup DR, AWS Config drift detection, and Security Hub posture management behind it.

The challenge

A children’s streaming brand carries the strictest bar in OTT: reliable, low-latency video delivery at internet scale, monetization that works everywhere through server-side ad insertion, and a governed, auditable operational posture appropriate to a kids’ audience. Kidoodle.TV also needed its cost base matched to actual audience demand — rightsizing and committed-use coverage — plus a defined Backup-and-Restore DR strategy, continuous configuration drift detection, and centralized security-finding aggregation.

The solution

Kidoodle.TV streams through Amazon CloudFront for global edge delivery of HLS/DASH segments and manifests, with AWS Elemental MediaTailor performing server-side ad insertion at the manifest layer — device-consistent, ad-blocker-resistant monetization for the AVOD inventory. Cache behaviors are tuned for OTT: long-lived caching for immutable media segments, short-TTL for the MediaTailor-personalized manifest path, fronted by AWS WAF, ACM HTTPS, and Amazon Route 53. Around the delivery plane VeUP ran a two-phase FinOps program — hunt the waste first with a line-by-line EC2 analysis, then commit to reserved capacity — and built out AWS Backup Backup-and-Restore DR to the RTO/RPO target, AWS Config continuous drift detection, AWS Security Hub centralized posture, and Amazon CloudWatch operational metrics under AWS Organizations + IAM Identity Center governance.

Architecture

Kidoodle.TV runs on the shared APMC OTT stack — one AWS estate serving both APMC streaming properties. From the pre-FinOps baseline to the production CloudFront + MediaTailor edge, VPC compute, and the AWS Backup / Config / Security Hub governance plane.

The shared APMC production streaming estate serving Kidoodle.TV: Route 53, AWS WAF, and ACM in front of CloudFront with a long-TTL segment / short-TTL manifest cache split, Lambda@Edge, Elemental MediaTailor server-side ad insertion, a private-subnet VPC with rightsized EC2, a KMS-encrypted S3 origin, and the AWS Backup, Config, Security Hub, CloudTrail, Organizations, IAM Identity Center, and CloudWatch governance plane.
The shared APMC estate as it runs today — CloudFront and MediaTailor at the edge, a governed VPC behind them, and the Backup / Config / Security Hub plane keeping it honest.

Production outcomes

KPIResult
Production outcomesKidoodle.TV runs in production on the shared APMC OTT stack with a Green account-health rating; the two-phase FinOps work — rightsizing from a line-by-line EC2 waste analysis, then committed-use coverage — identified and captured cost reductions protecting streaming margin; a Backup-and-Restore DR strategy on AWS Backup was deployed to the RTO/RPO target; AWS Config drift detection and AWS Security Hub centralized findings keep the estate at a governed, auditable posture.
Cost / TCO postureCost optimization was a primary workstream: CloudFront data transfer and requests, MediaTailor ad-insertion volume, and the supporting compute and storage were modeled against the growth curve, then attacked in two phases — hunt the waste first, then commit — tying delivery spend to AVOD unit economics: sustainable cost-per-stream as audience and catalog scale.
Lessons & continuationCloudFront’s native MediaTailor integration makes server-side ad insertion device-consistent and origin-efficient; OTT cache behaviors must split immutable-segment caching from the short-TTL personalized-manifest path; native managed services (AWS Backup + Config + Security Hub) give a governed, auditable posture without bespoke tooling — the right bar for a children’s streaming brand.
AWS services in production
Amazon CloudFrontAWS Elemental MediaTailorAWS WAFAWS Certificate ManagerAmazon Route 53Amazon S3AWS BackupAWS ConfigAWS Security HubAmazon CloudWatchAWS OrganizationsIAM Identity Center