Final bucket policy applied:

{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "Statement1",
"Effect": "Allow",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::covenantcloudworks.online/*"
}
]
}

This ensures only CloudFront can fetch objects from S3,