Networking
Elastic Load Balancing
Elastic Load Balancing distributes incoming traffic across targets in multiple AZs, checks their health, and lets you scale horizontally. Load balancers appear in most availability and scalability questions.
The three load balancers
| Application Load Balancer (ALB) | Network Load Balancer (NLB) | Gateway Load Balancer (GWLB) | |
|---|---|---|---|
| OSI layer | 7 (HTTP, HTTPS, gRPC, WebSocket) | 4 (TCP, UDP, TLS) | 3 (IP packets, GENEVE) |
| Routing | Path, host, header, query string, method, source IP | Port/protocol | To a fleet of virtual appliances |
| Targets | Instances, IPs, Lambda functions, containers | Instances, IPs, ALBs | Appliance instances/IPs |
| Static IP | No (use Global Accelerator in front if needed) | Yes — one per AZ; can use Elastic IPs | — |
| Performance | High | Extreme (millions of requests/second, ultra-low latency) | — |
| Client IP | In X-Forwarded-For header |
Preserved | Preserved |
| Extras | Authentication (Cognito/OIDC), redirects, fixed responses, WAF integration | TLS termination, PrivateLink services, long-lived connections | Third-party firewalls, IDS/IPS, deep packet inspection |
Key idea
HTTP routing rules or Lambda targets → ALB. Static IPs, extreme performance, non-HTTP protocols (TCP/UDP) or PrivateLink → NLB. Inline third-party security appliances → GWLB.
Core concepts
- Listener — protocol and port the load balancer accepts (e.g. HTTPS:443), with rules.
- Target group — a set of targets plus health check settings; a listener rule forwards to a target group.
- Health checks — unhealthy targets stop receiving traffic. Auto Scaling groups can use ELB health checks to replace unhealthy instances.
- Cross-zone load balancing — spreads traffic evenly across targets in all AZs (on by default for ALB; optional for NLB).
- Sticky sessions — bind a user to the same target with cookies (ALB). Better: make apps stateless and store sessions in ElastiCache or DynamoDB.
- Deregistration delay (connection draining) — let in-flight requests finish before a target is removed.
- TLS termination with ACM certificates; SNI lets one listener serve many certificates (many domains).
ALB routing examples
https://example.com/api/* → target group: api-service
https://example.com/images/* → target group: image-service
https://admin.example.com/* → target group: admin (with Cognito authentication)
http://* → redirect to HTTPS
One ALB can front many microservices — cheaper and simpler than one load balancer per service.
Internal vs internet-facing
- Internet-facing — public DNS name; nodes in public subnets.
- Internal — private IPs only; used between tiers (e.g. web tier → internal ALB → app tier).
Classic Load Balancer
The previous generation. You may see it in legacy questions; new designs use ALB or NLB.
Exam patterns
- "Route /orders and /users to different services" → ALB path-based routing.
- "Partners must allow-list fixed IP addresses" → NLB with Elastic IPs (or Global Accelerator).
- "Millions of TCP connections with very low latency" → NLB.
- "Inspect all traffic with a third-party firewall appliance fleet" → GWLB.
- "Users get logged out when instances scale in" → store sessions externally (ElastiCache/DynamoDB) or enable stickiness.