Skip to content

Application Load Balancer (ALB)

An Application Load Balancer (ALB) sits in front of your application and distributes incoming requests across your running instances. It routes each request based on content such as the URL path or HTTP headers.

Byks guides

Terraform configuration

terraform-byks-module doesn't create the ALB. Provision it directly with the terraform-aws-alb module, outside the module "application" block. Each instance of the module creates one ALB with an HTTPS listener, an HTTP listener that redirects to HTTPS, a security group, and an S3 bucket for access logs.

terraform-byks-module then finds the ALB by its name, <environment>-<application_name>, and attaches each service in ecs_services to its HTTPS listener. Set function = "" and use the same application_name in both modules, so the names match. If the names differ, set override_alb_name in module "application" to the ALB's name.

For the full steps to set up a new ALB, see Deploy an Application Load Balancer.

alb.tf
data "aws_ssm_parameter" "vpc_information" {
  name = "/bym/vpc"
}

module "alb" {
  source = "git@github.com:BYM-IKT/terraform-aws-alb.git?ref=v3"
  application_name = "example"
  environment      = var.environment
  function         = ""
  vpc              = jsondecode(data.aws_ssm_parameter.vpc_information.insecure_value)

  acm_config = {
    primary_domain = {
      dns_record     = "example-alb-default.test.bymoslo.net"
      route53_domain = "test.bymoslo.net"
    }
  }

  providers = {
    aws.route53 = aws.route53
  }
  # options go here
}

Options

Option Type Default Description
application_name string required Name of the application using the ALB. Part of the ALB name, the security group name, and the log bucket name.
environment string required Environment the ALB belongs to, for example test or prod. Part of the ALB name and the security group name.
function string required Suffix that tells apart multiple ALBs in the same application. The ALB is named <environment>-<application_name>-<function>. Set it to "" to name the ALB <environment>-<application_name>, which is the name terraform-byks-module looks for.
vpc any required The account's VPC information. Read it from the /bym/vpc SSM parameter with jsondecode, as in the example. The module reads the VPC ID, its network ranges, and where to place public and private resources.
is_private bool false Give the ALB internal IP addresses in the private network, so it's reachable only from inside the network, for example behind an API Gateway. With false, the ALB is internet-facing. Contact Team Cloud if you're unsure which one you need.
disable_ipv6 bool false Use IPv4 only. Set to true only if the VPC has no IPv6 configured.
ssl_policy string "ELBSecurityPolicy-FS-1-2-Res-2020-10" TLS policy for the HTTPS listener.
create_dns_records bool true Create Route53 A and AAAA records that point the domains in acm_config to the ALB. Set to false for a private ALB, or to keep existing DNS records managed outside the module.
alb_sg_description string "" Description of the ALB's security group. Empty uses ALB <ALB name>. AWS replaces a security group when its description changes, so set this to the existing description when you move an existing ALB to the module.
waf bool false Tag the ALB with WAF-PROTECT = True, which marks it for protection by a web application firewall. The module only sets the tag.
enable_observability bool false Forward the ALB's access logs to Datadog. The datadog-forwarder Lambda function must exist in the account first, or terraform plan fails.
remove_logs_on_destroy bool false Delete the access log bucket and its logs when you delete the module. Access logs expire after 90 days either way.
override_name string null Override the generated ALB name. If you set it, set override_alb_name in module "application" to match.
override_listen_ports object {} Override the ports the listeners use. See Listen ports object.
acm_config object {} TLS certificate and domains for the HTTPS listener. The module creates an ACM certificate unless you set cert_arn. See Certificate object.

Listen ports object

Used in override_listen_ports.

Option Type Default Description
http_port number 80 Port of the HTTP listener, which redirects all requests to HTTPS.
https_port number 443 Port of the HTTPS listener.

Certificate object

Used in acm_config.

Option Type Default Description
cert_arn string null ARN of an existing ACM certificate for the HTTPS listener. With null, the module creates and validates a certificate for primary_domain and additional_domains.
primary_domain object null The ALB's main domain. Required unless you set both cert_arn and create_dns_records = false. By convention, use a placeholder domain such as <application_name>-alb-default.test.bymoslo.net, since each service in ecs_services adds its own certificate. See Domain object.
additional_domains list(object) [] Extra domains added to the certificate and pointed to the ALB. Requires primary_domain. The DNS records for these domains go in the hosted zone of primary_domain. See Domain object.

Domain object

Used in primary_domain and additional_domains.

Option Type Default Description
dns_record string required Full domain name, for example example-alb-default.test.bymoslo.net.
route53_domain string required Route53 hosted zone the domain belongs to: dev.bymoslo.net, test.bymoslo.net, or bymoslo.no.
evaluate_target_health bool true Let Route53 check the ALB's health before it answers DNS requests for the domain.

Outputs

Read these from the module, for example module.alb.listener_arn.

Output Description
alb_arn ARN of the ALB.
alb_arn_suffix ARN suffix of the ALB, used by some CloudWatch alarms.
alb_dns_name DNS name of the ALB, for Route53 alias records.
alb_zone_id Hosted zone ID of the ALB, for Route53 alias records.
alb_sg_id ID of the ALB's security group.
listener_arn ARN of the HTTPS listener, for adding listener rules.

Resources