Application Load Balancer (ALB)
An Application Load Balancer (ALB) sits in front of your application and distributes incoming requests across your running instances. It routes each request based on content such as the URL path or HTTP headers.
Byks guides
-
Deploy an Application Load Balancer (ALB)
Use the Terraform module to provision an AWS Application Load Balancer
Terraform configuration
terraform-byks-module doesn't create the ALB. Provision it directly with the terraform-aws-alb module, outside the module "application" block. Each instance of the module creates one ALB with an HTTPS listener, an HTTP listener that redirects to HTTPS, a security group, and an S3 bucket for access logs.
terraform-byks-module then finds the ALB by its name, <environment>-<application_name>, and attaches each service in ecs_services to its HTTPS listener. Set function = "" and use the same application_name in both modules, so the names match. If the names differ, set override_alb_name in module "application" to the ALB's name.
For the full steps to set up a new ALB, see Deploy an Application Load Balancer.
data "aws_ssm_parameter" "vpc_information" {
name = "/bym/vpc"
}
module "alb" {
source = "git@github.com:BYM-IKT/terraform-aws-alb.git?ref=v3"
application_name = "example"
environment = var.environment
function = ""
vpc = jsondecode(data.aws_ssm_parameter.vpc_information.insecure_value)
acm_config = {
primary_domain = {
dns_record = "example-alb-default.test.bymoslo.net"
route53_domain = "test.bymoslo.net"
}
}
providers = {
aws.route53 = aws.route53
}
# options go here
}
Options
| Option | Type | Default | Description |
|---|---|---|---|
application_name |
string |
required | Name of the application using the ALB. Part of the ALB name, the security group name, and the log bucket name. |
environment |
string |
required | Environment the ALB belongs to, for example test or prod. Part of the ALB name and the security group name. |
function |
string |
required | Suffix that tells apart multiple ALBs in the same application. The ALB is named <environment>-<application_name>-<function>. Set it to "" to name the ALB <environment>-<application_name>, which is the name terraform-byks-module looks for. |
vpc |
any |
required | The account's VPC information. Read it from the /bym/vpc SSM parameter with jsondecode, as in the example. The module reads the VPC ID, its network ranges, and where to place public and private resources. |
is_private |
bool |
false |
Give the ALB internal IP addresses in the private network, so it's reachable only from inside the network, for example behind an API Gateway. With false, the ALB is internet-facing. Contact Team Cloud if you're unsure which one you need. |
disable_ipv6 |
bool |
false |
Use IPv4 only. Set to true only if the VPC has no IPv6 configured. |
ssl_policy |
string |
"ELBSecurityPolicy-FS-1-2-Res-2020-10" |
TLS policy for the HTTPS listener. |
create_dns_records |
bool |
true |
Create Route53 A and AAAA records that point the domains in acm_config to the ALB. Set to false for a private ALB, or to keep existing DNS records managed outside the module. |
alb_sg_description |
string |
"" |
Description of the ALB's security group. Empty uses ALB <ALB name>. AWS replaces a security group when its description changes, so set this to the existing description when you move an existing ALB to the module. |
waf |
bool |
false |
Tag the ALB with WAF-PROTECT = True, which marks it for protection by a web application firewall. The module only sets the tag. |
enable_observability |
bool |
false |
Forward the ALB's access logs to Datadog. The datadog-forwarder Lambda function must exist in the account first, or terraform plan fails. |
remove_logs_on_destroy |
bool |
false |
Delete the access log bucket and its logs when you delete the module. Access logs expire after 90 days either way. |
override_name |
string |
null |
Override the generated ALB name. If you set it, set override_alb_name in module "application" to match. |
override_listen_ports |
object |
{} |
Override the ports the listeners use. See Listen ports object. |
acm_config |
object |
{} |
TLS certificate and domains for the HTTPS listener. The module creates an ACM certificate unless you set cert_arn. See Certificate object. |
Listen ports object
Used in override_listen_ports.
| Option | Type | Default | Description |
|---|---|---|---|
http_port |
number |
80 |
Port of the HTTP listener, which redirects all requests to HTTPS. |
https_port |
number |
443 |
Port of the HTTPS listener. |
Certificate object
Used in acm_config.
| Option | Type | Default | Description |
|---|---|---|---|
cert_arn |
string |
null |
ARN of an existing ACM certificate for the HTTPS listener. With null, the module creates and validates a certificate for primary_domain and additional_domains. |
primary_domain |
object |
null |
The ALB's main domain. Required unless you set both cert_arn and create_dns_records = false. By convention, use a placeholder domain such as <application_name>-alb-default.test.bymoslo.net, since each service in ecs_services adds its own certificate. See Domain object. |
additional_domains |
list(object) |
[] |
Extra domains added to the certificate and pointed to the ALB. Requires primary_domain. The DNS records for these domains go in the hosted zone of primary_domain. See Domain object. |
Domain object
Used in primary_domain and additional_domains.
| Option | Type | Default | Description |
|---|---|---|---|
dns_record |
string |
required | Full domain name, for example example-alb-default.test.bymoslo.net. |
route53_domain |
string |
required | Route53 hosted zone the domain belongs to: dev.bymoslo.net, test.bymoslo.net, or bymoslo.no. |
evaluate_target_health |
bool |
true |
Let Route53 check the ALB's health before it answers DNS requests for the domain. |
Outputs
Read these from the module, for example module.alb.listener_arn.
| Output | Description |
|---|---|
alb_arn |
ARN of the ALB. |
alb_arn_suffix |
ARN suffix of the ALB, used by some CloudWatch alarms. |
alb_dns_name |
DNS name of the ALB, for Route53 alias records. |
alb_zone_id |
Hosted zone ID of the ALB, for Route53 alias records. |
alb_sg_id |
ID of the ALB's security group. |
listener_arn |
ARN of the HTTPS listener, for adding listener rules. |
Resources
-
AWS documentation
Official AWS documentation for ALB