Ravindra BagaleCourses & study guides मराठी Track your progress

Chapter 18: Load Balancing

18.14 Different HTTP listeners

Why a balancer listens on more than one port

A listener is the front socket. People on the internet type https://www.example.com, which is port 443. Old links and health tools still call port 80. If you only open 443, the http:// link fails instead of moving the user to HTTPS. If you only open 80, the password and the cookie cross the network in clear text.

A third port, 8080, is for a check or an admin path that must not be reachable from the internet. That listener belongs on the internal balancer in section 18.16. It does not belong on the internet-facing balancer. Opening 8080 to the world would undo that later section.

What a listener is

A listener is four things:

  1. A protocol, HTTP or HTTPS.
  2. A port, such as 80, 443, or 8080.
  3. A default action, used when no rule matches.
  4. Rules, checked in order. The smaller priority number is first. The first match wins. Later rules are not tried.

The certificate sits on the HTTPS listener only. Port 80 has no certificate. Amazon Certificate Manager (ACM) is the place you request or import a certificate for www.example.com and api.example.com. This chapter does not invent a certificate id. If ACM shows no issued certificate yet, stop and validate the domain before you attach one. The console label may vary.

How port 80 and port 443 divide the work

Two listeners on the internet-facing Application Load Balancer.

Two listeners on one ALB Internet-facing ALB Listener :80 HTTPaction: redirect 301 → :443 Listener :443 HTTPS + ACM P1 api.example.com /v1/* → TG-api P2 www… /images/* → TG-images P10 www… / → TG-web Default → fixed 404 301 Port 80 has no certificate. Smaller priority number is checked first.

Listener :80 only redirects 301 to HTTPS. Listener :443 holds the ACM certificate and rules with priorities 1, 2, 10, then a default fixed 404.

Listener 1 is HTTP on port 80. Its only action is a redirect to HTTPS on port 443, status 301. It has no certificate. It does not forward to a target group.

Listener 2 is HTTPS on port 443. The ACM certificate is attached here only. Its rules, in the order we set:

  1. Host api.example.com AND path /v1/* forwards to TG-api. Priority 1.
  2. Host www.example.com AND path /images/* forwards to TG-images. Priority 2.
  3. Host www.example.com AND path / forwards to TG-web. Priority 10.
  4. Default action: fixed response 404. Forwarding the default to TG-web is the other choice. This example does not do that. An unknown host gets 404.

A request is tested like this.

  1. https://api.example.com/v1/feed matches rule 1 and goes to TG-api on port 8080.
  2. https://www.example.com/images/photo-12.jpg does not match rule 1. It matches rule 2 and goes to TG-images.
  3. https://www.example.com/ does not match rule 1 or rule 2. It matches rule 3 and goes to TG-web.
  4. https://www.example.com/no-such-page matches none of those paths. The default returns 404.
  5. http://www.example.com/images/photo-12.jpg hits listener 1 first and is redirected, 301, to the HTTPS URL. The 443 rules then run.
http → redirect → https → matching rule User :80redirect :443rules TG-api (P1) TG-images (P2) TG-web (P10) Dot hits :80, bounces to :443, then lands on the first matching rule (example: TG-api).

A request hits port 80, bounces to port 443, then lands on the first matching rule.

Priority 1 is checked before priority 10 because 1 is the smaller number. If you give the / rule a smaller number than /images/*, the image path can be stolen by the earlier rule. Read the numbers before you save.

How to add the two listeners

Button names may vary. The balancer is the internet-facing Application Load Balancer.

  1. Open Load Balancers and select the balancer.
  2. Open the Listeners tab.
  3. Add a listener.
  4. Set the protocol to HTTP.
  5. Set the port to 80.
  6. Set the default action to Redirect.
  7. Set the redirect protocol to HTTPS.
  8. Set the redirect port to 443.
  9. Set the status code to 301.
  10. Save.
  11. You should see a listener on port 80 with a redirect action, and no certificate on that row.
  12. Add a second listener.
  13. Set the protocol to HTTPS.
  14. Set the port to 443.
  15. Choose the issued ACM certificate for example.com. If the list is empty, stop. Do not type a made-up certificate name.
  16. Set the default action to Return fixed response.
  17. Set the response code to 404.
  18. Save the listener.
  19. Add rule priority 1: host api.example.com, path /v1/*, forward to TG-api.
  20. Add rule priority 2: host www.example.com, path /images/*, forward to TG-images.
  21. Add rule priority 10: host www.example.com, path /, forward to TG-web.
  22. You should see priorities 1, 2, and 10, with the fixed 404 as the default, not as a numbered rule.

How port 8080 stays off the public balancer

Second listener example. This one is not for users in Pune.

  1. Do not add port 8080 on the internet-facing balancer.
  2. On the internal balancer from section 18.16, add a listener.
  3. Set the protocol to HTTP.
  4. Set the port to 8080.
  5. Forward /health and the API paths to TG-api.
  6. On the security group, allow 8080 only from the web tier security group.
  7. Do not allow 8080 from 0.0.0.0/0.
  8. You should see 8080 on the internal balancer only. A scan of the public DNS name should not find that port open to the world.