18.14 Different HTTP listeners
Why a balancer listens on more than one port
A listener is the front socket. People on the internet type https://www.example.com, which is port 443. Old links and health tools still call port 80. If you only open 443, the http:// link fails instead of moving the user to HTTPS. If you only open 80, the password and the cookie cross the network in clear text.
A third port, 8080, is for a check or an admin path that must not be reachable from the internet. That listener belongs on the internal balancer in section 18.16. It does not belong on the internet-facing balancer. Opening 8080 to the world would undo that later section.
What a listener is
A listener is four things:
- A protocol, HTTP or HTTPS.
- A port, such as 80, 443, or 8080.
- A default action, used when no rule matches.
- Rules, checked in order. The smaller priority number is first. The first match wins. Later rules are not tried.
The certificate sits on the HTTPS listener only. Port 80 has no certificate. Amazon Certificate Manager (ACM) is the place you request or import a certificate for www.example.com and api.example.com. This chapter does not invent a certificate id. If ACM shows no issued certificate yet, stop and validate the domain before you attach one. The console label may vary.
How port 80 and port 443 divide the work
Two listeners on the internet-facing Application Load Balancer.
Listener :80 only redirects 301 to HTTPS. Listener :443 holds the ACM certificate and rules with priorities 1, 2, 10, then a default fixed 404.
Listener 1 is HTTP on port 80. Its only action is a redirect to HTTPS on port 443, status 301. It has no certificate. It does not forward to a target group.
Listener 2 is HTTPS on port 443. The ACM certificate is attached here only. Its rules, in the order we set:
- Host
api.example.comAND path/v1/*forwards toTG-api. Priority 1. - Host
www.example.comAND path/images/*forwards toTG-images. Priority 2. - Host
www.example.comAND path/forwards toTG-web. Priority 10. - Default action: fixed response 404. Forwarding the default to
TG-webis the other choice. This example does not do that. An unknown host gets 404.
A request is tested like this.
https://api.example.com/v1/feedmatches rule 1 and goes toTG-apion port 8080.https://www.example.com/images/photo-12.jpgdoes not match rule 1. It matches rule 2 and goes toTG-images.https://www.example.com/does not match rule 1 or rule 2. It matches rule 3 and goes toTG-web.https://www.example.com/no-such-pagematches none of those paths. The default returns 404.http://www.example.com/images/photo-12.jpghits listener 1 first and is redirected, 301, to the HTTPS URL. The 443 rules then run.
A request hits port 80, bounces to port 443, then lands on the first matching rule.
Priority 1 is checked before priority 10 because 1 is the smaller number. If you give the / rule a smaller number than /images/*, the image path can be stolen by the earlier rule. Read the numbers before you save.
How to add the two listeners
Button names may vary. The balancer is the internet-facing Application Load Balancer.
- Open Load Balancers and select the balancer.
- Open the Listeners tab.
- Add a listener.
- Set the protocol to HTTP.
- Set the port to 80.
- Set the default action to Redirect.
- Set the redirect protocol to HTTPS.
- Set the redirect port to 443.
- Set the status code to 301.
- Save.
- You should see a listener on port 80 with a redirect action, and no certificate on that row.
- Add a second listener.
- Set the protocol to HTTPS.
- Set the port to 443.
- Choose the issued ACM certificate for example.com. If the list is empty, stop. Do not type a made-up certificate name.
- Set the default action to Return fixed response.
- Set the response code to 404.
- Save the listener.
- Add rule priority 1: host
api.example.com, path/v1/*, forward toTG-api. - Add rule priority 2: host
www.example.com, path/images/*, forward toTG-images. - Add rule priority 10: host
www.example.com, path/, forward toTG-web. - You should see priorities 1, 2, and 10, with the fixed 404 as the default, not as a numbered rule.
How port 8080 stays off the public balancer
Second listener example. This one is not for users in Pune.
- Do not add port 8080 on the internet-facing balancer.
- On the internal balancer from section 18.16, add a listener.
- Set the protocol to HTTP.
- Set the port to 8080.
- Forward
/healthand the API paths toTG-api. - On the security group, allow 8080 only from the web tier security group.
- Do not allow 8080 from
0.0.0.0/0. - You should see 8080 on the internal balancer only. A scan of the public DNS name should not find that port open to the world.