18.5 Target groups
Why a listener needs a list
The load balancer does not store your EC2 instances inside itself. It forwards to a target group. The group is the list of instances, the port, and the health check. When Chapter 17's Auto Scaling group launches an instance, it registers that instance in this list. When the instance is terminated, it leaves the list.
What a target group is
A target group has a name, a protocol, a port, a VPC, and a health check. This lab uses two groups.
| Name | Instance | Port | Page you should see |
|---|---|---|---|
site-a-tg |
Instance A | 80 | This is server A, the shop |
site-b-tg |
Instance B | 80 | This is server B, the api, and /api/ shows api on server B |
Health check means the balancer asks the instance for a page on a timer. If the page fails enough times, the instance is unhealthy and receives no new user requests. The other healthy instance still does.
The console default is often an HTTP check on the path /, about every 30 seconds, with a healthy count of 5 and an unhealthy count of 2. Those numbers may vary. A good instance can sit on initial for about two minutes before it says healthy. That wait is the check repeating. It is not a stuck console.
How to create the groups and register the instances
- Open the EC2 console.
- Open Target Groups.
- Choose Create target group.
- Choose target type Instances.
- Set the name to
site-a-tg. - Set the protocol to HTTP and the port to 80.
- Select the same VPC as instance A.
- Set the health check path to
/. - Leave the success code at 200.
- Choose Next.
- Select instance A.
- Confirm the port is 80.
- Include it as pending.
- Choose Create target group.
- Open
site-a-tg. - You should see instance A. The health is initial, then healthy. Wait for healthy before you judge the page.
- Create
site-b-tgthe same way. - Register instance B on port 80.
- You should see instance B become healthy.
Instance A must allow the check. You will attach the balancer's security group in the next steps. If the health stays unhealthy, the usual cause is port 80 blocked, or Nginx stopped.
- SSH to the unhealthy instance.
- Run
sudo service nginx status. - If it is stopped, run
sudo service nginx start. - Run
curl -s -o /dev/null -w '%{http_code}\n' http://127.0.0.1/. - You should see
200.
How one listener forwards to a target group
An Application Load Balancer needs subnets in two Availability Zones. The default VPC already has them. The balancer's security group is not the instance security group.
- Open Load Balancers.
- Choose Create load balancer.
- Choose Application Load Balancer.
- Set the name to
lab-alb. - Choose scheme Internet-facing.
- Choose IP type IPv4.
- Select the Mumbai VPC.
- Select two public subnets in two Availability Zones.
- Create a security group named
lb-sgthat allows inbound HTTP port 80. - On the listener, set protocol HTTP and port 80.
- Set the default action to Forward to
site-a-tg. - Choose Create load balancer.
- Wait until the state is Active.
- Copy the DNS name. It looks like
lab-alb-123.ap-south-1.elb.amazonaws.com. - Edit the instance security groups.
- Allow inbound HTTP port 80 from
lb-sg, not only from your own IP. - Wait until
site-a-tgshows instance A as healthy. - Open
http://that DNS name in the browser. - You should see
This is server A, the shop. - Refresh a few times.
- You should still see server A, because this listener's only action is
site-a-tg. Instance B is registered in the other group and is not in this forward.
How a path rule sends /api/ to the other group
- Open
lab-alb. - Open the listener on port 80.
- Choose Manage rules or View/edit rules. Button names may vary.
- Add a rule.
- Add a condition of type Path.
- Set the path value to
/api/*. - Set the action to Forward to
site-b-tg. - Set the priority to 10. A smaller number is checked first. The default action stays last.
- Save the rule.
- Run
curl -s http://ALB-DNS/, using the DNS name you copied. - You should see
This is server A, the shop. - Run
curl -s http://ALB-DNS/api/. - You should see
api on server B. - If you see server A on
/api/, the path rule is missing or its priority lost to another rule. Read the rule list again.
The listener picked the group. It did not pick the instance. Instance B is the only member of site-b-tg, so B wins inside that group.