Ravindra BagaleCourses & study guides मराठी Track your progress

Chapter 18: Load Balancing

18.5 Target groups

Why a listener needs a list

The load balancer does not store your EC2 instances inside itself. It forwards to a target group. The group is the list of instances, the port, and the health check. When Chapter 17's Auto Scaling group launches an instance, it registers that instance in this list. When the instance is terminated, it leaves the list.

What a target group is

A target group has a name, a protocol, a port, a VPC, and a health check. This lab uses two groups.

Name Instance Port Page you should see
site-a-tg Instance A 80 This is server A, the shop
site-b-tg Instance B 80 This is server B, the api, and /api/ shows api on server B

Health check means the balancer asks the instance for a page on a timer. If the page fails enough times, the instance is unhealthy and receives no new user requests. The other healthy instance still does.

The console default is often an HTTP check on the path /, about every 30 seconds, with a healthy count of 5 and an unhealthy count of 2. Those numbers may vary. A good instance can sit on initial for about two minutes before it says healthy. That wait is the check repeating. It is not a stuck console.

How to create the groups and register the instances

  1. Open the EC2 console.
  2. Open Target Groups.
  3. Choose Create target group.
  4. Choose target type Instances.
  5. Set the name to site-a-tg.
  6. Set the protocol to HTTP and the port to 80.
  7. Select the same VPC as instance A.
  8. Set the health check path to /.
  9. Leave the success code at 200.
  10. Choose Next.
  11. Select instance A.
  12. Confirm the port is 80.
  13. Include it as pending.
  14. Choose Create target group.
  15. Open site-a-tg.
  16. You should see instance A. The health is initial, then healthy. Wait for healthy before you judge the page.
  17. Create site-b-tg the same way.
  18. Register instance B on port 80.
  19. You should see instance B become healthy.

Instance A must allow the check. You will attach the balancer's security group in the next steps. If the health stays unhealthy, the usual cause is port 80 blocked, or Nginx stopped.

  1. SSH to the unhealthy instance.
  2. Run sudo service nginx status.
  3. If it is stopped, run sudo service nginx start.
  4. Run curl -s -o /dev/null -w '%{http_code}\n' http://127.0.0.1/.
  5. You should see 200.

How one listener forwards to a target group

An Application Load Balancer needs subnets in two Availability Zones. The default VPC already has them. The balancer's security group is not the instance security group.

  1. Open Load Balancers.
  2. Choose Create load balancer.
  3. Choose Application Load Balancer.
  4. Set the name to lab-alb.
  5. Choose scheme Internet-facing.
  6. Choose IP type IPv4.
  7. Select the Mumbai VPC.
  8. Select two public subnets in two Availability Zones.
  9. Create a security group named lb-sg that allows inbound HTTP port 80.
  10. On the listener, set protocol HTTP and port 80.
  11. Set the default action to Forward to site-a-tg.
  12. Choose Create load balancer.
  13. Wait until the state is Active.
  14. Copy the DNS name. It looks like lab-alb-123.ap-south-1.elb.amazonaws.com.
  15. Edit the instance security groups.
  16. Allow inbound HTTP port 80 from lb-sg, not only from your own IP.
  17. Wait until site-a-tg shows instance A as healthy.
  18. Open http:// that DNS name in the browser.
  19. You should see This is server A, the shop.
  20. Refresh a few times.
  21. You should still see server A, because this listener's only action is site-a-tg. Instance B is registered in the other group and is not in this forward.

How a path rule sends /api/ to the other group

  1. Open lab-alb.
  2. Open the listener on port 80.
  3. Choose Manage rules or View/edit rules. Button names may vary.
  4. Add a rule.
  5. Add a condition of type Path.
  6. Set the path value to /api/*.
  7. Set the action to Forward to site-b-tg.
  8. Set the priority to 10. A smaller number is checked first. The default action stays last.
  9. Save the rule.
  10. Run curl -s http://ALB-DNS/, using the DNS name you copied.
  11. You should see This is server A, the shop.
  12. Run curl -s http://ALB-DNS/api/.
  13. You should see api on server B.
  14. If you see server A on /api/, the path rule is missing or its priority lost to another rule. Read the rule list again.

The listener picked the group. It did not pick the instance. Instance B is the only member of site-b-tg, so B wins inside that group.