18.6 Routing policy
Why "pick a server" has a name
Once a rule has chosen a target group, the group still has to choose an instance when more than one instance is healthy. That choice is the routing algorithm. Separately, the listener rules choose which group. Students mix these up. The rule runs first. The algorithm runs second, and only inside the group the rule selected.
What the two algorithms are, and what a rule is
On an Application Load Balancer target group you can set the algorithm.
| Algorithm | What it does | When it matters |
|---|---|---|
| Round robin | Each new request goes to the next healthy target, in turn | The default. Two healthy instances share requests one after another |
| Least outstanding requests | The next request goes to the healthy target that currently has fewer requests still in flight | One instance is busy with a slow page, and the other is free |
A listener rule does not replace that algorithm. The rule looks at the host or the path and chooses a target group. Round robin then happens inside that group only.
| Request | Rule that matches | Group | Who can answer |
|---|---|---|---|
http://example.com/ |
Default, or host example.com | site-a-tg |
Instance A, or anyone else you registered there |
http://example.com/api/ |
Path /api/* |
site-b-tg |
Instance B |
http://api.example.com/ |
Host api.example.com |
site-b-tg |
Instance B |
A Network Load Balancer does not use these two HTTP algorithms. For TCP it uses a flow hash. This section's clicks are on the Application Load Balancer groups.
How to see round robin with two instances in one group
- Open
site-a-tg. - Register instance B on port 80 as well, next to instance A. This is temporary.
- Wait until both show healthy.
- Open the group Attributes.
- Set the load balancing algorithm to Round robin.
- Save.
- Run
curl -s http://ALB-DNS/six times, one command per try, not/api/. - You should see server A and server B taking turns, or close to turns. A keep-alive connection can stick for a moment. Open a fresh
curleach time. - Write down how many answers said A and how many said B.
How to switch that group to least outstanding requests
- Open
site-a-tgattributes again. - Set the algorithm to Least outstanding requests.
- Save.
- SSH to instance A.
- Run
yes >/dev/nullso that instance is busy. This is the same idea as the CPU lab in Chapter 17. - From your own computer, run
curl -s http://ALB-DNS/three times. - You should see server B more often, because A has work outstanding.
- On instance A, run
pkill yes. - Open
site-a-tg. - Deregister instance B from
site-a-tgso only instance A remains in that group. - Leave instance B registered only in
site-b-tg. - You should see
/answer from server A again, and/api/still answer from server B.
How a host rule and a path rule choose different groups
You already added the path rule. Add the host rule next to it. Do not delete the path rule.
- Open the port 80 listener rules on
lab-alb. - Add a rule.
- Add a condition of type Host header.
- Set the value to
api.example.com. - Forward to
site-b-tg. - Set the priority to 5, so it is checked before the path rule at 10.
- Save.
- Run
curl -s -H 'Host: example.com' http://ALB-DNS/. - You should see
This is server A, the shop. - Run
curl -s -H 'Host: api.example.com' http://ALB-DNS/. - You should see
This is server B, the api. - Run
curl -s -H 'Host: example.com' http://ALB-DNS/api/. - You should see
api on server B, because the host is notapi.example.com, so the path rule still sends/api/*tosite-b-tg. - If the host rule and the path rule disagree, the smaller priority number wins. Read the numbers on the rule page before you change them.
The Host header is how you test without changing public DNS. A real user gets the same result when api.example.com is a DNS record aimed at this balancer. That record is in Chapter 9. The balancer match is the Host header, not the IP.