17 ms·
AWS Application Load Balancer
- rjsamson 10y agoThey finally added support for websockets! Really looking forward to giving this a try with Phoenix.
- bas 10y agoI just did a little dance at my desk.
- pgtruesdell 10y agoSame here, can't wait to start using WS and HTTP/2 without extra work involved.
- Swennemans 10y agoCurious, why would you combine this with Phoenix?
- sjtgraham 10y agoBecause Phoenix has a WS abstraction (Channels) and supports it out of the box.
- Swennemans 10y agoYes but isn't one of Elixir's strenghts that it scales very well on a single machine? Why do we need the load balancing?
- iEchoic 10y agoEvery backend architecture should account for having multiple machines. What are you going to do once you get enough traffic that one machine can't handle it?
- 0xmohit 10y agoAWS still doesn't support IPv6. Good to see them talking about HTTP/2. Waiting for AWS to embrace IPv6.
- jeffbarr 10y agoThat's my post, and my misunderstanding. I'll clean it up now, thanks!
- 0xmohit 10y agoThose underlined headers hurt the eyes. Could you please switch to a different heading style, please? Maybe smallcaps? EDIT: And while you're listening: AWS documentation is a mess in the sense that it's way too unorganized; it might be documented but one cannot find it easily.
- 0xmohit 10y agoBTW, is there any place to log feature requests?
- johns 10y agoBecome a big enough customer
- bashtoni 10y agoI run an AWS partner who deals with many large ($millions a year each but not tens of millions each) aws customers. It seems like the number of customers asking for a feature is more important than the size of those customers in my experience.
- gerhardhaering 10y agoWe have the AWS Business support plan. If you have it, you can file feature requests using the support interface.
- rajivm 10y ago
- nodesocket 10y agoSo what would be a use case for using ELBs now? Seems like ALBs do everything ELBs do, but with websocket and HTTP/2 support.
- kronin 10y agoIf your security requirements are such that AWS can't terminate TLS would be one reason.
- caleblloyd 10y agoAlso if you're load balancing any other application protocol other than HTTP/HTTPS. (e.g. SMTP load balancer)
- deleted 10y ago[deleted]
- Thaxll 10y agoPricing is different.
- dexterdog 10y agoIf you're using classic (non-VPC) you have to use classic ELBs.
- lsaferite 10y agoIs there a benefit to using 'Classic'?
- dexterdog 10y agoIf your setup worked under classic you didn't have to setup your VPC and worry about internet gateways and routing all of that stuff. It is better to use VPC and if you have a newer account and in fact you don't even get the option, but some of us have instances that have been running without issue for 7 years and don't want to reconfigure what is working.
- archgrove 10y agoAny love for Elastic Beanstalk with these? They seem well matched. Though EB always feels a bit of a red-headed stepchild in the AWS portfolio.
- bpicolo 10y agoI love elastic beanstalk (minus it's mediocre docs). Agreed here, does elastic beanstalk support setup of new-style elbs (without me doing extensive customization)? When will it if not?
- jeffbarr 10y agoElastic Beanstalk supports ALB.
- agwa 10y ago> 25 connections/second with a 2 KB certificate, 3,000 active connections, and 2.22 Mbps of data transfer or >5 connections/second with a 4 KB certificate, 3,000 active connective, and 2.22 Mbps of data transfer. "2KB certificate" and "4KB certificate"? Is this supposed to read "2048 bit RSA" and "4096 bit RSA"?
- creshal 10y agoMost likely, yes.
- avitzurel 10y agoThis is very good. Recently my workflow has been ELB -> NGINX -> Cluster. Nginx was a cluster of machines that did routing based on rules into the ec2 machines. Now that the AELB has some of those capabilities it's time to evaluate it.
- manishsharan 10y agoThis is definitely nicer than having to create subdomains for microservices and mapping each subdomain url to its own Elastic Loaad Balancer + Elastic Beanstalk instance. But I have already gone down this path so I am unlikely to use AWS Application Load balancer. I wish I had this option a year ago.
- nodesocket 10y agoDo ALBs support more than a single SSL certificate?
- pat2man 10y agoLike via SNI? No mention of it and the screenshots make it seem unlikely.
- pgib 10y agoThe Amazon Certificate Manager uses SNI, and you can request certificates with multiple hosts and even wildcard domains. I would imagine if you upload your own multi-domain certificate that it would work in the same way, but I have never tested that.
- imperalix 10y agoI think you mean SAN instead of SNI. SNI is like host headers for TLS connections, while SAN on certs allow you have to very valid for multiple names.
- koolba 10y agoIf the top level is the same you can use a wildcard (*.example.com) cert.
- pyre 10y agoYou're missing the use-case where you want to use a wildcard certificate and an EV certificate. You can't get an EV wildcard certificate.
- koolba 10y ago> You're missing the use-case where you want to use a wildcard certificate and an EV certificate. You can't get an EV wildcard certificate. Yes that's not possible as EV certs are not issue for wildcards. My counter is that EV certs are for chumps and the entire concept is a scamola. The only justification I'd accept for getting one is proper A/B testing that an EV cert lead to increased revenue. There's no inherent security argument for them.
- kookster 10y agoAs a heavy ECS user, all I can say is thank you, finally!
- leetrout 10y agoWhat are you using for configuration / orchestration of both the container servers and the tasks? CF? Terraform?
- nzoschke 10y agoTake a look at Convox as a fast way to bootstrap managing instances, ECS, and load balancers via CloudFormation. We have ALB working already. https://github.com/convox/rack/pull/1045 https://github.com/convox/rack/pull/1045 Disclaimer: I work on Convox.
- indale 10y agoThis looks pretty sweet. The next big thing for api versioning would be header instead of url based routing, looking forward to 'give you access to other routing methods'.
- mattlong 10y agoAlready has it! "An Application Load Balancer has access to HTTP headers and allows you to route requests to different backend services accordingly." Edit: On a second read, it's less clear if header based routing is actually available yet...
- cheald 10y agoIt only allows you to route via path matching right now. "each Application Load Balancer allows you to define up to 10 URL-based rules to route requests to target groups. Over time, we plan to give you access to other routing methods." The ALB clearly has technical access to the headers, but use of them isn't exposed to users yet.
- ihsw 10y agoCan we agree on the terminology for Application Load Balancer and Elastic Load Balancer? * ALB: Application Load Balancer * ELB: Elastic Load Balancer I have seen Application Elastic Load Balancer/AELB, Classic Load Balancer/CLB, Elastic Load Balancer (Classic)/ELBC, Elastic Load Balancer (Application)/ELBA. In any event, I think it is great that AWS is bringing WebSockets and HTTP/2 to the forefront of web technology.
- mdani 10y agoIn my opinion, it is HTTP and WS LB rather than Application LB as it supports just two protocols. In contrast, if you look at F5 load balancer, it can look at LDAP packets or Diameter packets and do a L7 load bakancing. So ALB seems misleading terminology to me as HTTP and WS != All L7 applications
- awj 10y agoJudging by how Amazon has handled other things, I wouldn't stick too hard to that conclusion. They tend to focus first on something generally useful and easy then come back to fill in more difficult/less popular options over time.
- nailer 10y agoNice haproxy / nginx alternative. It's got http2 support though which puts it ahead of haproxy.
- KenCochrane 10y agoI wouldn't consider this a full haproxy/nginx replacement just yet. It doesn't support host based routing, so you would need a different ALB for each host in order to get the same thing you would get with haproxy/nginx.
- cheald 10y agoExciting! Disappointing that you can't route based on hostname yet, though. I've got 5 ELBs set up to route to different microservices for one app, and because we couldn't do path-based routing before, that's all segmented by hostname. As soon as ALB supports hostname routing, I can collapse those all into a single LB.
- snug 10y agoThe "Hostname" is in the HTTP Header, "Host." The article states that you can route based on Layer 7 headers, so this shouldn't be an issue.
- cheald 10y agoYeah, but they only allow you to route via path matching right now. The ALB has access to the headers, but configuring it based on arbitrary headers isn't exposed to end users yet. I excitedly set up an ALB as soon as I read the post, because I've needed it, only to find that support for what I want isn't available to me yet!
- bgentry 10y agoThe article actually just states that layer 7 load balancers have access to the header information and typically allow you to route based on those headers. ALB, however, doesn't :( Weird thing to highlight when the product being announced doesn't even have that feature.
- sturgill 10y agoThis sentence sums up one of my main reasons for appreciating AWS: The hourly rate for the use of an Application Load Balancer is 10% lower than the cost of a Classic Load Balancer. They frequently introduce new features while cutting costs.
- nivertech 10y agono, they replaced bandwidth costs with new pricing component $0.008 per LCU-hour[1]. If you have 1M idle websocket connections you will pay 100 times more for ALB vs ELB (i.e. $2K/mo vs $18/mo). Good thing ELB is still here, so you can choose between them depending on your workload. [1] LCU - Load Balancer Capacity Units https://aws.amazon.com/elasticloadbalancing/applicationloadbalancer/pricing/ https://aws.amazon.com/elasticloadbalancing/applicationloadb...
- sturgill 10y agoI don't believe classic ELB supports websockets[1] making this a tenuous comparison. There might be workarounds that I'm not aware of (our production network isn't currently on AWS so I'm a couple of years behind in my day-to-day experience with them). That said, I don't dispute that there might be use cases where classic ELB is a better option. And I'm glad it's still available (as opposed to ALB replacing classic). [1]https://aws.amazon.com/elasticloadbalancing/classicloadbalancer/faqs/ https://aws.amazon.com/elasticloadbalancing/classicloadbalan...
- nivertech 10y agoit supports any TCP-based protocol, like websockets or MQTT, similar to Network LB on GCE.
- encoderer 10y agoWe plan to do a blog post about this at some point, but we had the pleasure of seeing exactly how elastic the elb is when we switched Cronitor from linode to aws in February 2015. Requisite backstory: Our api traffic comes from jobs, daemons, etc, which tend to create huge hot spots at tops of each minute, quarter hour, hour and midnight of popular tz offsets like UTC, us eastern, etc. There is an emergent behavior to stacking these up and we hit peak traffic many many times our resting baseline. At the time, our median ping traffic was around 8 requests per second, with peaks around 25x that. What's unfortunate is that in the first day after setting up the elb we didn't have problems, but soon after we started getting reports of intermittent downtime. On our end our metrics looked clean. The elb queue never backed up seriously according to cloud watch. But when we started running our own healthchecks against the elb we saw what our customers had been reporting: in the crush of traffic at the top of the hour connections to the elb were rejected despite the metrics never indicating a problem. Once we saw the problem ourselves it seemed easy to understand. Amazon is provisioning that load balancer elastically and our traffic was more power law than normal distribution. We didn't have high enough baseline traffic to earn enough resources to service peak load. So, cautionary tale of dont just trust the instruments in the tin when it comes to cloud iaas -- you need your own. It's understandable that we ran into a product limitation, but unfortunate that we were not given enough visibility to see the obvious problem without our own testing rig.
- MrMullen 10y agoThis is actually fairly common. ELB scales up as your traffic scales up but it can not handle tsunami levels of traffic. It can only handle incremental level increases of traffic. You have to contact Amazon support to get them to fix your ELB at a larger instance for the entire life of the instance. One the major down sides of Amazon AWS.
- bgentry 10y agoI was coming here to ask whether pre-warming is still an issue with the ALB service. Maybe jeffbarr can comment on whether that's changed? GCE's load balancer does not use independent VM instances for each load balancer, instead balancing at the network level. So you can instantly scale from 0 to 1M req/s with no issues at all.
- boundlessdreamz 10y agoSo this is pretty much the same as Google HTTP load balancing https://cloud.google.com/compute/docs/load-balancing/http/ https://cloud.google.com/compute/docs/load-balancing/http/ + websocket & http2?
- manigandham 10y agoGoogle's load balancer does do HTTP/2. It doesnt have native websocket protocol support (you have to use the network LB for that traffic) but it does provide cross-region balancing.
- thesandlord 10y agoWebsockets over SSL is in beta: https://cloud.google.com/compute/docs/load-balancing/tcp-ssl/ https://cloud.google.com/compute/docs/load-balancing/tcp-ssl...
- manigandham 10y agoYes, saw that, but it requires setting up a whole new LB just for websockets. It would be nice if it was just a natively supported protocol on the existing HTTPS LBs, is there a reason why that cant be done?
- advisedwang 10y agoIt sounds like ALB is still regional whereas Google's LB is global.
- erikcw 10y agoI'm curious if this will Convox to route to multiple services with just a single ALB instead of the historical default of 1 ELB per service. Would be a real cost savings for a micro-services architecture.
- bgentry 10y agoIt should allow Convox to do that, yes. Although it doesn't appear (from the screenshots) that you can route by Host header, so you'd have to put all your services on the same hostname with different path prefixes to make it work.
- ddollar 10y agoWe've got some changes coming along these lines. Looks like we might also be able to use CloudFront for hostname routing.
- merb 10y agoVirtual Host Load Balancer would be great.
- deleted 10y ago[deleted]
- axelfontaine 10y agoIt looks like the big missing piece is auto-scaling groups as target groups...
- azylman 10y agoIt looks like it supports ECS services as target groups, and ECS services can do auto-scaling.
- M2Ys4U 10y agoNot much help if your services aren't containerised though
- axelfontaine 10y agoUpdate: seems to be supported after all http://docs.aws.amazon.com/AutoScaling/latest/APIReference/API_AttachLoadBalancerTargetGroups.html http://docs.aws.amazon.com/AutoScaling/latest/APIReference/A...
- tobz 10y agoThe real question: does this provide a faster elasticity component than ELBs? At a previous employer, we punted on ever using ELBs at the edge because our traffic was just too unpredictable. Combining together all of the internet rumors, I've been led to believe that ELBs were/are custom software running on simple EC2 instances in an ASG or something, hence being relatively slow to respond to traffic spikes. Given that ALBs are metered, it seems like this suggests shared infrastructure (binpacking peoples ALBs onto beefy machines) which makes me wonder if that is how it actually works now, because it would seem the region/AZ-level elasticity of ALBs could actually help the elasticity of a single ALB. If you don't have to spin up a brand new machine, but simply configure another to start helping out, or spin up a container on another which launches faster than an EC2 instance... that'd be clutch. Deep thoughts?
- bradavogel 10y agoDoes anyone know if it (finally) supports sticky websocket sessions?
- buzzdenver 10y agoWhat is that ?
- zob_cloud 10y agoYes they do. For a single connection the websocket will always go to the same back end regardless of sticky sessions being enabled. If stickyness is enabled, and the same client creates a new websocket, it will go to the same back end as previous connections.
- renaudg 10y agoWhere is this documented officially ? There's very little mention of Websockets in the guides, and none at all in the ALB creation wizard, which I didn't find reassuring.
- iEchoic 10y agoThis isn't working for me, I'm not getting an upgrade header back from the server, it just stalls. Hm. Did you have to do anything special to get this to work?
- amasad 10y agoI wonder if they fixed the routing algorithm for TCP connections. It's round-robin on ELB, which is performs terribly for long lasting connections.
- dblooman 10y agoIt seems that routing is done in the following way /API/* goes to applications and expects :8080/api/ rather than the root. Would be nice to have the option to direct traffic to just :8080.
- brianwawok 10y agoWhat client webserver can't handle this though?
- DonFizachi 10y agoAny idea if sticky TCP sessions will be supported on ELB/ALB any time soon?
- daigoba66 10y agoThese new features are cool... but they still pale in comparison to something like HAProxy. I guess the tradeoff is that with ELB/ALB, like most PaaS, you don't have to "manage" your load balancer hosts. And it's probably cheaper than running an HAProxy cluster on EC2. But for the power you get with HAProxy, is it worth it? Does anyone have experience running HAProxy on EC2 at large scale?
- jdub 10y agoELB is HAproxy. :-) Sure, you get a lot of flexibility configuring HAproxy yourself, but you also have to run it yourself. 90% of the time it's easier to just use ELB (plus it has some direct integration with other services, like IAM-stored server certs/keys, ASG, etc). I have swapped out ELB for HAproxy and/or nginx on a couple of occasions. If you know your load and feature requirements intimately, you might be able to do a better job. But it's work.
- NeckBeardPrince 10y agoAny idea if it's HIPPA compliant?
- dpessis 10y agoCustomers with an AWS Business Associate Agreement (BAA) can use Application Load Balancer and Classic Load Balancer following the configuration obligations in the BAA. Since Application Load Balancer and Classic Load Balancer are features of an existing HIPAA Eligible Service, Elastic Load Balancing, no changes to the AWS BAA are required.
- fred256 10y ago+1 for CloudFormation support on launch day. +1 for support for ECS services with dynamic ports (finally!) -1 for no CloudFormation support for ECS (To configure an ECS service to use an ALB, you need to set a Target Group ARN in the ECS service, which is not exposed by CloudFormation)
- nzoschke 10y agoThanks for sharing the info. We're using CloudFormation and ECS heavily for Convox, and just can't get off a CloudFormation custom handler (Lambda func) for managing ECS task definitions and services for small reasons like this.
- deleted 10y ago[deleted]
- chris47493 10y agoLooks like you can set the Target Group ARN in the LoadBalancers property group now http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-ecs-service-loadbalancers.html http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuid...
- shawn-butler 10y agoAnybody know whether the new ALB handles a client TLS (SSL) when operating in http mode? I was trying secure an API Gateway backend using a client certificate but found ELB doesn't currently support client side certificates when operating in http mode. There was this complicated Lambda proxy workaround solution but I gave up halfway through... https://aws.amazon.com/blogs/compute/using-api-gateway-with-vpc-endpoints-via-aws-lambda/ https://aws.amazon.com/blogs/compute/using-api-gateway-with-...
- joneholland 10y agoDisappointing. I was hoping they were launching a service discovery stack to compliment ECS.
- renaudg 10y agoI'm the process of containerizing an app that includes a Websockets service, and given ECS / ELB limitations we'd just decided to go for Kubernetes as the orchestration layer. This ALB announcement + the nicer ECS integration could tip the balance though. Any thoughts on how likely it is that Kubernetes can/will take advantage of ALBs (as Ingress objects I suppose) soon ?