AWS ALB/ELB Load Balancing Setup for High-Load Websites

When a website fails under peak load and responds with 502 errors, business loses customers at the most critical moment. We configure load balancing on AWS ALB and ELB turnkey: we conduct an audit, design the architecture, implement, and support the solution. Our team ensures stable operation of your website even during sudden traffic spikes, and the result is reliable infrastructure that scales with your business.

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Our competencies:

Frequently Asked Questions

Latest works

  • Development of a web application for FEEDME
    Development of a web application for FEEDME
    1344
  • Development of an online store for the company FURNORO
    Development of an online store for the company FURNORO
    1307
  • Development of a web application for Enviok
    Development of a web application for Enviok
    1050
  • CRM development for Chasseurs
    CRM development for Chasseurs
    1100
  • Website development for SBH Partners
    Website development for SBH Partners
    1171
  • Website development for Red Pear
    Website development for Red Pear
    596

AWS ALB/ELB Load Balancing Setup

Website crashing under load? 502 errors during peak promotional traffic? We've encountered this in projects with 100k+ RPS. Load balancing with AWS ALB is the standard solution for high-load projects. We configure ALB/ELB turnkey: target groups, listener rules, SSL, Auto Scaling integration. 7+ years of experience, 50+ configured load balancers. Proper ALB configuration is critical for site availability and speed — significant infrastructure savings with competent tuning.

AWS provides managed load balancers without needing to maintain your own server. Application Load Balancer (ALB) works at HTTP/HTTPS level with routing by path and headers. Network Load Balancer (NLB) — L4 TCP/UDP with minimal latency. Classic ELB is deprecated and not recommended for new projects.

Why Choose ALB over NLB?

ALB is better than NLB for HTTP/HTTPS: it supports intelligent routing, WAF integration, and static content delivery. NLB is indispensable for TCP services requiring static IPs and minimal latency. If you have a React/Vue web application or Node.js API — choose ALB. For GameServer or VoIP — NLB. We often combine them: ALB for web, NLB for WebSocket.

Characteristic ALB (L7) NLB (L4)
Protocols HTTP/HTTPS/gRPC TCP/UDP/TLS
Routing by path, header, host none
WAF integration yes no
Static IP no yes (via Elastic IP)
Latency ~2-5 ms <1 ms
Target groups EC2, ECS, Lambda, IP EC2, IP, ALB

How ALB Works with Auto Scaling?

Attach an ALB target group to an Auto Scaling Group. When scaling, new instances automatically register and start receiving traffic. ALB health check (path /health, threshold of 2 successful responses) determines when the instance is ready to accept requests. This ensures zero-downtime deployment. For critical services we use target groups with deregistration_delay of 30 seconds to allow in-flight requests to complete.

Step-by-Step ALB Setup via Terraform

  1. Create an ALB with security groups and subnets.
  2. Configure HTTPS listener with ACM certificate and HTTP redirect.
  3. Define target groups with health check and stickiness.
  4. Add listener rules for routing by paths, headers, or hosts.
  5. Attach target group to your service (EC2, ECS, Lambda).
  6. Enable access logs and monitoring.

Full configuration example below.

Application Load Balancer

ALB is the standard choice for web applications. Routes by path, host, HTTP headers, method, query string. Integrates with ECS, EKS, Lambda, Auto Scaling Groups. Below is a complete configuration with AWS ALB, routing, and ACM.

# Terraform: полная конфигурация ALB + routing + ACM
resource "aws_lb" "main" {
  name = "myapp-alb"
  internal = false
  load_balancer_type = "application"
  security_groups = [aws_security_group.alb.id]
  subnets = aws_subnet.public[*].id
  enable_deletion_protection = true
  enable_cross_zone_load_balancing = true
  drop_invalid_header_fields = true
  access_logs {
    bucket = aws_s3_bucket.alb_logs.bucket
    prefix = "alb"
    enabled = true
  }
  tags = {
    Name = "myapp-alb"
  }
}

# HTTPS Listener
resource "aws_lb_listener" "https" {
  load_balancer_arn = aws_lb.main.arn
  port = 443
  protocol = "HTTPS"
  ssl_policy = "ELBSecurityPolicy-TLS13-1-2-2021-06"
  certificate_arn = aws_acm_certificate.main.arn
  default_action {
    type = "forward"
    target_group_arn = aws_lb_target_group.web.arn
  }
}

# HTTP → HTTPS redirect
resource "aws_lb_listener" "http" {
  load_balancer_arn = aws_lb.main.arn
  port = 80
  protocol = "HTTP"
  default_action {
    type = "redirect"
    redirect {
      port = "443"
      protocol = "HTTPS"
      status_code = "HTTP_301"
    }
  }
}

# Target Group для веб-приложения
resource "aws_lb_target_group" "web" {
  name = "myapp-web-tg"
  port = 8080
  protocol = "HTTP"
  vpc_id = aws_vpc.main.id
  target_type = "ip" # для ECS Fargate
  health_check {
    enabled = true
    path = "/health"
    healthy_threshold = 2
    unhealthy_threshold = 3
    timeout = 5
    interval = 10
    matcher = "200"
  }
  deregistration_delay = 30
  stickiness {
    type = "lb_cookie"
    cookie_duration = 86400
    enabled = false
  }
}

# API Target Group
resource "aws_lb_target_group" "api" {
  name = "myapp-api-tg"
  port = 3000
  protocol = "HTTP"
  vpc_id = aws_vpc.main.id
  health_check {
    path = "/api/health"
    matcher = "200"
  }
}

# Правила маршрутизации
resource "aws_lb_listener_rule" "api" {
  listener_arn = aws_lb_listener.https.arn
  priority = 10
  action {
    type = "forward"
    target_group_arn = aws_lb_target_group.api.arn
  }
  condition {
    path_pattern {
      values = ["/api/*"]
    }
  }
}

# Маршрут по заголовку (версионирование API)
resource "aws_lb_listener_rule" "api_v2" {
  listener_arn = aws_lb_listener.https.arn
  priority = 5
  action {
    type = "forward"
    target_group_arn = aws_lb_target_group.api_v2.arn
  }
  condition {
    http_header {
      http_header_name = "X-API-Version"
      values = ["2", "2.0"]
    }
  }
}

# Weighted forwarding для Canary deployments
resource "aws_lb_listener_rule" "canary" {
  listener_arn = aws_lb_listener.https.arn
  priority = 20
  action {
    type = "forward"
    forward {
      target_group {
        arn = aws_lb_target_group.web_stable.arn
        weight = 95
      }
      target_group {
        arn = aws_lb_target_group.web_canary.arn
        weight = 5
      }
      stickiness {
        enabled = true
        duration = 3600
      }
    }
  }
  condition {
    path_pattern {
      values = ["/*"]
    }
  }
}

# Сертификат ACM
resource "aws_acm_certificate" "main" {
  domain_name = "example.com"
  subject_alternative_names = ["*.example.com"]
  validation_method = "DNS"
  lifecycle {
    create_before_destroy = true
  }
}

resource "aws_route53_record" "cert_validation" {
  for_each = {
    for dvo in aws_acm_certificate.main.domain_validation_options : dvo.domain_name => {
      name = dvo.resource_record_name
      record = dvo.resource_record_value
      type = dvo.resource_record_type
    }
  }
  zone_id = aws_route53_zone.main.zone_id
  name = each.value.name
  type = each.value.type
  ttl = 60
  records = [each.value.record]
}

resource "aws_acm_certificate_validation" "main" {
  certificate_arn = aws_acm_certificate.main.arn
  validation_record_fqdns = [for record in aws_route53_record.cert_validation : record.fqdn]
}

ALB + WAF

We integrate WAF for protection against OWASP top-10 and rate limiting.

resource "aws_wafv2_web_acl_association" "alb" {
  resource_arn = aws_lb.main.arn
  web_acl_arn = aws_wafv2_web_acl.main.arn
}

resource "aws_wafv2_web_acl" "main" {
  name = "myapp-waf"
  scope = "REGIONAL"

  default_action {
    allow {}
  }

  rule {
    name = "AWSManagedRulesCommonRuleSet"
    priority = 1

    override_action {
      none {}
    }

    statement {
      managed_rule_group_statement {
        name = "AWSManagedRulesCommonRuleSet"
        vendor_name = "AWS"
      }
    }

    visibility_config {
      cloudwatch_metrics_enabled = true
      metric_name = "CommonRuleSet"
      sampled_requests_enabled = true
    }
  }

  rule {
    name = "RateLimit"
    priority = 2

    action {
      block {}
    }

    statement {
      rate_based_statement {
        limit = 2000
        aggregate_key_type = "IP"
      }
    }

    visibility_config {
      cloudwatch_metrics_enabled = true
      metric_name = "RateLimit"
      sampled_requests_enabled = true
    }
  }

  visibility_config {
    cloudwatch_metrics_enabled = true
    metric_name = "MyAppWAF"
    sampled_requests_enabled = true
  }
}

ALB + ECS Fargate

Example of ALB integration with Fargate: the service automatically registers in the target group.

resource "aws_ecs_service" "app" {
  name = "myapp-web"
  cluster = aws_ecs_cluster.main.id
  task_definition = aws_ecs_task_definition.app.arn
  desired_count = 3
  launch_type = "FARGATE"

  network_configuration {
    subnets = aws_subnet.private[*].id
    security_groups = [aws_security_group.app.id]
    assign_public_ip = false
  }

  load_balancer {
    target_group_arn = aws_lb_target_group.web.arn
    container_name = "web"
    container_port = 8080
  }

  deployment_circuit_breaker {
    enable = true
    rollback = true
  }

  deployment_controller {
    type = "ECS"
  }

  depends_on = [aws_lb_listener.https]
}

Network Load Balancer

NLB for TCP/UDP with static IPs and minimal latency.

resource "aws_lb" "nlb" {
  name = "myapp-nlb"
  internal = false
  load_balancer_type = "network"
  subnets = aws_subnet.public[*].id
  enable_cross_zone_load_balancing = true
}

resource "aws_lb_listener" "nlb_tls" {
  load_balancer_arn = aws_lb.nlb.arn
  port = 443
  protocol = "TLS"
  ssl_policy = "ELBSecurityPolicy-TLS13-1-2-2021-06"
  certificate_arn = aws_acm_certificate.main.arn
  default_action {
    type = "forward"
    target_group_arn = aws_lb_target_group.nlb_tcp.arn
  }
}

resource "aws_lb_target_group" "nlb_tcp" {
  name = "myapp-nlb-tg"
  port = 8080
  protocol = "TCP"
  vpc_id = aws_vpc.main.id
  health_check {
    protocol = "HTTP"
    path = "/health"
    healthy_threshold = 2
    unhealthy_threshold = 2
    interval = 10
  }
}

Monitoring ALB

Key CloudWatch metrics: RequestCount, ActiveConnectionCount, TargetResponseTime (p50/p95/p99), HTTPCode_ELB_5XX_Count, HealthyHostCount, UnHealthyHostCount. We set up alerts for 5xx and high latency.

resource "aws_cloudwatch_metric_alarm" "target_5xx" {
  alarm_name          = "alb-5xx-errors"
  comparison_operator = "GreaterThanThreshold"
  evaluation_periods  = 2
  metric_name         = "HTTPCode_Target_5XX_Count"
  namespace           = "AWS/ApplicationELB"
  period              = 60
  statistic           = "Sum"
  threshold           = 10
  alarm_actions       = [aws_sns_topic.alerts.arn]
  dimensions = {
    LoadBalancer = aws_lb.main.arn_suffix
  }
}

resource "aws_cloudwatch_metric_alarm" "latency" {
  alarm_name          = "alb-high-latency"
  comparison_operator = "GreaterThanThreshold"
  evaluation_periods  = 3
  metric_name         = "TargetResponseTime"
  namespace           = "AWS/ApplicationELB"
  period              = 60
  extended_statistic  = "p95"
  threshold           = 2.0
  alarm_actions       = [aws_sns_topic.alerts.arn]
  dimensions = {
    LoadBalancer = aws_lb.main.arn_suffix
  }
}

What's Included in the Work

  • Load balancing design: type selection (ALB/NLB), network scheme.
  • Terraform code with target groups, listener rules, ACM, WAF.
  • Monitoring and alert setup.
  • Integration with CI/CD and Auto Scaling.
  • Operations documentation and team training.

Implementation Timelines

Configuration Timeline
ALB + Target Group + HTTPS 1–2 days
Path/header routing +1 day
WAF + rate limiting +1–2 days
Canary deployment via weighted forwarding +1 day
Full Terraform configuration with monitoring 3–5 days

Typical Configuration Mistakes

  • Health check not configured — instances receive traffic before readiness.
  • Deletion protection missing — accidental ALB deletion.
  • Incorrect SSL policy — vulnerabilities.
  • Click-through on WAF — managed rules not enabled.

We guarantee stability and performance. Get a consultation on ALB setup for your project. Contact us — we'll estimate timelines for your case. AWS ALB Documentation can help delve deeper into capabilities.