Load Balancer
Operator-managed Layer 4–7 load balancing. Distribute traffic across several backend servers, keep a service available while individual instances fail or are replaced, and give it a public address on the Internet.
Information
A load balancer accepts the traffic, decides which healthy backend should answer, and stops sending requests to one that is not responding. Without it, a published application is only as available as the single instance behind it — and every maintenance window is an outage.
High availability
Active/standby and active/active configurations keep the service reachable when an instance — or the load balancer itself — is lost.
Health monitoring
Continuous probes check each backend. Traffic is withdrawn from a failing server automatically and restored when it recovers.
The public front door
A load balancer on the external network receives the public VIP through which a service is reached from the Internet.
TLS termination
Encrypted traffic can be terminated at the load balancer using a certificate held in Secrets, keeping key material out of the application servers.
Listener types
A listener defines the port and protocol on which the load balancer accepts traffic. Choosing between them is the main design decision: it determines where encryption is terminated and therefore what the load balancer can see and do with the traffic.
| Characteristic | TCP | UDP | HTTP | HTTPS | TERMINATED HTTPS |
|---|---|---|---|---|---|
| Typical port | Any | Any | 80 | 443 | 443 |
| Use case | Generic TCP load balancing — databases, custom applications | UDP-based applications — DNS, VoIP | Web traffic without encryption | Encrypted web traffic, end to end | Encrypted web traffic, decrypted at the load balancer |
| TLS terminated at | Backend | Not applicable | Not encrypted | Backend | Load balancer |
| Certificate managed by | Your servers | None | None | Your servers | Barbican container reference |
| Cookie-based session persistence | No | No | Yes | No | Yes |
| Client IP pass-through | Requires the PROXY protocol (v2) on the listener, and backends that parse the header | ||||