Skip to main content

Load Balancer

Operator-managed Layer 4–7 load balancing. Distribute traffic across several backend servers, keep a service available while individual instances fail or are replaced, and give it a public address on the Internet.


Information​

A load balancer accepts the traffic, decides which healthy backend should answer, and stops sending requests to one that is not responding. Without it, a published application is only as available as the single instance behind it — and every maintenance window is an outage.

High availability

Active/standby and active/active configurations keep the service reachable when an instance — or the load balancer itself — is lost.

Health monitoring

Continuous probes check each backend. Traffic is withdrawn from a failing server automatically and restored when it recovers.

The public front door

A load balancer on the external network receives the public VIP through which a service is reached from the Internet.

TLS termination

Encrypted traffic can be terminated at the load balancer using a certificate held in Secrets, keeping key material out of the application servers.


Listener types​

A listener defines the port and protocol on which the load balancer accepts traffic. Choosing between them is the main design decision: it determines where encryption is terminated and therefore what the load balancer can see and do with the traffic.

Characteristic
TCP
UDP
HTTP
HTTPS
TERMINATED
HTTPS
Typical portAnyAny80443443
Use caseGeneric TCP load balancing — databases, custom applicationsUDP-based applications — DNS, VoIPWeb traffic without encryptionEncrypted web traffic, end to endEncrypted web traffic, decrypted at the load balancer
TLS terminated atBackendNot applicableNot encryptedBackendLoad balancer
Certificate managed byYour serversNoneNoneYour serversBarbican container reference
Cookie-based session persistenceNoNoYesNoYes
Client IP pass-throughRequires the PROXY protocol (v2) on the listener, and backends that parse the header

Usage​