如何为同一VPC内的两个集群配置AWS应用负载均衡器(ALB)?
Absolutely, you can use a single Application Load Balancer (ALB) for two clusters in the same VPC—this is a common, supported pattern in AWS. The random routing you're seeing right now isn't a limitation of the service; it's just a result of missing targeted routing configuration.
Why Your Traffic Is Randomly Routing
Your current setup is probably registering instances from both Cluster A and Cluster B into the same target group. ALBs distribute traffic evenly across all healthy targets in a single group by default, which explains why requests are bouncing between your two clusters. The fix is to split your targets into separate groups and use listener rules to direct traffic intentionally.
Step-by-Step Correct Configuration
Here's how to set this up properly:
Create Separate Target Groups for Each Cluster
- Head to the EC2 Console > Target Groups > Create target group
- For Cluster A, make a unique target group (e.g.,
tg-cluster-a), register its instances/IPs, and configure health checks to match your cluster's service health endpoint (like/healthon port 8080). - Repeat for Cluster B with a distinct target group (e.g.,
tg-cluster-b). Ensure both groups use the same VPC as your clusters. - Pro Tip: If you're using ECS or EKS, enable IP-based target registration (instead of instance-based) for better flexibility with containerized workloads.
Configure ALB Listener Rules to Route Traffic
- Go to your ALB's listeners (e.g., HTTP on port 80 or HTTPS on port 443)
- Add custom rules to direct traffic to the right target group based on your needs:
- Host Header Matching: Route
app-a.yourdomain.comtotg-cluster-aandapp-b.yourdomain.comtotg-cluster-b(perfect for multi-subdomain setups) - Path Pattern Matching: Route
/app-a/*totg-cluster-aand/app-b/*totg-cluster-b(ideal if you want to share a single domain) - Query Parameter Matching: Route traffic with
?cluster=ato Cluster A (useful for testing, but not recommended for production)
- Host Header Matching: Route
- Set rule priorities to ensure more specific rules run first (e.g., a path rule should take priority over a default catch-all rule)
Validate the Setup
- Test with
curlcommands or a browser to confirm traffic lands in the correct cluster:curl app-a.yourdomain.com/health curl app-b.yourdomain.com/health - Check the ALB's access logs (stored in S3 if enabled) to verify requests are being routed to the right target groups.
- Test with
Key Notes to Avoid Issues
- Security Groups: Make sure your ALB's security group allows incoming traffic from your clients, and your target groups' security groups allow inbound traffic from the ALB's security group on your service port.
- Health Checks: Keep health check settings aligned with your cluster's service health endpoints—unhealthy targets will be automatically removed from traffic rotation.
- EKS/ECS Specific: If using EKS with the ALB Ingress Controller, you can define separate
Ingressresources with host/path rules that map to your cluster's Services. This will automatically create the required target groups and listener rules for you.
内容的提问来源于stack exchange,提问作者Luke Skywalker

