EC2绑定Elastic IP后,如何通过负载均衡器实现HTTP转HTTPS?
Hey there! Let's walk through this step by step—since you're getting back into server config and new to AWS, I'll keep this clear and actionable. First, let's address your core questions:
Is using an Application Load Balancer (ALB) the best approach?
Absolutely. ALB is AWS's recommended, low-effort way to handle HTTP→HTTPS redirects, and it adds extra perks like health checks, multi-AZ redundancy, and simplified SSL management. You don't need to touch your EC2 instance's existing config (since it only listens on 443) — all the routing logic lives in the ALB.
What about the Elastic IP issue?
ALBs can't directly bind Elastic IPs (they use dynamic, distributed public IPs across AZs), but we have two solid workarounds depending on your needs:
- If you use a domain name: Point it to the ALB's DNS name via Route 53 (AWS's DNS service) — this is the simplest and most scalable option.
- If you absolutely need a fixed public IP: Use a Network Load Balancer (NLB) as a front-end, bind your Elastic IP to the NLB, and have the NLB forward traffic to the ALB.
1. Get a Free SSL Certificate (via AWS Certificate Manager)
Before setting up the ALB, you'll need an SSL certificate for HTTPS:
- Log into the AWS Console, navigate to Certificate Manager (ACM).
- Click "Request a certificate" → choose "Public certificate" → enter your domain(s) (e.g.,
example.comor*.example.comfor subdomains). - Choose DNS verification (the easiest route): AWS will generate a Route 53 record for you — just click "Create records in Route 53" to auto-add it.
- Wait a few minutes for the certificate to be issued (ACM will update the status to "Issued").
2. Create the Application Load Balancer
Head to the EC2 Console → "Load Balancers" → "Create load balancer":
- Select "Application Load Balancer" → "Create".
- Basic Configuration: Name your ALB, select "Internet-facing", and pick "IPv4" for IP address type.
- Network Mapping: Choose the same AZ(s) where your EC2 instance lives (pick at least one, multi-AZ is better for reliability) and select a public subnet for each AZ.
- Security Groups: Create a new security group (or use an existing one) that allows inbound traffic on ports 80 (HTTP) and 443 (HTTPS) from
0.0.0.0/0. - Listeners and Routing:
- Port 80 (HTTP): For the action, select "Redirect to HTTPS" instead of forwarding to a target group. Set the target port to 443, choose status code
301 (Permanent Redirect)(best for SEO and caching), and check boxes to preserve the original host, path, and query string. - Port 443 (HTTPS): Select "Forward to a target group" → click "Create target group".
- Target group type: "Instance" → name it, set protocol to HTTPS, port to 443.
- Under "Register targets", select your EC2 instance and click "Include as pending below" → "Register targets".
- Back to the 443 listener: Select the SSL certificate you created in ACM, then choose the target group you just made.
- Port 80 (HTTP): For the action, select "Redirect to HTTPS" instead of forwarding to a target group. Set the target port to 443, choose status code
- Click "Create load balancer" and wait 5-10 minutes for it to provision.
3. Secure Your EC2 Instance's Security Group
Right now, your EC2 instance probably allows 443 traffic from anywhere — let's lock that down to only accept traffic from the ALB:
- Go to your EC2 instance's details page → "Security" tab → click the security group linked to the instance.
- Edit inbound rules: Delete any rule that allows HTTPS (443) from
0.0.0.0/0. - Add a new rule: Type "HTTPS", Port range "443", and set the source to the ALB's security group (select it from the dropdown).
- Save the rules.
4. Switch Traffic to the ALB (and Handle Elastic IP)
Option A: Using a Domain Name (Recommended)
- Go to Route 53 → "Hosted zones" → select your domain's zone.
- Click "Create record":
- For record type, choose "CNAME" (or "A" with alias enabled, which is better for root domains).
- Set the value to your ALB's DNS name (found in the ALB's details page under "DNS name").
- Save the record. Traffic to your domain will now go through the ALB, which redirects HTTP to HTTPS.
Option B: Using a Fixed Elastic IP
If you need a static IP (e.g., for IP whitelisting):
- Create a Network Load Balancer (NLB) in the EC2 Console:
- Name it, select "Internet-facing", IPv4.
- Under "Network Mapping", for each AZ you selected earlier, choose "Assign elastic IP" and pick your existing Elastic IP (make sure it's unbound from your EC2 instance first).
- Add a listener: Protocol "TCP", Port "443" → forward to a new target group of type "ALB", selecting your ALB as the target.
- Now users can access the Elastic IP directly, and traffic will flow:
Elastic IP → NLB → ALB → EC2 Instance.
Clean Up the Old Elastic IP Binding
- Go to your EC2 instance's details page → "Network" tab → next to "Elastic IP", click "Unassociate".
- You can either release the IP (if you don't need it) or keep it for future use.
Why This Is the Best Approach
- No changes needed to your EC2 instance's existing setup (it only listens on 443, which stays intact).
- ALB handles all redirect logic at the edge, reducing load on your instance.
- Built-in health checks: If your EC2 instance goes down, the ALB stops sending traffic to it.
- ACM manages SSL certificates for free, with auto-renewal — no manual certificate updates.
内容的提问来源于stack exchange,提问作者Stu

