You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Network Load Balancer实现与Amazon ALB一致的路径路由?

如何用Amazon Network Load Balancer实现ALB的子域名路由方案

Great question! Since Amazon Network Load Balancers (NLB) operate at Layer 4 (TCP/UDP)—unlike Application Load Balancers (ALB) which work at Layer 7—they don’t natively support host-based (like www.example.com vs api.example.com) or path-based routing out of the box. But there are a couple of reliable workarounds to replicate your existing ALB setup:

方案1:NLB + 七层代理服务器(Nginx/HAProxy)

This is the most straightforward way to add Layer 7 routing capabilities to an NLB. Here’s how to set it up:

  • Step 1: Deploy your proxy layer
    Launch a fleet of EC2 instances (or use ECS/EKS containers) running Nginx or HAProxy, placed in an Auto Scaling Group to handle traffic spikes. These servers will act as the "Layer 7 brain" for routing.

  • Step 2: Configure the NLB
    Create an NLB with a listener for your desired port (e.g., 443 for HTTPS). Point its target group to your proxy servers. You can enable SSL termination directly on the NLB (using AWS Certificate Manager certificates) to offload encryption from the proxies.

  • Step 3: Set up routing rules on the proxy
    Configure your proxy to route traffic based on the host header. For example, here’s a simplified Nginx config snippet:

    server {
        listen 443 ssl;
        server_name www.example.com;
    
        # Forward to Frontend targets
        location / {
            proxy_pass http://frontend-target-group-ip-or-dns;
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
        }
    }
    
    server {
        listen 443 ssl;
        server_name api.example.com;
    
        # Forward to Backend targets
        location / {
            proxy_pass http://backend-target-group-ip-or-dns;
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
        }
    }
    

    Make sure the proxy can resolve the target group DNS (or use static IPs if you’re using IP-targeted target groups).

方案2:Route 53 + 独立NLBs per subdomain

If you don’t want to manage a proxy layer, you can split your traffic at the DNS level:

  • Step 1: Create two separate NLBs

    • One NLB configured with a target group pointing to your Frontend resources, listening on port 443.
    • Another NLB configured with a target group pointing to your Backend resources, listening on port 443.
  • Step 2: Update Route 53 records
    Create two A/AAAA alias records:

    • Point www.example.com to the Frontend NLB.
    • Point api.example.com to the Backend NLB.

    This way, Route 53 routes traffic directly to the appropriate NLB before it even hits the load balancer layer.

关键注意事项

  • Cost consideration: The proxy layer adds extra compute costs, while multiple NLBs add minimal extra cost (since NLB pricing is based on data processed). Choose based on your budget and operational overhead preferences.
  • Performance: NLBs are designed for high throughput and low latency. When using a proxy layer, ensure your proxy fleet is sized correctly (Auto Scaling helps here) to avoid bottlenecks.
  • SSL management: If using the proxy approach, you can terminate SSL at the NLB or the proxy—terminating at the NLB is generally easier since you can use AWS Certificate Manager for certificate management.

Hope one of these approaches fits your needs! If you run into specific issues with configuration, feel free to dive deeper into the details.

内容的提问来源于stack exchange,提问作者John Mike

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 07:33:44