如何通过Network Load Balancer实现与Amazon ALB一致的路径路由?
Great question! Since Amazon Network Load Balancers (NLB) operate at Layer 4 (TCP/UDP)—unlike Application Load Balancers (ALB) which work at Layer 7—they don’t natively support host-based (like www.example.com vs api.example.com) or path-based routing out of the box. But there are a couple of reliable workarounds to replicate your existing ALB setup:
方案1:NLB + 七层代理服务器(Nginx/HAProxy)
This is the most straightforward way to add Layer 7 routing capabilities to an NLB. Here’s how to set it up:
Step 1: Deploy your proxy layer
Launch a fleet of EC2 instances (or use ECS/EKS containers) running Nginx or HAProxy, placed in an Auto Scaling Group to handle traffic spikes. These servers will act as the "Layer 7 brain" for routing.Step 2: Configure the NLB
Create an NLB with a listener for your desired port (e.g., 443 for HTTPS). Point its target group to your proxy servers. You can enable SSL termination directly on the NLB (using AWS Certificate Manager certificates) to offload encryption from the proxies.Step 3: Set up routing rules on the proxy
Configure your proxy to route traffic based on the host header. For example, here’s a simplified Nginx config snippet:server { listen 443 ssl; server_name www.example.com; # Forward to Frontend targets location / { proxy_pass http://frontend-target-group-ip-or-dns; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } } server { listen 443 ssl; server_name api.example.com; # Forward to Backend targets location / { proxy_pass http://backend-target-group-ip-or-dns; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } }Make sure the proxy can resolve the target group DNS (or use static IPs if you’re using IP-targeted target groups).
方案2:Route 53 + 独立NLBs per subdomain
If you don’t want to manage a proxy layer, you can split your traffic at the DNS level:
Step 1: Create two separate NLBs
- One NLB configured with a target group pointing to your Frontend resources, listening on port 443.
- Another NLB configured with a target group pointing to your Backend resources, listening on port 443.
Step 2: Update Route 53 records
Create two A/AAAA alias records:- Point
www.example.comto the Frontend NLB. - Point
api.example.comto the Backend NLB.
This way, Route 53 routes traffic directly to the appropriate NLB before it even hits the load balancer layer.
- Point
关键注意事项
- Cost consideration: The proxy layer adds extra compute costs, while multiple NLBs add minimal extra cost (since NLB pricing is based on data processed). Choose based on your budget and operational overhead preferences.
- Performance: NLBs are designed for high throughput and low latency. When using a proxy layer, ensure your proxy fleet is sized correctly (Auto Scaling helps here) to avoid bottlenecks.
- SSL management: If using the proxy approach, you can terminate SSL at the NLB or the proxy—terminating at the NLB is generally easier since you can use AWS Certificate Manager for certificate management.
Hope one of these approaches fits your needs! If you run into specific issues with configuration, feel free to dive deeper into the details.
内容的提问来源于stack exchange,提问作者John Mike

