AWS Fargate部署ECS服务时多端口负载均衡方案咨询
Multi-Port Load Balancing for Fargate ECS Services
Great question—you're absolutely right that Classic Load Balancers (CLB) don't work with Fargate's awsvpc network mode (CLB's architecture relies on traditional EC2 instance networking, which clashes with the per-task elastic network interfaces awsvpc uses). But there are two reliable, supported ways to set up multi-port load balancing for your Fargate ECS services:
1. Application Load Balancer (ALB) with Multiple Target Groups
This is the most common and flexible approach for HTTP/HTTPS traffic:
- Create a separate target group for each port your service needs to expose (e.g., one for port 80, another for port 443). Each target group should be configured to target your ECS service's corresponding container port, using the awsvpc network mode.
- Add listeners to your ALB for each port you want to expose. For example, set up an HTTP listener on port 80 that forwards traffic to your port-80 target group, and an HTTPS listener on port 443 that forwards to your port-443 target group.
- When configuring your ECS service, associate all of these target groups with it. Make sure your task definition has the correct port mappings for each container port.
2. Network Load Balancer (NLB)
NLB is ideal for TCP/UDP traffic where low latency is critical (e.g., game servers, database proxies):
- NLB fully supports awsvpc network mode. You can configure multiple TCP/UDP listeners directly on the same NLB, each mapped to a specific port.
- Each listener forwards traffic directly to the corresponding port on your Fargate tasks. Just ensure your task definition has the port mappings set up, and your security groups allow traffic from the NLB to those ports.
Key Notes for Both Approaches
- Ensure your Fargate task security group allows inbound traffic from the ALB/NLB on all the ports you're exposing.
- For awsvpc mode, you can either specify fixed host ports or set the host port to
0(which lets AWS assign a random ephemeral port—your target group will automatically discover these ports via ECS service discovery). - Don't forget to configure appropriate health checks for each target group, tailored to the service running on that port (e.g., an HTTP health check path for a web service on port 80, or a TCP handshake check for a backend service).
内容的提问来源于stack exchange,提问作者hoodsy
相关产品推荐
相关产品推荐

