Amazon Web Services
Load Balancing — ALB, NLB & Gateway Load Balancer
Spread traffic across targets and know which balancer suits which protocol and failure mode.
Three balancers, operating at different layers.
A head waiter seating guests. The ALB reads the booking and takes you to the right room; the NLB simply sends you to whichever table is free, far faster, without asking why you came.
Key Concepts
1
ALB layer 7, HTTP/HTTPS routes on host, path, header, method
NLB layer 4, TCP/UDP/TLS millions of req/s, static IP, ultra low latency
GWLB layer 3 transparently inserts firewall appliances2
ALB is the default for web traffic, because it understands the request:
3
/api/* -> api-target-group
/images/* -> static-target-group
Host: admin.example.com -> admin-target-group4
That routing is impossible at layer 4, where there is no URL to read.
5
NLB is for everything else. It forwards packets without parsing them, so it handles any TCP protocol —
databases, gRPC, game servers, MQTT. It also gives a static IP per AZ, which is what you need when a
client or a partner firewall must allow-list an address. An ALB's IPs change.
6
Target groups are where health checking lives.
health check /healthz every 30s, 2 failures = unhealthy
unhealthy target -> removed from rotation, traffic continues7
Make the health check mean something. A check that returns 200 unconditionally keeps a broken instance in
rotation; one that checks the database makes a database blip take out every instance at once. Check what the
instance itself needs to serve.
8
Cross-zone load balancing spreads evenly across all AZs rather than evenly per AZ. ALB has it on by
default; NLB does not, and uneven target counts per AZ then produce uneven load.
9
Connection draining — deregistration delay — lets in-flight requests finish before a target is removed,
which is what makes a rolling deploy invisible.
10
Sticky sessions pin a client to one target with a cookie. Useful for legacy apps that hold session state
in memory, and a sign the application should be storing that state elsewhere.
11
The client's IP needs care. An ALB puts it in X-Forwarded-For; the socket shows the balancer's address,
which is why access logs and rate limiting read the wrong IP when nobody configured it.
X-Forwarded-For
12
What the interviewer is probing.1. "ALB or NLB?" Probing: the layer. Stalls: "ALB, it is newer." Moves up: ALB for HTTP
where you route on path, host or header; NLB for other TCP protocols, extreme throughput, or when
you need a static IP to allow-list.
13
2. "Your health check returns 200 unconditionally. What is wrong with that?" Probing: what a
health check should assert. Stalls: "Nothing, it proves it is up." Moves up: a broken instance
stays in rotation; conversely, a check that tests a shared database turns one blip into a total
outage.
14
3. "Why does your access log show the same IP for every request?" Probing: X-Forwarded-For.
Stalls: "A bug." Moves up: behind an ALB the socket shows the balancer; the client address is in
X-Forwarded-For.
15
4. "What is deregistration delay for?" Probing: draining. Stalls: "It slows deploys." *Moves
up:* it lets in-flight requests finish before a target is removed, which is what makes a rolling
deploy invisible.