Skip to content

Create the load balancer

A target group with a health check, and an internet-facing Application Load Balancer in front of the API.

About 20 min · Verified 8 October 2026

0 of 9 steps done0%

The Application Load Balancer (ALB) is the only public door to your API. It accepts HTTP on port 80, picks a healthy server from a target group, and forwards the request to port 3000. It keeps asking each server a question (the health check) and stops sending traffic to servers that do not answer.

You will create the target group first, then the load balancer. The server does not exist yet, and that is fine: you register it in the EC2 chapter.

Create the target group#

Open the wizard#

Open EC2Target GroupsCreate target group.

FieldValue
Choose a target typeInstances
Target group nameshortlink-app-tg
Protocol : PortHTTP : 3000
IP address typeIPv4
VPCshortlink-vpc
Protocol versionHTTP1

Set the health check#

Under Health checks:

FieldValue
Health check protocolHTTP
Health check path/health

Expand Advanced health check settings:

FieldValue
PortTraffic port
Healthy threshold2
Unhealthy threshold2
Timeout5 seconds
Interval10 seconds
Success codes200

/health is a route the API provides. It runs a tiny query against the database and returns 200 {"status":"ok","database":"up"}, or 503 if the database cannot be reached. So a server only counts as healthy if the database connection works too.

Skip registering targets and create#

Choose Next. On Register targets do not select anything. Choose Create target group.

Shorten the deregistration delay#

Open the new target group → Attributes → Edit. Change Deregistration delay from 300 to 30 seconds and save.

Create the load balancer#

Choose the type#

Open EC2Load BalancersCreate load balancer. Under Application Load Balancer choose Create.

Basic configuration and network mapping#

FieldValue
Load balancer nameshortlink-alb
SchemeInternet-facing
Load balancer IP address typeIPv4
VPCshortlink-vpc
MappingsTick both Availability Zones and, for each, choose the public subnet (10.0.1.0/24 and 10.0.2.0/24)

Security group and listener#

FieldValue
Security groupsRemove default, add shortlink-alb-sg
Listener protocol : portHTTP : 80
Default actionForward to shortlink-app-tg

Choose Create load balancer.

Wait for Active and save the DNS name#

Open the load balancer. State moves from Provisioning to Active in 2 to 3 minutes. Copy DNS name (it looks like shortlink-alb-123456789.<region>.elb.amazonaws.com) into My values → Load balancer DNS name.

Verify#

Your computerAsk the load balancer for /health
curl -i http://<ALB_DNS>/health

Replace <ALB_DNS> with your own value (or fill in the known ones once under My values at the top of the page).

Expected output
HTTP/1.1 503 Service Temporarily Unavailable

A 503 is exactly what you want right now. It proves the load balancer is reachable from the internet and that it has no healthy servers yet.

curl times out or cannot resolve the host
  • Cannot resolve host: the load balancer may still be provisioning. Wait a minute and retry.
  • Timeout: the load balancer is in the wrong subnets, or shortlink-alb-sg does not allow port 80 from 0.0.0.0/0. Re-check the mappings and the security group.

Next: the S3 website bucket.

Found a mistake? Edit this page on GitHub.