Create a NodeBalancer
This guide walks you through creating a NodeBalancer through Cloud Manager.
- Open the Create NodeBalancer Form in Cloud Manager
- Set the label and add tags
- Select a NodeBalancer Tier
- Select a region
- Assign a Cloud Firewall (optional)
- Set the IP address the NodeBalancer listens on and how it connects to backends
- Add a VPC (optional)
- Add and configure ports
UDP (BETA) configurationsUDP support is available as a limited beta feature for Premium NodeBalancers and is not enabled on all accounts. To request access, contact your account team or open a support ticket.
Currently, you can create NodeBalancer configurations using the
TCP,HTTP, orHTTPSprotocols in Cloud Manager. However, configurations usingUDPcan only be created via the API.You can configure UDP on the same premium NodeBalancer that also uses TCP, HTTP, or HTTPS, but only when managing it through the API. If UDP is configured and you make changes to the TCP, HTTP or HTTPS settings in Cloud Manager, the existing UDP configuration will be overwritten. This is because Cloud Manager doesn't currently support UDP.
Open the Create NodeBalancer form in Cloud Manager
Log in to Cloud Manager and select NodeBalancers from the left navigation menu. Click the Create NodeBalancer button. This opens the NodeBalancer Create form.
Set the label and add tags
Within the Label field, enter the label you wish to use to identify it from other NodeBalancers on your account. A good label should provide some indication as to what the NodeBalancer will be used for. The label must be alphanumeric, between 3 and 32 characters, and unique from other NodeBalancer labels on your account.
To help you identify and manage your NodeBalancer more effectively, you can Add Tags to specify its purpose, environment (e.g. staging, production, testing), or any other relevant detail.
Select a NodeBalancer Tier
Choose the tier that best aligns with your application's performance, scale, and protocol requirements:
- Basic. Designed for general purpose workloads using shared infrastructure. Supports up to 1,000 backend nodes, 10,000 concurrent connections, and TCP, HTTP, or HTTPS configurations.
- Premium. Designed for demanding workloads. Uses dedicated infrastructure. Supports up to 2,000 backend nodes, 100,000 concurrent connections, and TCP, HTTP, or HTTPS configurations.
Review premium and basic NodeBalancers to compare performance, scalability, and protocol support between tiers.
Select a region
Select the Region where the NodeBalancer will reside. Regions correspond with individual data centers, each located in a different geographical area. The NodeBalancer must be deployed in the same region as the backend Linodes and any associated VPC or VPC subnets. If you have not yet deployed Linodes or created a VPC, select the region closest to your target users to minimize latency and ensure optimal connection speeds.
Assign a Cloud Firewall (optional)
A NodeBalancer can only be attached to one Cloud Firewall at a time. You can attach the same Cloud Firewall to multiple NodeBalancers, Linodes and Linode interfaces.
Select the Cloud Firewall from the Assign Firewall pull down to use with the NodeBalancer.
If the firewall doesn't exist yet, you can create the firewall using either the Firewall application, or the NodeBalancer application. Rules for the firewall, can only be added in the Firewalls application.
To create a firewall and add rules using the Firewall application, see Create a Cloud Firewall and Add rules.
To create a firewall using the NodeBalancer application, in the NodeBalancer Create form, click the Create Firewall. This displays the Create Firewall drawer.
Select the option to create a Custom Firewall or create a firewall From a Template. Templates are available for VPC and public Linode interfaces and come with some pre-configured rules.
Select a tab to configure your Firewall with the required fields:
| Configuration | Description |
|---|---|
| Label | The label is used as an identifier for this Cloud Firewall. Required. |
| Default Inbound Policy | The default behavior for inbound traffic is set to Drop, which blocks all unsolicited inbound traffic unless explicitly allowed by other rules. |
| Default Outbound Policy | The default behavior for outbound traffic is set to Accept, which allows all outbound traffic unless explicitly denied by other rules. Note. Outbound firewall rules do not apply to NodeBalancers. |
| Linodes | The Linode(s) and it's interfaces on which to apply the firewall. A list of all Linodes on your account are visible. You can skip this configuration if you do not yet wish to apply the firewall to a Linode. For Linodes using Configuration Profile network interfaces, firewalls are assigned at the Linode level, and the same firewall rules apply to all non-VLAN interfaces in the profile. For Linodes using Linode network interfaces, separate firewalls can be assigned to the VPC network interface and the public network interface. To assign firewalls to Linode Interfaces, see Apply firewalls. |
| Additional NodeBalancers | The NodeBalancer(s) on which to apply the firewall. A list of all NodeBalancers on your account are visible. You may skip this configuration if you do not yet wish to apply the firewall to a NodeBalancer. Note. Outbound firewall rules do not apply to NodeBalancers. |
Click on the Create Firewall button to finish creating the Cloud Firewall and to returned to the NodeBalancers Create form.
By default, a new Cloud Firewall accepts all inbound and outbound connections. Only inbound firewall rules apply to NodeBalancers. Custom rules can be added in the Firewall application as needed. See Add rules.
Cloud Firewall inbound rules for NodeBalancer
- Inbound rules limit incoming network connections to the NodeBalancer based on the port(s) and sources you configure.
- The NodeBalancer accepts traffic and routes traffic on an internal network to backend targets. For this reason, only inbound firewall rules apply to NodeBalancer.
- Inbound firewall rules such as IPv4 and IPv6 access control lists (ACLs) can be configured to Accept or Drop ingress traffic to the NodeBalancer.
- NodeBalancers can accept TCP connections on all ports. When you add an inbound rule for a NodeBalancer in Cloud Firewalls, select TCP or UDP as the transport layer protocol. ICMP, and IPENCAP are not currently supported on NodeBalancers.
- The firewall is in front of the NodeBalancer and the assigned backend nodes. When both the NodeBalancer and its backend nodes have firewalls, the NodeBalancers inbound firewall rules are applied to incoming requests first, before the requests reach the backend nodes.
- A backend node server (Linode) can have multiple IP addresses. The NodeBalancer firewall only controls inbound traffic to the backend nodes IPs that are assigned to the NodeBalancer. A Linode can be accessed from any interface (not just the NodeBalancer). To filter traffic from other interfaces, backend Linodes require their own firewalls.
Set the IP address the NodeBalancer listens on and how it connects to backends
Choose how to assign the frontend public IP address the NodeBalancer uses to listen for incoming connections: Auto-assigned or Reserved.
- Auto-assigned. The system automatically allocates a new ephemeral IP public IPv4 address for your NodeBalancer. Ephemeral IP addresses are tied directly to the NodeBalancer rather than your account. They are typically recycled once the NodeBalancer is deleted so the IP is no longer available for you to use.
- Reserved. Select this option if you want to attach an existing reserved static IP address to this NodeBalancer. Reserved IPs are static, permanent addresses ideal for services requiring a consistent entry point. A reserved IP is permanently bound to the specific region where it was created. You can create a reserved IP independently of a resource, allowing it to exist on your account with or without an active assignment. Charges apply as soon as a reserved IP is added to your account, regardless of whether it is assigned to a resource. Use reserved IPs for NodeBalancers that require a consistent IP address. Select your pre-allocated IP from the dropdown menu, or click Reserve IP to provision a new one on the spot.
Select how your NodeBalancer routes traffic to backend nodes: VPC, IPv6 or Legacy.
- VPC. Routes traffic to backend nodes inside a Virtual Private Cloud (VPC) subnet.
- IPv6: Routes traffic to non-VPC backend nodes using public IPv6 addresses.
- Legacy: Routes traffic to non-VPC backend nodes using classic private IPv4 addresses.
Add a VPC (optional)
If VPC is selected for Backend Connectivity, complete the VPC section by selecting your VPC and subnet from the dropdown menus. If none of the backends are (or will be) in a VPC, skip this step.
To load balance traffic to applications in a VPC, select a VPC and a subnet. This allows the NodeBalancer to communicate with backend nodes within the VPC. The subnet must be in the same data center as the NodeBalancer.
Once the NodeBalancer is created, its VPC can't be changed.
- VPC. Select the VPC that contains the backend nodes (Linodes) that this NodeBalancer will route requests to.
- Subnet. Choose the subnet that the NodeBalancer will use to source IP addresses for routing requests to Linodes in the VPC.
- Auto-assign IPs for this NodeBalancer. When enabled, the system automatically allocates a
/30IPv4 range from the selected subnet for this NodeBalancer’s backend nodes. This helps you reserve address space for other NodeBalancers in the same VPC. When disabled, you can manually enter the IPv4 range the NodeBalancer will use to communicate with backend nodes.
A/30subnet defines a range of 4 addresses. This range is required for high availability of NodeBalancer instances.
Add and configure ports
To start load balancing traffic, you need to define which ports the NodeBalancer should listen to and how the incoming traffic should be routed to the backend nodes. By default, a single port configuration is visible in this area. Additional ports can be added by clicking the Add Another Configuration button. See Configuration options for more details regarding each of these settings.
- Port: Enter the inbound port the NodeBalancer should listen to. This can be any port from 1 through 65534 and should align with the port the client connects to. See Configuration options > Port.
- Protocol: Select TCP, HTTP, or HTTPS. For many applications, using TCP offers the most flexibility and allows for TLS pass through. Using HTTP and HTTPS offers some additional NodeBalancer options and allows for TLS termination. See Configuration options > Protocol. Configurations using
UDPcan only be created via the API. UDP configurations are supported on premium NodeBalancers only. - Proxy Protocol: Only visible when the TCP protocol is selected. Used for sending the client IP address to the backend nodes. See Configuration options > Proxy protocol.
- Algorithm: Controls how new connections are allocated across backend nodes. See Configuration options > Algorithm.
- Session Stickiness: Controls how subsequent requests from the same client are routed when selecting a backend node. See Configuration options > Session stickiness.
- SSL Certificate and Private Key (required when protocol is HTTPS):
- Certificate: The TLS/SSL certificate (and certificate chain) that has been obtained for the application.
- Private Key: The passphraseless private key that is associated with the certificate file.
For most web applications, it's common to configure two ports: port 80 and port 443.
Set up health checks for each port
Each port can optionally be configured with health checks. These health checks either proactively query the backend nodes (active) or monitor the existing traffic to backend nodes (passive). If a health check determines that the back ends aren't responsive or are encountering another issue, they can be marked as down and taken out of rotation.
-
Active Health Checks: Active health checks proactively query the backend nodes by performing TCP connections or making HTTP requests. See Configuration Options > Active Health Checks.
-
Passive Checks: Passive health checks monitor requests sent to the backend nodes and look for any issues. See Configuration Options > Passive Health Checks.
Add backend nodes to each port
Load balancers work by distributing traffic to a pool of servers. For NodeBalancers, these servers are Linode(s) configured as backend nodes. Depending on the Backend Connectivity method selected under Networking, you can attach VPC subnets, public IPv6 addresses, or legacy private IPv4 addresses as backend endpoints. For information on configuring backend nodes, see the Backend nodes (Linodes) guide.
Backend connectivity typeAll backend nodes assigned to a NodeBalancer must use the same connectivity type. You can't mix public IPv6, private IPv4, and VPC backends on the same NodeBalancer or across different port configurations.
Deploy the NodeBalancer
Once you've adjusted the settings to fit your needs, review the NodeBalancer Summary section and click the Create NodeBalancer button. The NodeBalancer should be provisioned within a few minutes.
Updated about 3 hours ago
