Sep 30, 2026 — NodeBalancers and flexible backend connectivity
This release introduces Premium NodeBalancers for enterprise-grade workloads and removes the private IPv4 requirement by adding support for VPC and IPv6 backend connectivity.
For more information, see:
Premium NodeBalancers
NodeBalancers are now offered in both premium (new) and basic versions. The following table compares these options. Use this information to help determine which version best meets your application’s requirements for performance, scalability, and protocol support.
| Feature / Specification | Premium (premium) | Basic (common) |
|---|---|---|
| Maximum backend nodes per configuration | Up to 2,000 | Up to 1,000 |
| Backend node connectivity | Support either VPC or public IPv6 backends. | Support legacy (private IPv4), VPC or public IPv6 backends. |
| Maximum concurrent connections (TCP/HTTP/HTTPS) | Up to 100,000 | Up to 10,000 |
| Maximum concurrent connections (UDP) | Up to 80,000 | Not supported |
| UDP (layer 4) load balancing | Supported (configured using APIs) | Not supported |
| TCP (layer 4) load balancing | Supported | Supported |
| HTTP/HTTPS (layer 7) load balancing | Supported (HTTP/1.1 only) | Supported (HTTP/1.1 only) |
| Maximum inbound network bandwidth | 10 Gbps | 10 Gbps |
| Assigned for LKE-E clusters | Automatically assigned | Not automatically assigned |
| Infrastructure and performance | Dedicated for consistent, predictable capacity | Shared, may experience resource contention |
| Reserved IPs | Supported (Except when provisioned by IAM restricted users for LKE-Enterprise). | Supported |
Flexible backend connectivity
NodeBalancers no longer require a private IP in the 192.168.255.0/24 range to communicate with backend nodes. Instead, the connectivity between the NodeBalancer and its backend nodes now depends on its backend_connectivity setting. Depending on this setting, IP addresses outside the private range can be used.
The NodeBalancer's backend_connectivity setting applies to all its backend nodes and can't be changed after the NodeBalancer is created. You can choose from legacy, ipv6, or vpc for this setting.
NodeBalancer connectivity to backend nodes
| Value | When to use | Example IP used for connectivity |
|---|---|---|
legacy | For basic NodeBalancers communicating with non-VPC backend nodes over private IPv4. The NodeBalancer's frontend IPv4 communicates with the backend node's private IPv4 address. Note: Limited quantities of private IPv4s are available. | 192.168.255.10 Other types of node addresses (IPv6, VPC IPs) are not allowed. |
ipv6 | For basic or premium NodeBalancers communicating with non-VPC backend nodes using a public IPv6. The NodeBalancer's frontend IPv6 communicates with the backend node's IPv6 address. | 2600:3c1f:51:1::1 Other types of node addresses (private IPv4, VPC IPs) are not allowed. |
vpc | For basic or premium NodeBalancers communicating with backend nodes assigned to a VPC. VPCs support IPv4 and IPv6 (BETA). | 10.0.250.4/30 Non-VPC IPs are not allowed. |
undefined(Read-only) | This value is assigned only when you create a NodeBalancer without specifying a After you add the first backend node to the NodeBalancer using the Create a node operation, this value updates to either | — |
Protecting backend nodes from unauthorized access and maintaining secure communication
The NodeBalancer's backend IPs are used for communication between the NodeBalancer and the backend nodes. Your backend nodes should be configured to block direct traffic from external sources or clients, accepting requests only through these NodeBalancer backend IPs.
To secure backend nodes, assign the Linodes to a VPC or use Cloud Firewalls and configure firewall rules to allow only NodeBalancer traffic. Add the NodeBalancer IP access control list (ACL) to the backend node's firewall rules. This setup is typically performed once.
NodeBalancer backend IP addresses differ by data center. You can obtain the ACL using the GET NodeBalancer's backend ACL operation.
Data transferred between services like NodeBalancers and Linodes in the same data center (using either a private IPv4, public IPv6, or VPC) is free and it doesn’t count against your monthly bandwidth allowance.
NodeBalancers - API changes
NodeBalancers
Added a new fields:
type. With the following options:premiumandcommon.backend_connectivity. With the following options:legacy,ipv6, andvpc. Ifbackend_connectivityis not specified and neither a VPC nor a node is provided, a new common NodeBalancer will haveundefinedassigned, while a new premium NodeBalancer will haveipv6assigned.backend_ipv6_prefix. Read-only, The backend ACL for this NodeBalancer that can be used for firewall rules on their backend Linodes, allowing traffic only from that NodeBalancer backend source range.
The
backend_connectivitysetting can't be changed after you create the NodeBalancer. All backend nodes must use the same IP addressing supported by the selectedbackend_connectivitytype. For example, if you setbackend_connectivitytolegacy, all backend nodes must use private IPv4 addresses.
- Create a NodeBalancer (POST /nodebalancers)
- List NodeBalancers (GET /nodebalancers)
- Get a NodeBalancer (GET /nodebalancers/{nodeBalancerId})
- Update a NodeBalancer (PUT /nodebalancers/{nodeBalancerId})
- Get a NodeBalancer's backend IPv6 prefix GET /nodebalancers/{nodeBalancerId}/backend_acl
Nodes
Updated the address field to include supported IP types for non-VPC backend nodes and backend nodes within a VPC.
- Create a node (POST /nodebalancers/{nodeBalancerId}/configs/{configId}/nodes)
- List nodes (GET /nodebalancers/{nodeBalancerId}/configs/{configId}/nodes)
- Get a NodeBalancer's node (GET /nodebalancers/{nodeBalancerId}/configs/{configId}/nodes/{nodeId})
- Update a node (PUT /nodebalancers/{nodeBalancerId}/configs/{configId}/nodes/{nodeId})
- Rebuild a config POST /nodebalancers/{nodeBalancerId}/configs/{configId}/rebuild
