AnkraDocs
Console

Concepts

Load balancers

A highly available HAProxy pair with an IPv4 address that fails over in about a second, TLS termination, health checks and IPv4 or IPv6 members.

A load balancer is two HAProxy VMs on different hosts, each with a leg on one of your private networks. They share one public IPv4 address with VRRP: the active VM holds it, and when that VM or its HAProxy stops, the other takes the address within about a second, without the control plane. Each VM also serves the same frontends on IPv6 on its own public /64.

Creating one#

bash
curl -X POST https://cloud.ankra.app/v1/load-balancers \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{ "zone": "de-fsn1", "name": "web", "network_id": "<network-id>" }'

The answer is 202 with a load_balancer.create operation, done once both VMs run and are configured. The zone needs two hosts with room (503 otherwise).

Frontends, backends and members#

  • A backend has a mode (tcp or http), a balance algorithm (roundrobin by default, leastconn, source) and a health check.
  • A member is an address and port in a backend, with a weight (0–256, default 100) and enabled. The address is an IPv4 host of the private network, an address on its IPv6 ULA /64, or a global IPv6 address such as a server's public_ipv6, so IPv6-only servers sit behind the one IPv4 address.
  • A frontend listens on a port and forwards to a backend, taking its mode.

Configuration changes take effect without an operation: each change bumps configuration_generation, the new HAProxy configuration is validated on both VMs with haproxy -c and reloaded. is_configuration_applied turns true when both have it.

Health checks#

health_check is { type, path, expected_status, interval_seconds, rise, fall }. A TCP check connects to the member; an HTTP check sends GET <path> and expects expected_status (for example 200-399); none never checks. The defaults are TCP every 2 s, rise 2, fall 3.

TLS#

Upload certificates with POST /v1/load-balancers/certificates: the PEM chain (leaf first) and an unencrypted private key (RSA of at least 2048 bits, ECDSA or Ed25519). The key is sealed at rest, never returned or logged, and reaches the load balancer VMs only inside their configuration. A tls frontend terminates TLS with 1 to 16 certificates: the first answers clients without SNI, the others are chosen by SNI. HTTP backends behind TLS get X-Forwarded-Proto: https and HTTP/2 via ALPN. A plain HTTP frontend with redirect_to_https answers every request with a redirect to HTTPS.

Pricing and limits#

A load balancer costs €6.98 a month, billed per hour held: €1.49 for each of its two VMs, disks included, plus €4.00 for its public IPv4 address. An account holds at most 5 load balancers and 100 certificates; a load balancer takes at most 50 frontends.

For a simpler IPv4 entry point for IPv6-only servers, a network edge with the load_balancer role may be enough.