Skip to content

[aws] Switch to TLS NLB #30

@captn3m0

Description

@captn3m0

Creating this issue to start a discussion.

Pros

  • L4 Load Balancer
  • You can assign internal static IPs to the NLB
  • Certs can be assigned to the NLB instead via ACM, and remove the burden of setting --cacert on the client side (possible today, but not sure if can be supported)
  • Because this retains TCP Source IP, etcd logs actual IPs

Cons

  • Pricing is significantly different, might need to be re-evaluated.

Reference:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions