Cloud Load Balancing
Cloud Load Balancing runs Google's managed load balancers, which terminate client connections at Google's edge and forward them to backends in a region. The GCP Web App Blueprint puts two global external Application Load Balancers in front of each stage, one for the API and one for the single-page application (SPA), and an internal one in front of ArgoCD.
What it does
A global external Application Load Balancer answers on one anycast address and terminates TLS at the target HTTPS proxy, which holds the certificates and an SSL policy (the TLS versions and ciphers it accepts). A URL map routes requests to backend services; a backend service carries the health check, the Google Cloud Armor policy, Cloud CDN and request logging, and points at backends such as a network endpoint group (NEG). A serverless NEG makes a Cloud Run service a backend. A forwarding rule binds the address and port to the proxy. The EXTERNAL_MANAGED scheme is the current, Envoy-based generation of these load balancers.
How BuiltForProd uses it
The API load balancer for blueprint-api.<stage>.company.com is built by the GKE Gateway controller from the chart's Gateway of class gke-l7-global-external-managed; see GKE Gateway. The api-gateway unit creates, outside the cluster, everything the Gateway references by name and publishes those names to Parameter Manager:
| Resource (prod) | Created by | Referenced from the chart by |
|---|---|---|
acme-usw1-prd-api-ip | api-gateway | the Gateway address (NamedAddress) |
acme-usw1-prd-api-certmap | api-gateway | the annotation networking.gke.io/certmap |
acme-usw1-prd-api-armor | api-gateway | GCPBackendPolicy securityPolicy |
acme-usw1-prd-api-tls | api-gateway | GCPGatewayPolicy sslPolicy |
The Gateway has one HTTPS listener on port 443; plain HTTP gets no answer. The chart's backend policy sets a 30-second backend timeout and logs every request, and its health check probes /health on the pods through container-native load balancing.
The SPA load balancer for blueprint-app.<stage>.company.com is built by the frontend-service unit itself: a serverless NEG on the Cloud Run service acme-usw1-prd-frontend, a backend service with Cloud CDN, the stage's Cloud Armor policy and request logging at a sample rate of 1.0, the URL map acme-usw1-prd-frontend-lb, an HTTPS proxy with a Certificate Manager map, and a second URL map that answers port 80 with a permanent redirect to HTTPS. Both forwarding rules share one reserved global address, and the unit writes the A record into the stage zone. The code comment lists ~$18 per month for each forwarding rule.
TLS. Each load balancer has its own SSL policy with the MODERN profile and TLS 1.2 as the minimum version.
ArgoCD is reached through a regional internal Application Load Balancer instead: an ArgoCD Gateway of class gke-l7-rilb on a reserved internal address of the stage's nodes subnet, with its proxies in the landing zone's proxy-only subnet. It is never exposed to the internet; see ArgoCD.
Terms you will see
| Term | Meaning |
|---|---|
| Serverless NEG | A backend that points at a Cloud Run service instead of instances or pods. |
| Backend service | Health check, Cloud Armor, CDN and logging settings for one set of backends. |
| URL map | The routing table of a load balancer; a CDN invalidation names the URL map. |
| SSL policy | The TLS versions and cipher suites a proxy accepts. |
NamedAddress | A Gateway address given as the name of a reserved global IP. |
Where to read more
- GCP Web App Blueprint overview for the request path end to end.
- GKE Gateway for how the API load balancer is built from Kubernetes objects.
- Google Cloud Armor for the policies on both backends.