Skip to main content

Cloud Load Balancing

Cloud Load Balancing runs Google's managed load balancers, which terminate client connections at Google's edge and forward them to backends in a region. The GCP Web App Blueprint puts two global external Application Load Balancers in front of each stage, one for the API and one for the single-page application (SPA), and an internal one in front of ArgoCD.

What it does​

A global external Application Load Balancer answers on one anycast address and terminates TLS at the target HTTPS proxy, which holds the certificates and an SSL policy (the TLS versions and ciphers it accepts). A URL map routes requests to backend services; a backend service carries the health check, the Google Cloud Armor policy, Cloud CDN and request logging, and points at backends such as a network endpoint group (NEG). A serverless NEG makes a Cloud Run service a backend. A forwarding rule binds the address and port to the proxy. The EXTERNAL_MANAGED scheme is the current, Envoy-based generation of these load balancers.

How BuiltForProd uses it​

The API load balancer for blueprint-api.<stage>.company.com is built by the GKE Gateway controller from the chart's Gateway of class gke-l7-global-external-managed; see GKE Gateway. The api-gateway unit creates, outside the cluster, everything the Gateway references by name and publishes those names to Parameter Manager:

Resource (prod)Created byReferenced from the chart by
acme-usw1-prd-api-ipapi-gatewaythe Gateway address (NamedAddress)
acme-usw1-prd-api-certmapapi-gatewaythe annotation networking.gke.io/certmap
acme-usw1-prd-api-armorapi-gatewayGCPBackendPolicy securityPolicy
acme-usw1-prd-api-tlsapi-gatewayGCPGatewayPolicy sslPolicy

The Gateway has one HTTPS listener on port 443; plain HTTP gets no answer. The chart's backend policy sets a 30-second backend timeout and logs every request, and its health check probes /health on the pods through container-native load balancing.

The SPA load balancer for blueprint-app.<stage>.company.com is built by the frontend-service unit itself: a serverless NEG on the Cloud Run service acme-usw1-prd-frontend, a backend service with Cloud CDN, the stage's Cloud Armor policy and request logging at a sample rate of 1.0, the URL map acme-usw1-prd-frontend-lb, an HTTPS proxy with a Certificate Manager map, and a second URL map that answers port 80 with a permanent redirect to HTTPS. Both forwarding rules share one reserved global address, and the unit writes the A record into the stage zone. The code comment lists ~$18 per month for each forwarding rule.

TLS. Each load balancer has its own SSL policy with the MODERN profile and TLS 1.2 as the minimum version.

ArgoCD is reached through a regional internal Application Load Balancer instead: an ArgoCD Gateway of class gke-l7-rilb on a reserved internal address of the stage's nodes subnet, with its proxies in the landing zone's proxy-only subnet. It is never exposed to the internet; see ArgoCD.

Terms you will see​

TermMeaning
Serverless NEGA backend that points at a Cloud Run service instead of instances or pods.
Backend serviceHealth check, Cloud Armor, CDN and logging settings for one set of backends.
URL mapThe routing table of a load balancer; a CDN invalidation names the URL map.
SSL policyThe TLS versions and cipher suites a proxy accepts.
NamedAddressA Gateway address given as the name of a reserved global IP.

Where to read more​