AWSLive-testedattested

Application Load Balancer

ALB with HTTPS listeners, target groups, listener rules, and access logging - drop-in for ECS/EC2/Lambda targets.

terraformAWSaws

Compare Load Balancer across clouds →

Part of: AWS Production Landing Zone, AWS Container Platform (EKS)

aws-albvizier v1.2.0

Verification

Live-tested

Really deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan test superseded by live test

Provenance

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-06-19 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o aws-alb-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/aws-alb/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle aws-alb-1.0.0.sigstore.json \
  aws-alb-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "90f67ba9318fd455f3b7160eb7dde8178fde966d01f0dfdb1b3f677e4eaef9e1  aws-alb-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "alb" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-alb/aws"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/aws-alb/badge)](https://www.iac-bazaar.com/catalog/aws-alb?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Terraform module 1.0.0, live-tested on IaC Bazaar: [Application Load Balancer](https://www.iac-bazaar.com/catalog/aws-alb?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```hcl
module "alb" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-alb/aws"
  version = "1.0.0"
}
```

Preview:IaC Bazaar: live-tested

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

aws-alb — Application Load Balancer

ALB with HTTPS listeners, target groups, listener rules, and access logging — drop-in for ECS/EC2/Lambda targets. Hand it an ACM certificate and you get a TLS 1.3 (1.2-floor) HTTPS listener with automatic HTTP→HTTPS 301 redirect; define target groups as a simple map and route to them with host/path listener rules. Hardened defaults: invalid-header dropping, desync mitigation, and deletion protection are all on.

Works with Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.

Requirements

  • Terraform or OpenTofu >= 1.6
  • hashicorp/aws >= 6.0, < 7.0

License

Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage
  • Inputs
  • Outputs
  • Notes

Related modules

Static validatedLive test pending

aws-gateway-load-balancer

A Gateway Load Balancer for firewall or IDS appliances, its endpoint service and endpoints. AWS turns cross-zone off, keeps flows on failed appliances and leaves deletion protection off by default; this module turns cross-zone and protection on and makes flow failover an explicit choice. It also says plainly that nothing is inspected until route tables point at the endpoints.

View module
Static validatedLive test pending

aws-global-accelerator

Two anycast addresses in front of load balancers or instances, with per-region endpoint groups, health checks and traffic dials for draining a region without deleting it.

View module
Live-tested

aws-nlb

A Layer-4 Network Load Balancer with map-driven TCP/UDP/TLS listeners and target groups, modern TLS 1.3 termination from an ACM cert, and self-contained default-VPC networking.

View module
Static validatedLive test pending

tencent-clb

A listener's health check is a switch that, off, sends traffic to every target forever; a port-80 listener forwards unless a redirection resource points it at 443; and delete_protect defaults to false. HTTP health checks on a path through listener rules, a 301 from 80 to 443 whenever a certificate is given, deletion protection on, access logs when a CLS topic is given.

View module
Static validatedLive test pending

huawei-elb

The default TLS policy accepts TLS 1.0; a pool without a monitor resource is never unhealthy and sends traffic to every member forever; an HTTPS listener does nothing about port 80 until an L7 policy redirects it; and deletion protection is off. tls-1-2-strict, an HTTP monitor on a path, a redirect on 80 whenever a certificate is given, two zones unless one is accepted, deletion protection on.

View module
Static validatedLive test pending

vultr-load-balancer

The default health check is TCP on the backend port, which a process that stopped serving still passes; ssl_redirect defaults to false, so the site stays in clear on 80; and a balancer with no instances is a public address that fails. HTTP checks on a path, redirect on whenever HTTPS exists, backends required, and a Let's Encrypt certificate from auto_ssl_domain rather than a pasted key in state.

View module