Linode NodeBalancer Load Balancer
Managed L4/L7 load balancer with TLS termination, health checks, session stickiness, and UDP support.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live test pending (no cloud run yet)
Last verified 2026-06-28 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o linode-nodebalancer-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/linode-nodebalancer/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle linode-nodebalancer-1.0.0.sigstore.json \
linode-nodebalancer-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "60ddba59a2248f6c86dea6416333e5707b6e7aa9c07dff23663529c0bb22c5c7 linode-nodebalancer-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "nodebalancer" {
source = "www.iac-bazaar.com/iac-bazaar/linode-nodebalancer/linode"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads static-verified because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/linode-nodebalancer?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Terraform module 1.0.0, static-verified on IaC Bazaar: [Linode NodeBalancer Load Balancer](https://www.iac-bazaar.com/catalog/linode-nodebalancer?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```hcl
module "nodebalancer" {
source = "www.iac-bazaar.com/iac-bazaar/linode-nodebalancer/linode"
version = "1.0.0"
}
```Preview:
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
linode-nodebalancer
Managed Linode NodeBalancer (L4/L7 load balancer) with TLS-terminating HTTPS
listeners, active health checks, session stickiness, and optional VPC-backed
backends — in one apply. Works with Terraform and OpenTofu (>= 1.6),
Linode provider >= 3.14, < 4.0.
Status: static-validated, live-test pending. This module ships under live-test quarantine: it has passed
tofu fmt,tofu validate, andtflint, but the real apply → verify → destroy gate is pending a Linode sandbox account. Treat the secure defaults below as the contract.
Design & secure defaults
- HTTPS by default. A config's
protocoldefaults tohttps, and the module requiresssl_cert+ssl_keyfor HTTPS listeners (enforced with a plan-time precondition). TLS material issensitive. - Modern ciphers only.
cipher_suiteis pinned torecommended; thelegacysuite (weak ciphers) is rejected by variable validation — opt-in would require a custom build, not a flag. - Health checking on by default. Every config gets active checks
(
check = "connection") plus passive checks (check_passive = true), so a failed backend is pulled out of rotation automatically. - Private-IP backends only. Every node
addressmust be an RFC1918 private IP (validated). Public-IP backends are rejected — backend traffic stays on the private/VPC network. - proxy_protocol is TCP-scoped. The module silently neutralizes
proxy_protocolon non-TCP configs so it can't be misapplied. - Firewalls stay out-of-band. Attach a Cloud Firewall via the
linode-firewallmodule (linode_firewall_device) so rules and balancer lifecycle are decoupled. - Optional VPC backends.
vpc_backendroutes backend traffic over a VPC subnet (newer NodeBalancer feature) instead of the legacy private network.
Requirements
- Terraform or OpenTofu
>= 1.6 linode/linodeprovider>= 3.14, < 4.0- Backend nodes must already exist and be reachable on a private IP (or VPC subnet) before the balancer can mark them healthy.
- VPC-backed backends are a newer Linode feature; confirm regional availability.
License
Commercial — LicenseRef-IaCBazaar-Commercial. © IaC Bazaar. Original work
(not derived from a third-party module).
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
- Inputs
- Outputs
Related modules
tencent-clb
A listener's health check is a switch that, off, sends traffic to every target forever; a port-80 listener forwards unless a redirection resource points it at 443; and delete_protect defaults to false. HTTP health checks on a path through listener rules, a 301 from 80 to 443 whenever a certificate is given, deletion protection on, access logs when a CLS topic is given.
huawei-elb
The default TLS policy accepts TLS 1.0; a pool without a monitor resource is never unhealthy and sends traffic to every member forever; an HTTPS listener does nothing about port 80 until an L7 policy redirects it; and deletion protection is off. tls-1-2-strict, an HTTP monitor on a path, a redirect on 80 whenever a certificate is given, two zones unless one is accepted, deletion protection on.
vultr-load-balancer
The default health check is TCP on the backend port, which a process that stopped serving still passes; ssl_redirect defaults to false, so the site stays in clear on 80; and a balancer with no instances is a public address that fails. HTTP checks on a path, redirect on whenever HTTPS exists, backends required, and a Let's Encrypt certificate from auto_ssl_domain rather than a pasted key in state.
do-load-balancer
The default health check is a TCP handshake, which a process that stopped serving still passes; redirect_http_to_https defaults to false, so the site stays in clear on 80; and a balancer with no tag and no droplets is a public address that 503s. HTTP checks on a path, redirect on whenever HTTPS exists, STRONG ciphers, backends required, and a Let's Encrypt certificate made from your domains.
upcloud-load-balancer
The backend health check defaults to TCP, which a process that stopped serving still passes; TLS is a certificate bundle nobody creates; a port-80 frontend forwards unless a rule redirects it; and a public network puts the frontend on the internet. HTTP checks on a path (TCP by name), a Let's Encrypt bundle for the hostnames you list, a 301 from 80 whenever it exists, and public by name.
scaleway-load-balancer
A Scaleway Load Balancer on a flexible IP with a Let's Encrypt certificate it issues itself (so the DNS must point at it first), TLS at the modern compatibility level (older clients by name), HTTP/3, the port 80 frontend answering only a 301 to HTTPS, and backends named by their Private Network address and probed over HTTP on a path you chose.