Create a rule for HTTP or HTTPS traffic
Control panel
OpenStack CLI
-
In the Control panel, in the top menu, click Products and select Cloud Servers.
-
Go to Load Balancers → the Load Balancers tab.
-
Open the load balancer page.
-
Click Create rule.
-
Select the traffic reception protocol — HTTP or HTTPS.
-
For the selected protocol, the standard port on which the load balancer will listen for traffic will be automatically selected — change it if necessary.
-
Optional: enter allowed CIDRs — IP addresses from which the load balancer will accept traffic with the selected protocol and port. You can enter a subnet in CIDR format or a single IP address with a mask
/32. If you leave the field empty, the load balancer will accept traffic from any IP addresses. You can specify allowed IP addresses in the rule after creating the load balancer.If the field is missing, traffic filtering (port security) is disabled on the load balancer network.
-
If you selected the HTTPS protocol, specify a certificate for terminating HTTPS traffic on the load balancer — select a certificate from the secret manager or upload a new one. Learn more in the Load Balancer TLS (SSL) Certificates instructions.
-
Select a default target group or create a new target group with the HTTP protocol. Traffic that does not match HTTP policies will be forwarded to the default target group. To drop traffic that does not match HTTP policies, select No target group.
-
Select the HTTP request headers that will be passed to the servers.
-
Optional: create HTTP policies:
11.1.Click Add new policy.
11.2. Select the parameter to check the request against:
HOSTNAME— to check the domain name;PATH— to check the path.
11.3. Select the match type for the reference value:
EQUAL TO— matches;STARTS WITH— starts with;ENDS WITH— ends with;CONTAINS— contains;REGEX— regular expression.
11.4.Enter a check value. If you selected the
REGEXcondition in step 11.3, enter a regular expression.11.5.Optional: to add another condition to the policy, click New condition and configure it. If there are multiple conditions in a policy, a request must match each of them to fall under the policy.
11.6. Specify where to direct matching requests:
- Forward to target group — select a target group or create a new one with the HTTP protocol;
- Redirect to URL — enter the target URL that will completely replace the request URL, including the protocol, domain name, path, and query parameters;
- Redirect to URL prefix — enter the part of the URL to replace the protocol and domain name in the request URL. For example, if you enter
https://example.com/new, a request tohttps://example.com/apiwill be redirected tohttps://example.com/new/api
To reject requests matching the policy, select Reject traffic.
11.7. Enter a policy name or leave the one generated by default.
11.8. Click Add.
11.9. Optional: to add another policy, click Add new policy and configure it.
-
Optional: change connection settings; to do this, open the Advanced rule settings section and specify:
- for incoming requests to the load balancer — specify the connection timeout and maximum connections;
- for requests from the load balancer to servers — specify the connection timeout, inactivity timeout, and TCP packet wait timeout.
-
Click Create.