#application-load-balancer
"Building a 3-Tier Web App on AWS: Security & HA" by MULIK ANIKET AJAY

Building a 3-Tier Web App on AWS: Security & HA
Learn how to design a secure 3-tier AWS web application using VPC, EC2, Nginx, Tomcat, RDS, IAM, Load Balancer, and CloudWatch.
community.aws
September 30, 2026 at 5:00 PM
Scoped measurement: Quota is measured and enforced on a per-project, per-region, or per-VPC depending on Application Load Balancer type. Active consumption: Only URL maps currently referenced by forwarding rules contribute to quota usage
September 30, 2026 at 2:40 PM
"What Happens When a Shop Gets Huge Traffic During a Sale? HOW " by santhosh kumar

#auto-scaling #load-balancer #load-balancing #amazon-ec2 #community
What Happens When a Shop Gets Huge Traffic During a Sale? HOW
How Application Load Balancer and Auto Scaling works in real time
community.aws
September 25, 2026 at 6:00 AM
わかってたことではあるんだが、個人開発でAWSはApplication Load BalancerとRDSが金かかるなぁ・・・
September 24, 2026 at 12:31 AM
It's unbelievable that in 2026 AWS Application Load Balancer still has hard limit on lambda payload size ~ 1 (one) Megabyte. And even more bizarre returning 810 Kilobyte JSON from Lambda somehow hits that limit causing 502 HTTP error. docs.aws.amazon.com/elasticloadb...
Use Lambda functions as targets of an Application Load Balancer - Elastic Load Balancing
Learn how to register a Lambda function as a target with an Application Load Balancer.
docs.aws.amazon.com
September 23, 2026 at 1:28 AM
Use Application Load Balancer with host header rewrite to expose AWS Lambda MicroVMs under custom domains without CloudFront or compute in the request path.
Adding custom domains to AWS Lambda MicroVMs with Application Load Balancer
Use Application Load Balancer with host header rewrite to expose AWS Lambda MicroVMs under custom domains without CloudFront or compute in the request path.
aws-news.com
September 22, 2026 at 4:53 PM
📰 New article by Frank Scarfo, Ben Freiberg

Adding custom domains to AWS Lambda MicroVMs with Application Load Balancer

#AWS #Compute
Adding custom domains to AWS Lambda MicroVMs with Application Load Balancer
Many teams want to expose their AWS Lambda MicroVMs under a custom domain they own, and satisfy CORS for browser clients, without changing the application. This post shows how, using an Application Load Balancer that rewrites the Host header and forwards over AWS PrivateLink, deployed with the AWS CDK.
aws.amazon.com
September 22, 2026 at 4:56 PM
"Implementing an Application Load Balancer health check that distinguishes a running process from a working application" by Frank Poma

Implementing an Application Load Balancer health check that distinguishes a running process from a working application
A hands-on guide to building shallow health checks for Apache and IIS behind an Application Load Balancer, avoiding a common threshold anti-pattern, and validating detection and recovery times with real measurements instead of assumptions.
community.aws
September 16, 2026 at 4:00 AM
📰 New article by Akber Rizwan Shaik, Amardeep Kumar Agrawal, Guido Pomidoro

Scale multi-tenant SaaS with per-tenant version pinning using Amazon CloudFront

#AWS #DotNet
Scale multi-tenant SaaS with per-tenant version pinning using Amazon CloudFront
Multi-tenant SaaS providers often need to control which application version each tenant runs, a practice called per-tenant version pinning, so they can roll out new releases incrementally and move tenants between versions without downtime and manual changes. A common approach is to configure the Application Load Balancer with hostname-based routing rules, but this doesn’t scale. [...]
aws.amazon.com
September 15, 2026 at 6:21 PM
"Protegendo aplicações na AWS: bloqueando Path Traversal e restringindo acesso por país com AWS WAF + Application Load Balancer" by Luiz Inhesta

#aws-waf #application-load-balancer #instances #amazon-route53 #aws-certificate-manager
Protegendo aplicações na AWS: bloqueando Path Traversal e restringindo acesso por país com AWS WAF + Application Load Balancer
O laboratório AWS WAF Security Lab — Projeto 02, um estudo prático de como o AWS WAF protege aplicações web quando associado a um Application Load Balancer (ALB).
community.aws
September 13, 2026 at 9:00 PM
I wanted a system-design lab that could prove me wrong
When I practice system design, the part that has always felt a little unsatisfying is that the diagram usually gets the final say. You can draw a load balancer, put PostgreSQL behind your application servers, add a private subnet, and end up with something that looks perfectly reasonable. But the diagram itself never proves that PostgreSQL is actually private. That is the idea I kept coming back to while building **Torollo** : > **What if the diagram was only the intended architecture, and the running system was the thing that decided whether you were right?** That became the core of the project. ## The architecture actually runs Torollo is a local system-design lab. You build an architecture visually, but the nodes on the canvas are backed by real Docker resources on your machine. If you add a server, there is a container behind it. If an exercise uses PostgreSQL, PostgreSQL is actually running. If the architecture introduces network boundaries, Torollo has real Docker networking underneath them. The roadmap then validates the environment that exists instead of checking whether your diagram looks correct. One of the free roadmaps, for example, has you build a resilient three-tier application. You start with a web server and a database, then progressively introduce: * a load balancer * multiple web servers * network restrictions * failure scenarios At one point, PostgreSQL is supposed to be isolated from the load balancer. Torollo actually checks that. If the load balancer can still reach PostgreSQL on port `5432`, the step fails. You change the configuration, run the validator again, and the step only turns green when that connection is really blocked. That loop ended up becoming the part of Torollo I care about the most: > **Build something → make an assumption → let the runtime prove whether the assumption is true.** ## The canvas is only one layer The frontend is built with: * React * TypeScript * React Flow The backend uses: * Node.js * Express * TypeScript * Dockerode But I try to keep a strict separation between what the canvas says exists and what Torollo can actually observe. If the frontend says a server exists, that is not enough for a validator. The validator can inspect whether the container is actually running. If an architecture says an application can reach its database, Torollo can test that connection. If a roadmap asks you to create a table, the validator can inspect PostgreSQL. If the exercise uses Redis, it can inspect actual Redis state. That was an important design decision for me, because otherwise Torollo would just become another graph editor with a green checkmark attached to it. > **The runtime has to be able to disagree with the diagram.** ## Docker networking made this much harder The container lifecycle was relatively straightforward. Networking was not. Some Torollo labs use Docker bridge networks, routing, NAT and `iptables` rules to make the architecture behave differently depending on how you configure it. That is where I started running into the fact that "runs on Docker" does not mean every Docker environment behaves identically. Rootless Docker is a good example. It can run the containers, but some of the advanced networking behavior Torollo uses requires capabilities that a rootless daemon cannot provide in the same way. Initially, I wanted to hide details like that from the learner. I eventually decided that was the wrong abstraction. Torollo is specifically trying to make infrastructure behavior tangible. Pretending that the underlying environment does not matter would work against that. So the CLI now includes: npx torollo doctor It checks the Docker environment, ports and some runtime requirements and tries to explain what is wrong before you spend time debugging an exercise that your machine cannot execute properly. That feature came directly from repeatedly debugging what looked like Torollo failures and discovering that the actual problem was the environment. ## I’m not trying to recreate AWS locally This is probably the easiest trap for a project like Torollo to fall into. Once you have containers, databases, load balancing, queues, caching and networking, there is always another infrastructure primitive you could implement. But I don’t want Torollo to become a fake cloud provider. The goal is much narrower: > **Take an architecture concept and make enough of it real that the learner can be wrong about it.** If you say a database is isolated, there should be a way to test that claim. If you introduce a cache, it should contain real state. If a worker is supposed to process a queue, there should be an actual worker and queue involved. If a failure is part of the exercise, something should really fail. The local environment is there to make the consequences of the architecture visible, not to pretend that Docker on a laptop is equivalent to production infrastructure. ## What Torollo includes right now The current public version has three free roadmaps: * a resilient three-tier application * Redis cache-aside * Redis queue workers The roadmap format is JSON, so the exercises are not hardcoded into the application. The core is **MIT licensed**. It runs locally. There is **no account requirement**. You currently need: * Node 18+ * Docker **Repository:** https://github.com/Derssa/Torollo **Three-tier roadmap:** https://torollo.app/r/devto ## The question I’m trying to answer next I think making the runtime real improves some parts of learning system design. "PostgreSQL is private" stops being something written next to a box and becomes a statement that can actually be false. But there is obviously a limit. A local Docker environment does not reproduce IAM, managed services, cloud control planes, real latency, production observability, regional failures and all the other things that shape real systems. So the question I’m trying to understand now is: > **Where does making the runtime real improve the way you learn system design, and where does it start creating the wrong mental model?** If you work with backend systems, Docker, DevOps, SRE or infrastructure, that is the feedback I would be most interested in.
dev.to
September 12, 2026 at 1:34 PM
"What I Learned Moving a Single-Server FastAPI App to an AWS High-Availability Architecture" by Ashen

#amazon-ec2 #auto-scaling #application-load-balancer #compute #amazon-vpc
What I Learned Moving a Single-Server FastAPI App to an AWS High-Availability Architecture
My experience moving FastAPI app from single server to AWS eco system and what i learned while doing it
community.aws
September 8, 2026 at 8:00 AM
The example below shows how you setup the AWS Load Balancer Controller with an IAM Roles for Service Accounts (IRSA) role and target-type ip, so the Application Load Balancer (ALB) registers pod IPs. This nice intro from Collin Smith gets you started.
September 7, 2026 at 4:14 PM
CVE-2026-84186 - Incorrect access control in PrestaShop
CVE ID : CVE-2026-84186

Published : Sept. 7, 2026, 8:39 a.m. | 50 minutes ago

Description : Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the cli...
CVE-2026-84186 - Incorrect access control in PrestaShop
Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse proxy, load balancer or CDN. The application incorrectly processes the IP address string and uses the address controlled …
cvefeed.io
September 7, 2026 at 9:46 AM
In this post, you will learn how to create an AWS Application Load Balancer (ALB) for your EC2 instances running a Spring Boot application. You will also create an Autoscaling Group (ASG).
#aws
How to Create an AWS ALB and ASG
In this post, you will learn how to create an AWS Application Load Balancer (ALB) for your EC2 instances running a Spring Boot application. You will also create an Autoscaling Group (ASG) which wil…
mydeveloperplanet.com
September 5, 2026 at 6:22 PM