{"id":19978341,"url":"https://github.com/geekcell/terraform-aws-application-load-balancer","last_synced_at":"2025-06-19T11:34:40.640Z","repository":{"id":150853816,"uuid":"599954257","full_name":"geekcell/terraform-aws-application-load-balancer","owner":"geekcell","description":"Terraform module to provision an AWS Application Load Balancer.","archived":false,"fork":false,"pushed_at":"2023-07-01T00:15:24.000Z","size":72,"stargazers_count":1,"open_issues_count":1,"forks_count":0,"subscribers_count":3,"default_branch":"main","last_synced_at":"2025-06-18T14:11:43.366Z","etag":null,"topics":["aws","load-balancer","terraform","terraform-module"],"latest_commit_sha":null,"homepage":"https://www.geekcell.io","language":"HCL","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/geekcell.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2023-02-10T08:51:06.000Z","updated_at":"2023-05-11T12:56:59.000Z","dependencies_parsed_at":null,"dependency_job_id":"c04a1598-7810-4ea7-8bff-a91a924a7bdf","html_url":"https://github.com/geekcell/terraform-aws-application-load-balancer","commit_stats":null,"previous_names":[],"tags_count":5,"template":false,"template_full_name":"geekcell/terraform-aws-module-template","purl":"pkg:github/geekcell/terraform-aws-application-load-balancer","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-application-load-balancer","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-application-load-balancer/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-application-load-balancer/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-application-load-balancer/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/geekcell","download_url":"https://codeload.github.com/geekcell/terraform-aws-application-load-balancer/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-application-load-balancer/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":260742590,"owners_count":23055809,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["aws","load-balancer","terraform","terraform-module"],"created_at":"2024-11-13T03:32:58.376Z","updated_at":"2025-06-19T11:34:35.619Z","avatar_url":"https://github.com/geekcell.png","language":"HCL","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003c!-- BEGIN_TF_DOCS --\u003e\n[![Geek Cell GmbH](https://raw.githubusercontent.com/geekcell/.github/main/geekcell-github-banner.png)](https://www.geekcell.io/)\n\n### Code Quality\n[![License](https://img.shields.io/github/license/geekcell/terraform-aws-application-load-balancer)](https://github.com/geekcell/terraform-aws-application-load-balancer/blob/master/LICENSE)\n[![GitHub release (latest tag)](https://img.shields.io/github/v/release/geekcell/terraform-aws-application-load-balancer?logo=github\u0026sort=semver)](https://github.com/geekcell/terraform-aws-application-load-balancer/releases)\n[![Release](https://github.com/geekcell/terraform-aws-application-load-balancer/actions/workflows/release.yaml/badge.svg)](https://github.com/geekcell/terraform-aws-application-load-balancer/actions/workflows/release.yaml)\n[![Validate](https://github.com/geekcell/terraform-aws-application-load-balancer/actions/workflows/validate.yaml/badge.svg)](https://github.com/geekcell/terraform-aws-application-load-balancer/actions/workflows/validate.yaml)\n[![Lint](https://github.com/geekcell/terraform-aws-application-load-balancer/actions/workflows/linter.yaml/badge.svg)](https://github.com/geekcell/terraform-aws-application-load-balancer/actions/workflows/linter.yaml)\n[![Test](https://github.com/geekcell/terraform-aws-application-load-balancer/actions/workflows/test.yaml/badge.svg)](https://github.com/geekcell/terraform-aws-application-load-balancer/actions/workflows/test.yaml)\n\n\u003c!--\nComment in if Bridgecrew is configured\n\n### Security\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/general)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=INFRASTRUCTURE+SECURITY)\n\n#### Cloud\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/cis_aws)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=CIS+AWS+V1.2)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/cis_aws_13)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=CIS+AWS+V1.3)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/cis_azure)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=CIS+AZURE+V1.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/cis_azure_13)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=CIS+AZURE+V1.3)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/cis_gcp)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=CIS+GCP+V1.1)\n\n##### Container\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/cis_kubernetes_16)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=CIS+KUBERNETES+V1.6)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/cis_eks_11)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=CIS+EKS+V1.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/cis_gke_11)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=CIS+GKE+V1.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/cis_kubernetes)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=CIS+KUBERNETES+V1.5)\n\n#### Data protection\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/soc2)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=SOC2)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/pci)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=PCI-DSS+V3.2)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/pci_dss_v321)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=PCI-DSS+V3.2.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/iso)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=ISO27001)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/nist)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=NIST-800-53)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/hipaa)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=HIPAA)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-application-load-balancer/fedramp_moderate)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-application-load-balancer\u0026benchmark=FEDRAMP+%28MODERATE%29)\n\n--\u003e\n\n# Terraform AWS Application Load Balancer\n\nThis Terraform module provides a preconfigured solution for setting up an\nAWS Application Load Balancer in your AWS account. The Application Load\nBalancer is a highly available and scalable load balancing solution for\nyour applications. With this Terraform module, you can easily and\nefficiently set up and manage your load balancer, ensuring that your\napplications are highly available and can handle increasing traffic.\n\nOur team has extensive experience working with AWS load balancers and\nhas optimized this module to provide the best possible experience for\nusers. The module encapsulates all necessary configurations, making it\neasy to use and integrate into your existing AWS environment. Whether you\nare just getting started with load balancing or looking for a more efficient\nway to manage your applications, this Terraform module provides a\npreconfigured solution for high availability and scalability.\n\n## Inputs\n\n| Name | Description | Type | Default | Required |\n|------|-------------|------|---------|:--------:|\n| \u003ca name=\"input_access_logs_bucket_id\"\u003e\u003c/a\u003e [access\\_logs\\_bucket\\_id](#input\\_access\\_logs\\_bucket\\_id) | The S3 bucket name to store the logs in. | `string` | `\"\"` | no |\n| \u003ca name=\"input_access_logs_bucket_prefix\"\u003e\u003c/a\u003e [access\\_logs\\_bucket\\_prefix](#input\\_access\\_logs\\_bucket\\_prefix) | The S3 bucket prefix. Logs are stored in the root if not configured. | `string` | `\"\"` | no |\n| \u003ca name=\"input_customer_owned_ipv4_pool\"\u003e\u003c/a\u003e [customer\\_owned\\_ipv4\\_pool](#input\\_customer\\_owned\\_ipv4\\_pool) | The ID of the customer owned ipv4 pool to use for this load balancer. | `string` | `null` | no |\n| \u003ca name=\"input_desync_mitigation_mode\"\u003e\u003c/a\u003e [desync\\_mitigation\\_mode](#input\\_desync\\_mitigation\\_mode) | Determines how the load balancer handles requests that might pose a security risk to an application due to HTTP desync. | `string` | `\"strictest\"` | no |\n| \u003ca name=\"input_drop_invalid_header_fields\"\u003e\u003c/a\u003e [drop\\_invalid\\_header\\_fields](#input\\_drop\\_invalid\\_header\\_fields) | Indicates whether HTTP headers with header fields that are not valid are removed by the load balancer (true) or routed to targets (false). | `bool` | `false` | no |\n| \u003ca name=\"input_enable_cross_zone_load_balancing\"\u003e\u003c/a\u003e [enable\\_cross\\_zone\\_load\\_balancing](#input\\_enable\\_cross\\_zone\\_load\\_balancing) | If true, cross-zone load balancing of the load balancer will be enabled. | `bool` | `false` | no |\n| \u003ca name=\"input_enable_deletion_protection\"\u003e\u003c/a\u003e [enable\\_deletion\\_protection](#input\\_enable\\_deletion\\_protection) | If true, deletion of the load balancer will be disabled via the AWS API. | `bool` | `true` | no |\n| \u003ca name=\"input_enable_http2\"\u003e\u003c/a\u003e [enable\\_http2](#input\\_enable\\_http2) | Indicates whether HTTP/2 is enabled in application load balancers. | `bool` | `true` | no |\n| \u003ca name=\"input_enable_http_to_https_redirect\"\u003e\u003c/a\u003e [enable\\_http\\_to\\_https\\_redirect](#input\\_enable\\_http\\_to\\_https\\_redirect) | Whether to create a default HTTP to HTTPS redirect rule. | `bool` | `true` | no |\n| \u003ca name=\"input_enable_security_group\"\u003e\u003c/a\u003e [enable\\_security\\_group](#input\\_enable\\_security\\_group) | Whether to create a security group for the load balancer. | `bool` | `true` | no |\n| \u003ca name=\"input_enable_security_group_default_http_https_rule\"\u003e\u003c/a\u003e [enable\\_security\\_group\\_default\\_http\\_https\\_rule](#input\\_enable\\_security\\_group\\_default\\_http\\_https\\_rule) | Whether to create a default security group rule to allow HTTP and HTTPS traffic from anywhere. | `bool` | `false` | no |\n| \u003ca name=\"input_enable_waf_fail_open\"\u003e\u003c/a\u003e [enable\\_waf\\_fail\\_open](#input\\_enable\\_waf\\_fail\\_open) | Indicates whether to allow a WAF-enabled load balancer to route requests to targets if it is unable to forward the request to AWS WAF. | `bool` | `false` | no |\n| \u003ca name=\"input_idle_timeout\"\u003e\u003c/a\u003e [idle\\_timeout](#input\\_idle\\_timeout) | The time in seconds that the connection is allowed to be idle. | `number` | `60` | no |\n| \u003ca name=\"input_internal\"\u003e\u003c/a\u003e [internal](#input\\_internal) | If true, the LB will be internal. | `bool` | `false` | no |\n| \u003ca name=\"input_ip_address_type\"\u003e\u003c/a\u003e [ip\\_address\\_type](#input\\_ip\\_address\\_type) | The type of IP addresses used by the subnets for your load balancer. | `string` | `\"ipv4\"` | no |\n| \u003ca name=\"input_name\"\u003e\u003c/a\u003e [name](#input\\_name) | Name or prefix of the Role. | `string` | n/a | yes |\n| \u003ca name=\"input_preserve_host_header\"\u003e\u003c/a\u003e [preserve\\_host\\_header](#input\\_preserve\\_host\\_header) | Indicates whether the Application Load Balancer should preserve the Host header in the HTTP request and send it to the target without any change. | `bool` | `false` | no |\n| \u003ca name=\"input_security_group_egress_rules\"\u003e\u003c/a\u003e [security\\_group\\_egress\\_rules](#input\\_security\\_group\\_egress\\_rules) | A list of CIDR blocks to allow ingress traffic from. | `any` | `[]` | no |\n| \u003ca name=\"input_security_group_ingress_rules\"\u003e\u003c/a\u003e [security\\_group\\_ingress\\_rules](#input\\_security\\_group\\_ingress\\_rules) | A list of CIDR blocks to allow ingress traffic from. | `any` | `[]` | no |\n| \u003ca name=\"input_security_groups\"\u003e\u003c/a\u003e [security\\_groups](#input\\_security\\_groups) | A list of security group IDs to assign to the LB. | `list(string)` | `[]` | no |\n| \u003ca name=\"input_subnets\"\u003e\u003c/a\u003e [subnets](#input\\_subnets) | A list of subnet IDs to attach to the LB. | `list(string)` | n/a | yes |\n| \u003ca name=\"input_tags\"\u003e\u003c/a\u003e [tags](#input\\_tags) | Tags to add to the Role. | `map(any)` | `{}` | no |\n\n## Outputs\n\n| Name | Description |\n|------|-------------|\n| \u003ca name=\"output_arn\"\u003e\u003c/a\u003e [arn](#output\\_arn) | ARN of the Application Load Balancer |\n| \u003ca name=\"output_arn_suffix\"\u003e\u003c/a\u003e [arn\\_suffix](#output\\_arn\\_suffix) | The ARN suffix for use with CloudWatch Metrics. |\n| \u003ca name=\"output_dns_name\"\u003e\u003c/a\u003e [dns\\_name](#output\\_dns\\_name) | The DNS name of the load balancer. |\n| \u003ca name=\"output_http_to_https_listener_arn\"\u003e\u003c/a\u003e [http\\_to\\_https\\_listener\\_arn](#output\\_http\\_to\\_https\\_listener\\_arn) | ARN of the HTTP to HTTPS listener |\n| \u003ca name=\"output_security_group\"\u003e\u003c/a\u003e [security\\_group](#output\\_security\\_group) | Security group ID of the Application Load Balancer |\n| \u003ca name=\"output_zone_id\"\u003e\u003c/a\u003e [zone\\_id](#output\\_zone\\_id) | The canonical hosted zone ID of the load balancer (to be used in a Route 53 Alias record) |\n\n## Providers\n\n| Name | Version |\n|------|---------|\n| \u003ca name=\"provider_aws\"\u003e\u003c/a\u003e [aws](#provider\\_aws) | \u003e= 4.4 |\n\n## Resources\n\n- resource.aws_lb.main (main.tf#19)\n- resource.aws_lb_listener.main (main.tf#49)\n- data source.aws_subnet.main (data.tf#1)\n\n# Examples\n### Basic Example\n```hcl\nmodule \"vpc\" {\n  source  = \"registry.terraform.io/terraform-aws-modules/vpc/aws\"\n  version = \"~\u003e 5.0.0\"\n\n  name           = \"main\"\n  cidr           = \"10.100.0.0/16\"\n  azs            = [\"eu-central-1a\", \"eu-central-1b\"]\n  public_subnets = [\"10.100.10.0/24\", \"10.100.11.0/24\"]\n}\n\nmodule \"basic-example\" {\n  source = \"../../\"\n\n  name    = \"my-lb\"\n  subnets = module.vpc.public_subnets\n\n  enable_security_group_default_http_https_rule = true\n}\n```\n\u003c!-- END_TF_DOCS --\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgeekcell%2Fterraform-aws-application-load-balancer","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fgeekcell%2Fterraform-aws-application-load-balancer","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgeekcell%2Fterraform-aws-application-load-balancer/lists"}