How the internet works · Lesson 8 · 35 min

Load balancers, proxies & CDNs

One server can only do so much, and it will break one day. Real sites run several copies of their app and put a load balancer in front: it spreads the visitors out and quietly stops sending them to a copy that's broken. Further out, a CDN keeps copies of the site's files all over the world, close to the visitors. This lesson puts both in front of the club's website.

You will learn

  • What a load balancer does, and how it chooses a server
  • Health checks: why one broken server doesn't take the site down
  • Layer 4 vs layer 7, reverse vs forward proxies, and X-Forwarded-For
  • Setting up HAProxy on Rocky and Ubuntu
  • How a CDN caches, and how to read HIT, MISS and Age

Spreading the load

                  ┌─▶ web1 (127.0.0.1:8081)
visitors ─▶ HAProxy :80 ─▶ web2 (127.0.0.1:8082)
                  └─▶ web3 (127.0.0.1:8083)

Visitors only ever talk to the load balancer. It picks a server for each request (or connection), using one of a few algorithms:

AlgorithmHow it picksGood for
roundrobinEach server in turn: 1, 2, 3, 1, 2, 3…Most web apps (the default)
leastconnThe server with the fewest open connectionsLong requests, like downloads or websockets
sourceThe same visitor always goes to the same server (a hash of their IP)Apps that keep a user's session in one server's memory ("sticky sessions")

Health checks

A load balancer keeps knocking on every server (every 2 seconds by default in HAProxy). When a server stops answering, it's marked DOWN and gets no more visitors until it's healthy again. That's how you can restart or update one server at a time without anyone noticing. Forget the check keyword and HAProxy never notices a dead server: some visitors get errors.

Layer 4 vs layer 7

Because the app now only sees connections from the balancer, it loses the visitor's real address. Layer 7 balancers add it to a header, X-Forwarded-For (HAProxy: option forwardfor), so logs and rate limits still work.

Reverse vs forward proxy

A reverse proxy sits in front of servers and acts for them, like HAProxy here or Apache in lesson 6. A forward proxy sits in front of users and acts for them, like a school's web filter. Same idea, opposite side.

HAProxy on each family

HAProxy's config is the same everywhere. Installing and starting it is where the families differ:

TaskRocky / RHELUbuntu / Debian
Installsudo dnf install haproxy (2.4)sudo apt install haproxy (2.8)
After installingnot running; the sample config listens on port 5000already running, with a config that does nothing yet
Config file/etc/haproxy/haproxy.cfg same on both
Check the configsudo haproxy -c -f /etc/haproxy/haproxy.cfg same on both
Logsjournalctl -u haproxyjournalctl -u haproxy and /var/log/haproxy.log
A real-life gotchaSELinux may stop HAProxy reaching servers on unusual ports: sudo setsebool -P haproxy_connect_any 1(AppArmor doesn't confine HAProxy by default)

A minimal config has a frontend (where visitors arrive) and a backend (the servers):

frontend club
    bind *:80
    default_backend club_apps

backend club_apps
    balance roundrobin
    server web1 127.0.0.1:8081 check
    server web2 127.0.0.1:8082 check

CDNs: copies close to the visitors

A CDN (content delivery network, like Cloudflare, Fastly or CloudFront) is a huge network of caching reverse proxies in cities all over the world. DNS sends each visitor to a nearby edge server. If the edge has a fresh copy of the file, it answers straight away (HIT). If not, it fetches it from your server, the origin, keeps a copy, and answers (MISS).

Try it: put a load balancer in front 🎛️

The club's web app now runs three copies on this server (web1, web2, web3, ports 8081–8083), but nothing spreads the visitors over them. A colleague left a starter config in ~/club-lb.cfg. Set up HAProxy, prove it balances, then break a server on purpose.

Quick check

1. You stop one of three web servers behind HAProxy. Visitors keep getting the site with no errors. Why?

2. Behind a load balancer, your app's logs show every visitor as 127.0.0.1. What's the fix?

3. You changed logo.png on your server, but visitors still see the old one. The CDN says x-cache: HIT, age: 3000. Why?

Finished the missions and the quiz? Mark it done to track your progress.