Skip to main content

Load Balancers (Octavia LBaaS)

Okustera Load Balancing-as-a-Service (LBaaS) is powered by OpenStack Octavia, delivering high-availability Layer 4 (TCP/UDP) and Layer 7 (HTTP/HTTPS) traffic distribution with automated health monitoring and TLS termination.

Load balancers run as redundant, active-standby amphora instances with dedicated Virtual IPs (VIPs) connected directly to your private VPC networks or external floating IP pools.


Key Capabilities​

  • High-Availability VIPs: Dedicated virtual IPs with sub-second failover between active and standby amphora worker instances.
  • L4 & L7 Traffic Distribution: Route TCP, UDP, HTTP, and HTTPS traffic across compute instances, containers, or bare-metal endpoints.
  • SSL/TLS Termination: Offload TLS encryption at the load balancer VIP using certificates stored securely in OpenStack Barbican.
  • Automated Health Monitoring: Continuous active polling of backend members via HTTP GET, TCP ping, or UDP probes to automatically divert traffic away from unhealthy servers.
  • Balancing Algorithms: Support for Round Robin, Least Connections, and Source IP hash.
  • Cloud Portal Management: Full graphical lifecycle controls in the Okustera Cloud Portal under Networking $\to$ Load Balancers.

Architecture Overview​


Configuring Load Balancers in the Cloud Portal​

You can manage the complete load balancer lifecycle from the Okustera Cloud Portal:

  1. Navigate to Networking $\to$ Load Balancers (/octavia).
  2. Click Create Load Balancer:
    • Name: web-production-lb
    • VPC Subnet: Select your private application subnet (tenant-vpc-subnet).
    • IP Address: Leave empty for dynamic allocation or specify a static private VIP.
  3. Configure Listeners:
    • Protocol: HTTP (Port 80) or TERMINATED_HTTPS (Port 443).
    • For HTTPS, select your TLS certificate from the Barbican certificate store.
  4. Define the Backend Pool & Members:
    • Algorithm: ROUND_ROBIN or LEAST_CONNECTIONS.
    • Add members by selecting running compute instances or entering their private IP addresses and target ports (e.g. 8080).
  5. Configure Health Monitor:
    • Type: HTTP
    • Path: /healthz or /
    • Interval: 5 seconds, Timeout: 3 seconds, Max Retries: 3.

Declarative Management via Terraform​

# 1. Allocate Load Balancer VIP on private VPC subnet
resource "okustera_loadbalancer" "web_lb" {
name = "web-production-lb"
vip_subnet_id = okustera_network.tenant_vpc.subnet_id
description = "Production Web Ingress Load Balancer"
}

# 2. Attach a Floating IP for public internet access
resource "okustera_floating_ip" "lb_fip" {
pool = "public_external"
}

resource "okustera_floating_ip_associate" "lb_fip_assoc" {
floating_ip = okustera_floating_ip.lb_fip.address
port_id = okustera_loadbalancer.web_lb.vip_port_id
}

# 3. Create HTTP Listener, Pool, and Health Monitor via OpenStack Provider
resource "openstack_lb_listener_v2" "http_listener" {
name = "http-listener"
protocol = "HTTP"
protocol_port = 80
loadbalancer_id = okustera_loadbalancer.web_lb.id
}

resource "openstack_lb_pool_v2" "web_pool" {
name = "web-backend-pool"
protocol = "HTTP"
lb_method = "ROUND_ROBIN"
listener_id = openstack_lb_listener_v2.http_listener.id
}

resource "openstack_lb_monitor_v2" "web_monitor" {
name = "web-health-monitor"
pool_id = openstack_lb_pool_v2.web_pool.id
type = "HTTP"
url_path = "/healthz"
delay = 5
timeout = 3
max_retries = 3
}

resource "openstack_lb_member_v2" "app_server_1" {
pool_id = openstack_lb_pool_v2.web_pool.id
address = "192.0.2.10"
protocol_port = 8080
}

resource "openstack_lb_member_v2" "app_server_2" {
pool_id = openstack_lb_pool_v2.web_pool.id
address = "192.0.2.11"
protocol_port = 8080
}

REST API Reference​

Load balancer operations can be executed programmatically via the Okustera API:

  • GET /api/v1/octavia/loadbalancers — List active load balancers and provisioning status.
  • POST /api/v1/octavia/loadbalancers — Provision a new load balancer.
  • GET /api/v1/octavia/loadbalancers/{id} — Retrieve status and VIP details.
  • DELETE /api/v1/octavia/loadbalancers/{id} — Decommission load balancer.
  • GET /api/v1/octavia/listeners — List listeners associated with tenant load balancers.
  • GET /api/v1/octavia/pools — List backend pools and member health states.