Load Balancers (Octavia LBaaS)
Okustera Load Balancing-as-a-Service (LBaaS) is powered by OpenStack Octavia, delivering high-availability Layer 4 (TCP/UDP) and Layer 7 (HTTP/HTTPS) traffic distribution with automated health monitoring and TLS termination.
Load balancers run as redundant, active-standby amphora instances with dedicated Virtual IPs (VIPs) connected directly to your private VPC networks or external floating IP pools.
Key Capabilities
- High-Availability VIPs: Dedicated virtual IPs with sub-second failover between active and standby amphora worker instances.
- L4 & L7 Traffic Distribution: Route TCP, UDP, HTTP, and HTTPS traffic across compute instances, containers, or bare-metal endpoints.
- SSL/TLS Termination: Offload TLS encryption at the load balancer VIP using certificates stored securely in OpenStack Barbican.
- Automated Health Monitoring: Continuous active polling of backend members via HTTP GET, TCP ping, or UDP probes to automatically divert traffic away from unhealthy servers.
- Balancing Algorithms: Support for Round Robin, Least Connections, and Source IP hash.
- Cloud Portal Management: Full graphical lifecycle controls in the Okustera Cloud Portal under Networking $\to$ Load Balancers.
Architecture Overview
Configuring Load Balancers in the Cloud Portal
You can manage the complete load balancer lifecycle from the Okustera Cloud Portal:
- Navigate to Networking $\to$ Load Balancers (
/octavia). - Click Create Load Balancer:
- Name:
web-production-lb - VPC Subnet: Select your private application subnet (
tenant-vpc-subnet). - IP Address: Leave empty for dynamic allocation or specify a static private VIP.
- Name:
- Configure Listeners:
- Protocol:
HTTP(Port 80) orTERMINATED_HTTPS(Port 443). - For HTTPS, select your TLS certificate from the Barbican certificate store.
- Protocol:
- Define the Backend Pool & Members:
- Algorithm:
ROUND_ROBINorLEAST_CONNECTIONS. - Add members by selecting running compute instances or entering their private IP addresses and target ports (e.g.
8080).
- Algorithm:
- Configure Health Monitor:
- Type:
HTTP - Path:
/healthzor/ - Interval:
5 seconds, Timeout:3 seconds, Max Retries:3.
- Type:
Declarative Management via Terraform
# 1. Allocate Load Balancer VIP on private VPC subnet
resource "okustera_loadbalancer" "web_lb" {
name = "web-production-lb"
vip_subnet_id = okustera_network.tenant_vpc.subnet_id
description = "Production Web Ingress Load Balancer"
}
# 2. Attach a Floating IP for public internet access
resource "okustera_floating_ip" "lb_fip" {
pool = "public_external"
}
resource "okustera_floating_ip_associate" "lb_fip_assoc" {
floating_ip = okustera_floating_ip.lb_fip.address
port_id = okustera_loadbalancer.web_lb.vip_port_id
}
# 3. Create HTTP Listener, Pool, and Health Monitor via OpenStack Provider
resource "openstack_lb_listener_v2" "http_listener" {
name = "http-listener"
protocol = "HTTP"
protocol_port = 80
loadbalancer_id = okustera_loadbalancer.web_lb.id
}
resource "openstack_lb_pool_v2" "web_pool" {
name = "web-backend-pool"
protocol = "HTTP"
lb_method = "ROUND_ROBIN"
listener_id = openstack_lb_listener_v2.http_listener.id
}
resource "openstack_lb_monitor_v2" "web_monitor" {
name = "web-health-monitor"
pool_id = openstack_lb_pool_v2.web_pool.id
type = "HTTP"
url_path = "/healthz"
delay = 5
timeout = 3
max_retries = 3
}
resource "openstack_lb_member_v2" "app_server_1" {
pool_id = openstack_lb_pool_v2.web_pool.id
address = "192.0.2.10"
protocol_port = 8080
}
resource "openstack_lb_member_v2" "app_server_2" {
pool_id = openstack_lb_pool_v2.web_pool.id
address = "192.0.2.11"
protocol_port = 8080
}
REST API Reference
Load balancer operations can be executed programmatically via the Okustera API:
GET /api/v1/octavia/loadbalancers— List active load balancers and provisioning status.POST /api/v1/octavia/loadbalancers— Provision a new load balancer.GET /api/v1/octavia/loadbalancers/{id}— Retrieve status and VIP details.DELETE /api/v1/octavia/loadbalancers/{id}— Decommission load balancer.GET /api/v1/octavia/listeners— List listeners associated with tenant load balancers.GET /api/v1/octavia/pools— List backend pools and member health states.