1"use strict";(self.webpackChunkcivo_documentation=self.webpackChunkcivo_documentation||[]).push([[4363],{4973:(e,n,a)=>{a.r(n),a.d(n,{assets:()=>o,contentTitle:()=>s,default:()=>h,frontMatter:()=>t,metadata:()=>r,toc:()=>c});const r=JSON.parse('{"id":"networking/load-balancers/internal","title":"Internal Load Balancers","description":"Learn how to create internal load balancers on Civo that are only accessible within your private network, not from the public internet.","source":"@site/content/docs/networking/load-balancers/internal.md","sourceDirName":"networking/load-balancers","slug":"/networking/load-balancers/internal","permalink":"/docs/networking/load-balancers/internal","draft":false,"unlisted":false,"tags":[],"version":"current","lastUpdatedAt":null,"sidebarPosition":2,"frontMatter":{"title":"Internal Load Balancers","description":"Learn how to create internal load balancers on Civo that are only accessible within your private network, not from the public internet.","sidebar_position":2},"sidebar":"mainSidebar","previous":{"title":"Load Balancers","permalink":"/docs/networking/load-balancers/creating-load-balancers"},"next":{"title":"Load Balancer Health Checks","permalink":"/docs/networking/load-balancers/health-checks"}}');var i=a(4848),l=a(8453);const t={title:"Internal Load Balancers",description:"Learn how to create internal load balancers on Civo that are only accessible within your private network, not from the public internet.",sidebar_position:2},s=void 0,o={},c=[{value:"Overview",id:"overview",level:2},{value:"Why Use an Internal Load Balancer?",id:"why-use-an-internal-load-balancer",level:2},{value:"Creating an Internal Load Balancer",id:"creating-an-internal-load-balancer",level:2},{value:"Step 1: Create a Firewall with No Inbound Rules",id:"step-1-create-a-firewall-with-no-inbound-rules",level:3},{value:"Using the Dashboard",id:"using-the-dashboard",level:4},{value:"Using the Civo CLI",id:"using-the-civo-cli",level:4},{value:"Step 2: Create the Load Balancer with the Firewall",id:"step-2-create-the-load-balancer-with-the-firewall",level:3},{value:"Using the Dashboard",id:"using-the-dashboard-1",level:4},{value:"Using Kubernetes",id:"using-kubernetes",level:4},{value:"Verifying Your Internal Load Balancer",id:"verifying-your-internal-load-balancer",level:2},{value:"Check the Load Balancer Status",id:"check-the-load-balancer-status",level:3},{value:"Test Internal Access",id:"test-internal-access",level:3},{value:"Verify Public Access is Blocked",id:"verify-public-access-is-blocked",level:3},{value:"Related Documentation",id:"related-documentation",level:2}];function d(e){const n={a:"a",admonition:"admonition",code:"code",h2:"h2",h3:"h3",h4:"h4",li:"li",ol:"ol",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,l.R)(),...e.components},{Head:a}=n;return a||function(e,n){throw new Error("Expected "+(n?"component":"object")+" `"+e+"` to be defined: you likely forgot to import, pass, or provide it.")}("Head",!0),(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(a,{children:(0,i.jsx)("title",{children:"Creating Internal Load Balancers | Civo Documentation"})}),"\n",(0,i.jsx)(n.h2,{id:"overview",children:"Overview"}),"\n",(0,i.jsx)(n.p,{children:"By default, Civo load balancers are assigned a public IP address and are accessible from the internet. However, you may need a load balancer that is only accessible within your private network for internal services, backend APIs, or microservices communication."}),"\n",(0,i.jsx)(n.p,{children:"An internal load balancer routes traffic only within your Civo private network. External traffic from the internet cannot reach the load balancer, providing an additional layer of security for internal services."}),"\n",(0,i.jsx)(n.h2,{id:"why-use-an-internal-load-balancer",children:"Why Use an Internal Load Balancer?"}),"\n",(0,i.jsx)(n.p,{children:"Internal load balancers are useful when you need to:"}),"\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"Expose internal services"}),": Route traffic to backend services that should not be publicly accessible (databases, internal APIs, message queues)."]}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"Implement microservices architecture"}),": Allow services within your cluster to communicate with each other through a stable endpoint."]}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"Improve security"}),": Reduce the attack surface by keeping internal services off the public internet."]}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"Separate traffic tiers"}),": Use public load balancers for user-facing applications and internal load balancers for backend communication."]}),"\n"]}),"\n",(0,i.jsx)(n.h2,{id:"creating-an-internal-load-balancer",children:"Creating an Internal Load Balancer"}),"\n",(0,i.jsx)(n.p,{children:"To create an internal load balancer, you need to configure a firewall that blocks all inbound traffic from external sources, then attach that firewall to your load balancer."}),"\n",(0,i.jsx)(n.h3,{id:"step-1-create-a-firewall-with-no-inbound-rules",children:"Step 1: Create a Firewall with No Inbound Rules"}),"\n",(0,i.jsx)(n.p,{children:"First, create a firewall that has no inbound rules, effectively blocking all external traffic."}),"\n",(0,i.jsx)(n.h4,{id:"using-the-dashboard",children:"Using the Dashboard"}),"\n",(0,i.jsxs)(n.ol,{children:["\n",(0,i.jsxs)(n.li,{children:["Navigate to ",(0,i.jsx)(n.strong,{children:"Networking"})," > ",(0,i.jsx)(n.strong,{children:"Firewalls"})," in your Civo dashboard."]}),"\n",(0,i.jsxs)(n.li,{children:["Click ",(0,i.jsx)(n.strong,{children:"Create Firewall"}),"."]}),"\n",(0,i.jsxs)(n.li,{children:["Enter a name for your firewall (e.g., ",(0,i.jsx)(n.code,{children:"internal-only"}),")."]}
1),"\n",(0,i.jsx)(n.li,{children:"Do not add any inbound rules."}),"\n",(0,i.jsxs)(n.li,{children:["Click ",(0,i.jsx)(n.strong,{children:"Create Firewall"}),"."]}),"\n"]}),"\n",(0,i.jsx)(n.h4,{id:"using-the-civo-cli",children:"Using the Civo CLI"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"civo firewall create internal-only\n"})}),"\n",(0,i.jsx)(n.p,{children:"This creates a firewall with no rules, which blocks all inbound traffic by default."}),"\n",(0,i.jsx)(n.h3,{id:"step-2-create-the-load-balancer-with-the-firewall",children:"Step 2: Create the Load Balancer with the Firewall"}),"\n",(0,i.jsx)(n.h4,{id:"using-the-dashboard-1",children:"Using the Dashboard"}),"\n",(0,i.jsxs)(n.ol,{children:["\n",(0,i.jsxs)(n.li,{children:["Navigate to ",(0,i.jsx)(n.strong,{children:"Networking"})," > ",(0,i.jsx)(n.strong,{children:"Load Balancers"}),"."]}),"\n",(0,i.jsxs)(n.li,{children:["Click ",(0,i.jsx)(n.strong,{children:"Create Load Balancer"}),"."]}),"\n",(0,i.jsx)(n.li,{children:"Configure your load balancer settings (algorithm, instance pool, ports)."}),"\n",(0,i.jsxs)(n.li,{children:["In the ",(0,i.jsx)(n.strong,{children:"Firewall"})," dropdown, select your ",(0,i.jsx)(n.code,{children:"internal-only"})," firewall."]}),"\n",(0,i.jsxs)(n.li,{children:["Click ",(0,i.jsx)(n.strong,{children:"Create Load Balancer"}),"."]}),"\n"]}),"\n",(0,i.jsx)(n.h4,{id:"using-kubernetes",children:"Using Kubernetes"}),"\n",(0,i.jsxs)(n.p,{children:["When deploying a Kubernetes Service of type ",(0,i.jsx)(n.code,{children:"LoadBalancer"}),", you can specify the firewall using an annotation:"]}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-yaml",children:'apiVersion: v1\nkind: Service\nmetadata:\n name: internal-api\n annotations:\n kubernetes.civo.com/firewall-id: "internal-only"\nspec:\n type: LoadBalancer\n selector:\n app: internal-api\n ports:\n - protocol: TCP\n port: 80\n targetPort: 8080\n'})}),"\n",(0,i.jsx)(n.admonition,{type:"note",children:(0,i.jsxs)(n.p,{children:["The ",(0,i.jsx)(n.code,{children:"kubernetes.civo.com/firewall-id"})," annotation accepts either a firewall name or ID."]})}),"\n",(0,i.jsx)(n.h2,{id:"verifying-your-internal-load-balancer",children:"Verifying Your Internal Load Balancer"}),"\n",(0,i.jsx)(n.p,{children:"After creating your internal load balancer, verify that it is correctly configured."}),"\n",(0,i.jsx)(n.h3,{id:"check-the-load-balancer-status",children:"Check the Load Balancer Status"}),"\n",(0,i.jsx)(n.p,{children:"Ensure the load balancer is active and has been assigned an IP address:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"civo loadbalancer show <loadbalancer-name>\n"})}),"\n",(0,i.jsx)(n.p,{children:"For Kubernetes-managed load balancers:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"kubectl get service internal-api\n"})}),"\n",(0,i.jsxs)(n.p,{children:["The ",(0,i.jsx)(n.code,{children:"EXTERNAL-IP"})," field shows the assigned IP address, even though it is not publicly accessible."]}),"\n",(0,i.jsx)(n.h3,{id:"test-internal-access",children:"Test Internal Access"}),"\n",(0,i.jsx)(n.p,{children:"From an instance or pod within the same private network, verify that you can reach the load balancer:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"curl http://<loadbalancer-ip>\n"})}),"\n",(0,i.jsx)(n.p,{children:"This should return a response from your backend service."}),"\n",(0,i.jsx)(n.h3,{id:"verify-public-access-is-blocked",children:"Verify Public Access is Blocked"}),"\n",(0,i.jsx)(n.p,{children:"From outside your Civo network (your local machine or an external server), attempt to connect:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"curl --connect-timeout 5 http://<loadbalancer-ip>\n"})}),"\n",(0,i.jsx)(n.p,{children:"This connection should time out, confirming that external access is blocked."}),"\n",(0,i.jsx)(n.h2,{id:"related-documentation",children:"Related Documentation"}),"\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.a,{href:"/docs/networking/firewalls",children:"Firewalls"})," - Learn more about configuring firewall rules"]}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.a,{href:"/docs/networking/private-networks",children:"Private Networks"})," - Set up private networks for your instances"]}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.a,{href:"/docs/networking/load-balancers/creating-load-balancers",children:"Load Balancers"})," - General load balancer configuration"]}),"\n"]})]})}function h(e={}){const{wrapper:n}={...(0,l.R)(),...e.components};return n?(0,i.jsx)(n,{...e,children:(0,i.jsx)(d,{...e})}):d(e)}},8453:(e,n,a)=>{a.d(n,{R:()=>t,x:()=>s});var r=a(6540);const i={},l=r.createContext(i);function t(e){const n=r.useContext(l);return r.useMemo((function(){return"function"==typeof e?e(n):{...n,...e}}),[n,e])}function s(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:t(e.components),r.createElement(l.Provider,{value:n},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.