Review load balancer attachment for an Auto Scaling group

Attach a load balancer when an Auto Scaling group needs request distribution.

Description

Without a load balancer or another suitable routing setup, a request-serving Auto Scaling group may not distribute traffic as instances are added or removed. Some workloads, such as queue workers, do not need a load balancer.

Potential impact

Requests may not reach new instances or may continue reaching failed instances.

Remediation

Use LoadBalancerNames for a Classic Load Balancer, or TargetGroupARNs for target groups used by an Application or Network Load Balancer. Configure listeners and health checks for the workload.

Examples

The excerpts attach an existing Classic Load Balancer. Launch template and subnet definitions are omitted.

Before

yaml
Resources:
  WebAsg:
    Type: AWS::AutoScaling::AutoScalingGroup
    Properties:
      MinSize: "1"
      MaxSize: "4"
      DesiredCapacity: "2"
      VPCZoneIdentifier:
        - !Ref PublicSubnetA
        - !Ref PublicSubnetB

After

yaml
Resources:
  WebAsg:
    Type: AWS::AutoScaling::AutoScalingGroup
    Properties:
      MinSize: "1"
      MaxSize: "4"
      DesiredCapacity: "2"
      LoadBalancerNames:
        - web-elb
      VPCZoneIdentifier:
        - !Ref PublicSubnetA
        - !Ref PublicSubnetB

References