Review HTTP traffic through a NIFCLOUD load balancer

Apply actual TLS encryption to public web traffic.

Description

Web requests sent as plain HTTP through a load balancer are not encrypted. Changing the port number to 443 alone does not enable TLS.

Potential impact

An attacker with access to the traffic path may read or alter requests and responses.

Remediation

Forward to a server that handles TLS, or configure load balancer TLS termination with a valid certificate. Set load_balancer_port and instance_port to match the actual service configuration.

Examples

The examples change forwarding from port 80 to port 443. After the change, the backend server must handle TLS on port 443 with a valid certificate.

Before

hcl
resource "nifcloud_load_balancer" "example" {
  load_balancer_name = "example"
  instance_port      = 80
  load_balancer_port = 80
}

After

hcl
resource "nifcloud_load_balancer" "example" {
  load_balancer_name = "example"
  instance_port      = 443
  load_balancer_port = 443
}

References