Load Balancers

Infrastructure > Load Balancers

Overview

HPE Morpheus Software can provision VM or Container HaProxy Load Balancers, Amazon Elastic and Application Load Balancers, Azure Load Balancers, and integrates with several external Load Balancers, including F5, Citrix, and AVI.

Once created or integrated, Load Balancers are available as an option to be added during provision time or post-provisioning.

Once a Load Balancer is added to an instance, you can manually scale or configure auto-scaling based on thresholds or schedules, and burst across clouds with cloud priority.

In the Load Balancers page there are two sections:

Load Balancers

View or edit existing Load Balancers, add new Load Balancers.

Virtual Servers

View and link to Instances that are attached to load balancers.

Group and Tenant Access

Load balancers can be configured to provide specific Group and Tenant access, if desired. Group Access controls which Groups at provision time will have access to the load balancer resource. Only workloads being provisioned to the selected Groups would have visibility to the load balancer. Workloads provisioned to other Groups would not see the load balancer as an available selection. Tenant Permissions control which Tenants may see the load balancer. Public visibility allows access to the load balancer for users in all Tenants (subject to additional RBAC controls) while Private visibility allows access only for selected Tenants. Select all that may apply.

Load Balancers

The Load Balancers tab list currently available Load Balancers, which you can select, edit or delete, and is where you can create new or integrate with external Load Balancers.

Add a new Load Balancer

Select + LOAD BALANCER, chose an option, and fill in the required information:

Amazon ALB
  • Scheme

  • Internal

  • Internet-Facing

  • Amazon Subnets (Select + to add additional) * Specify the subnets to enable for your load balancer. You can specify only one subnet per Availability Zone. You must specify subnets from at least two Availability Zones to increase the availability of your load balancer.

  • Amazon Security Groups (Select + to add additional)

AVI
  • API Host

  • API Port

  • Username

  • Password

  • Internal IP

  • Public IP

  • VIP Address

  • VIP Port

Azure Load Balancer
  • Cloud

  • Resource Group * Populated from cloud selection

Citrix NetScaler
  • API Host

  • API Port

  • Username

  • Password

F5 BigIP (v11.4+)
  • API Host

  • API Port

  • Username

  • Password

  • Management URL

FortiADC
  • API HOST

  • API PORT

  • USERNAME

  • PASSWORD

  • INTERFACE (synced on auth)

HaProxy Container (Internal, will create a HaProxy container, must have available docker host to provision to)
  • Group

  • Cloud

  • Name

  • Description

  • Plan * Select the size of HaProxy container to be provisioned

NSX Load Balancer
  • NSX

  • Name

  • Description

  • Enabled

  • Admin State

  • Size

  • Tier-1 Gateways

  • Log Level

Upon saving your new Load Balancer will be added to the Load Balancers list and available in the Load Balancer dropdown in the Provisioning Wizard Automation Section for Instance Types that have scaling enabled.

Load Balancer Detail Pages

In the main Load Balancer page, select an existing Load Balancer to go to that Load Balancers Details Page, which lists Stats, Settings, Actions and Virtual Servers for that load balancer.

Orchestrating Load Balancers

A large part of application orchestration and automation involves tying various web services and backend services into different load balancer configurations. If the automation tool is unable to communicate or integrate with this aspect of your infrastructure, a lot of gaps will be created in the full orchestrated flow of application deployment. This is why Morpheus provides deep integration with load balancers and explicit definitions with catalog items as to how they are connected to provisioned instances. Some of the functionality includes:

  • Public Cloud Load Balancer Support

  • Private Cloud Load Balancer Support

  • Port Type definitions (Profiles like HTTP/HTTPS or UDP)

  • SSL Certificate Management and SSL Certificate Upload

  • SSL Passthrough or Forced Redirect

Not only does Morpheus have an ability to provision HAProxy based load balancer containers for easy consumption in development environments, but also has direct tie ins with several Load Balancer Types:

  • F5 BigIP

  • Netscaler

  • NSX Advanced Load Balancer

  • Amazon ELB

  • Amazon ALB

  • Azure Load Balancer

  • Fortinet

  • Openstack Octavia

  • HA Proxy

  • NSX

Morpheus exposes configuration options during provisioning of an Instance relevant and common to each supported LB Integration. In some cases, Morpheus also provides direct management and sync support for VIP configurations on the various Load Balancers (such as F5, and NSX Advanced Load Balancer), However in a day to day orchestrated workflow this would not be the ideal means by which a user should consume load balancer services.

By tying the Load Balancer associations into the provisioning of instances and the definition of the instance catalog item, the lifecycle of the VIP can more easily be maintained throughout the lifecycle of whatever application may be deployed.

Setting up an Instance for Load Balancer Consumption

Several of the provided Morpheus instance types are ready to go with load balancer orchestration out of the box (Apache, Nginx, Tomcat, Node.js, etc). It is also fairly easy to extend existing generic instance types during provisioning to be tied to load balancers or to set up said catalog items in advanced for such functionality.

When creating a custom Instance Type (in Library), one can define a list of exposed ports that the node type within the instance exposes. When defining these exposed ports it prompts for a Name, Port Number, and LB Type. The LB Type is what enables load-balancer functionality. This can either be HTTP,HTTPS, or TCP. This specification helps build the correct profile for the VIP as well as setup the appropriate types of Health Monitors within the target load balancer integration.

Now, when a user consumes this custom instance type (either through single instance provisioning or full application blueprint provisioning), a section appears in the Automation phase of provisioning. Each port that is defined that exposes a load-balancer gets a dropdown to choose which load balancer integration attach to the exposed port and various prompts become available.

These prompts control features ranging from target VIP Address to selecting an SSL Certificate to be applied to the VIP. These SSL Certificates will even go so far as to create SSL Profiles in integrations for things like an F5 automatically for the application.

Once the instance is provisioned, as part of the final phase, the load balancer configuration will be applied and maintained on the instance. This association can be manipulated after the fact via the “Scale” tab found on the Instance Detail page.

Another benefit to associating load-balancers this way is that the pool members are automatically maintained during scaling events, either via auto-scaling thresholds or manual node additions / removals.

F5 Load Balancers

Add F5 Load Balancer

To add a F5 Load Balancer Integration:

  1. Navigate to Infrastructure > Load Balancers

  2. Select + ADD

  3. Select F5 BigIP

  4. Fill in the following:

    GROUP

    Select the Group the Load Balancer will be available for

    CLOUD

    Select the Cloud the Load Balancer will be available for

    NAME

    Name of the Load Balancer in HPE Morpheus Software

    DESCRIPTION

    Identifying information displayed on the Load Balancer list page.

    VISIBILITY

    Define Multi-Tenant permissions

    API HOST

    IP or resolvable hostname url.

    API PORT

    Typically 8443

    USERNAME

    API user

    PASSWORD

    API user password

    MANAGEMENT URL

    Example: https://10.30.20.31:8443/xui/

    Advanced Options (optional)
    • VIRTUAL NAME

    • POOL NAME

    • SERVER NAME

  5. Save Changes

Important

The F5 API handles SSL certificate installation by downloading the certificate from a URL the user provides. HPE Morpheus Software provides the “Appliance URL” configured in global settings (Administration > Settings > Appliance) to satisfy that requirement. Make sure you have configured a valid URL in this field and that F5 can reach it.

Virtual Servers

Instances attached to an F5 will be listed in the Virtual servers tab. Virtual servers can also be manually added in this section.

Add Virtual Server

  1. Navigate to Infrastructure > Load Balancers

  2. Select F5 Integration name to drill into the detail page

  3. Select + ADD in the VIRTUAL SERVERS tab

  4. Fill in the following:

    • NAME

      Name of the Virtual Server in HPE Morpheus Software

    • DESCRIPTION

      Description of the Virtual Server in HPE Morpheus Software

    • Enabled

      Uncheck to keep the configuration but disable F5 availability in HPE Morpheus Software

    • VIP TYPE
      • Standard

      • Forwarding (Layer 2)

      • Forwarding (IP)

      • Performance (HTTP)

      • Performance (Layer 4)

      • Stateless

      • Reject

      • DHCP

      • Internal

      • Message Routing

    • VIP HOSTNAME

      Enter Hostname of the VIP (optional)

    • VIP ADDRESS

      Enter IP address for the VIP

    • VIP PORT

      Enter post used for the VIP

    • SOURCE ADDRESS

      Enter Virtual Server source address

    • PROTOCOL

      tcp, udp, or sctp

    • PROFILES

      Search for and select from available PROFILES

    • POLICIES

      Search for and select from available POLICIES

    • IRULES

      Search for and select from available RUEL SCRIPTS

    • PERSISTENCE
      • cookie

      • dest-addr

      • global-settings

      • hash

      • msrdp

      • sip

      • source-addr

      • ssl

      • universal

    • DEFAULT POOL

      Select from available POOLS

  5. Select SAVE CHANGES

Policies

Policies will be synced and listed in the Policies tab. These policies will be available options when creating Virtual Servers.

Pools

Create Pool

NAME

Name of the POOL in HPE Morpheus Software

DESCRIPTION

Description of the POOL in HPE Morpheus Software

BALANCE MODE
  • Round Robin

  • Least Connections

SERVICE PORT

Specify SERVICE PORT for the POOL

MEMBERS

Search for and select from available NODES

MONITORS

Search for and select from available Monitors

Profiles

SSL Profiles are synced and and will be created when an SSL Certificate is assigned in the Load balancer section when provisioning or editing a Load balancer on an Instance.

Monitors

Create Monitor

NAME

Name of the MONITOR in HPE Morpheus Software

DESCRIPTION

Description of the MONITOR in HPE Morpheus Software

PARENT MONITOR

Select from available MONITORS

DESTINATION

Specify Destination, such a *:443. Default is *:*

INTERVAL

Specify Monitor Interval. Default is 5

TIMEOUT

Specify Monitor Timeout. Default is 15

MONITOR CONFIG

Enter monitor config.

Nodes

Create Node

NAME

Name of the NODE in HPE Morpheus Software

DESCRIPTION

Description of the NODE in HPE Morpheus Software

ADDRESS

Enter node address

MONITOR

Select from available MONITORS

SERVICE PORT

Specify SERVICE PORT for the NODE

Rule Scripts

Rule Scripts will be synced and listed in the RULE SCRIPTS tab. These rules will be available options when creating Virtual Servers.

Citrix NetScaler

../../_images/netScaler-logo.png

Add NetScaler Integration

To add a NetScaler Load Balancer Integration:

  1. Navigate to Infrastructure > Load Balancers

  2. Select + ADD

  3. Select Citrix NetScaler

  4. Fill in the following:

    GROUP *

    Select the Group the Load Balancer will be available for.

    CLOUD *

    Select the Cloud the Load Balancer will be available for.

    NAME *

    Name of the Load Balancer in HPE Morpheus Software.

    DESCRIPTION

    Identifying information displayed on the Load Balancer list page.

    VISIBILITY
    Define Tenant Visibility
    • Public: Available to all Tenants.

    • Private: Only available to specified Tenant.

    Tenant

    If Visibility is set to private, define the Tenant the Load Balancer will be available in.

    API URL *
    URL of the NetScaler API
    API PORT *
    NetScaler API port
    • Example: 80

    USERNAME *

    NetScaler service account username

    PASSWORD *

    NetScaler service account password

    VIRTUAL NAME
    Naming Pattern for new NetScaler Virtual Servers
    • If blank, defaults to morph_lb_${loadBalancer.id}

    SERVICE NAME
    Naming Pattern for new NetScaler Services
    • If blank, defaults to morph_service_${container.id}

    SERVER NAME
    Naming Pattern for new NetScaler Servers
    • If blank, defaults to morph_server_${server.id}

Add Load Balancer to Instance

Load Balancers can be added to Instances during Provisioning or to existing Instances. For Load Balancer settings to appear during provisioning, or for the scale tab to be available on an Instance, the instances Node Type must have a LB port defined.

Note

For Load Balancer settings to appear during provisioning, or for the scale tab to be available on an Instance, the instances Node Type must have a LB port defined.

Add Load Balancer during Provisioning

In the Instance Provisioning wizard, Load Balancers can be configured in the Automation > Load Balancer section.

  1. Navigate to Provisioning ‣ Instances.

  2. Select + ADD.

  3. Select an Instance Type that supports scaling. (ENABLE SCALING (HORIZONTAL) flagged on Instance Type configuration)

  4. Proceed with Instance configuration to the Automation section.

  5. Fill in the following:

    VIP ADDRESS
    Define IP Address for the Virtual Server
    • Example: 10.30.23.191

    VIP PORT
    Define port for the Virtual Server
    • Example: 80

    VIP HOSTNAME
    Define hostname that will resolve to the VIP IP.
    • Example: jwDemoHaApp59.den.example.com

    VIRTUAL SERVICE NAME

    Define name for the Virtual Service. Defaults to ${instance.name}

    BALANCE MODE
    Specify balance mode for the VIP
    • Least Connections

    • Round Robin

    STICKY MODE
    Specify sticky session options for the VIP
    • Source IP

    • Cookie

    SHARED VIP ADDRESS

    Select if VIP is shared, then enter DIRECT VIP ADDRESS

    SSL CERT
    SSL Certificate that will be applied to the VIP.
    • No SSL

    • Select existing Certificate from Infrastructure > Keys & Certs or from a Trust Provider Integration.

    USE EXTERNAL ADDRESS FOR BACKEND NODES
    • Select if traffic from LB to Backend Nodes needs to be sent to the External Addresses, or leave deselected to use Internal Addresses for Backed Nodes.

  6. Optionally configure auto-scaling configuration in the Scale section

  7. Select NEXT and provision the Instance.

After all nodes in the Instance are provisioned, the LB configuration will be added to the Instance and Virtual Servers, Services and Servers will be created and configured on the NetScaler. The Load Balancer settings and status will be visible in the Instance details page LOAD BALANCER section, with additional details, links, and configurations options available in the SCALE tab.

A10 Load Balancers

Overview

HPE Morpheus Software integrates with A10 Networks Thunder and vThunder Application Delivery Controllers (ADC). The integration supports automated provisioning of virtual servers, service groups, and HTTP templates with domain-based routing.

When instances are attached to an A10 load balancer, HPE Morpheus Software automatically:

  • Creates server entries for each container/VM in the instance

  • Creates a service group with the appropriate port mappings

  • Updates the HTTP template with host-based routing rules

  • Configures SSL certificates (when applicable)

Adding an A10 Load Balancer

  1. Navigate to Infrastructure > Load Balancers

  2. Click + ADD

  3. Select A10

  4. Fill in the following:

    GROUP

    Select the Group the Load Balancer will be available for.

    CLOUD

    Select the Cloud the Load Balancer will be available for.

    NAME

    Name of the Load Balancer in HPE Morpheus Software.

    DESCRIPTION

    Identifying information displayed on the Load Balancer list page.

    VISIBILITY

    Define Multi-Tenant visibility. Public allows all Tenants to see the load balancer. Private restricts visibility to selected Tenants.

    API HOST

    IP address or resolvable hostname of the A10 management interface.

    API PORT

    Management API port (typically 443).

    USERNAME

    API user with administrative privileges.

    PASSWORD

    API user password.

    INTERNAL IP

    The internal VIP address for the load balancer.

    PUBLIC IP

    The external/public IP address (if applicable).

    VIP ADDRESS

    The Virtual IP address for load balancing traffic.

    VIP PORT

    The port on which the VIP listens (e.g., 80, 443).

  5. Click SAVE CHANGES

How A10 Integration Works

When an Instance is added to an A10 load balancer, HPE Morpheus Software performs the following operations via the A10 aXAPI:

  1. Server Creation — For each container in the instance, a server object is created on the A10 with the container’s IP address.

  2. Service Group Creation — A service group is created containing all the servers and their designated ports.

  3. HTTP Template Update — The virtual server’s HTTP template is updated with host-based routing rules that direct traffic to the correct service group based on the instance’s hostname.

  4. SSL Configuration — If SSL is configured for the instance, certificates and keys are uploaded to the A10 and bound to the virtual server port 443.

Removing an Instance

When an instance is removed from the A10 load balancer, HPE Morpheus Software reverses the operations:

  • Removes host routing entries from the HTTP template

  • Deletes the service group

  • Removes individual server registrations

Virtual Servers

A10 virtual servers are automatically created when the load balancer integration is initialized. The virtual server is configured with:

  • The VIP address and port specified during integration setup

  • An HTTP template for host-based routing

  • Ports 80 and 443 with the routing template applied

SSL Certificate Management

HPE Morpheus Software can automatically manage SSL certificates on A10 load balancers:

  • Certificates are uploaded as PEM files via the aXAPI

  • Private keys are uploaded separately

  • Certificate bindings are applied to port 443 on the virtual server

  • When instances are removed, their associated certificates are cleaned up

Note

The A10 integration uses the aXAPI v3 interface. Ensure the A10 device is running ACOS 4.x or later for full compatibility.

Troubleshooting

  • Connection errors — Verify the API Host and Port are reachable from the HPE Morpheus Software appliance and that the management interface is enabled.

  • Authentication failures — Confirm the credentials have administrative (or at minimum, read/write) API access on the A10 device.

  • SSL upload failures — Ensure the certificate and key are in valid PEM format.

Avi Networks (NSX ALB) Load Balancers

Overview

HPE Morpheus Software integrates with Avi Networks (now VMware NSX Advanced Load Balancer) to provide application delivery services. The integration syncs virtual services, pools, SSL profiles, health monitors, and cloud configurations from the Avi Controller.

Adding an Avi Load Balancer

  1. Navigate to Infrastructure > Load Balancers

  2. Click + ADD

  3. Select AVI

  4. Fill in the following:

    GROUP

    Select the Group the Load Balancer will be available for.

    CLOUD

    Select the Cloud the Load Balancer will be available for.

    NAME

    Name of the Load Balancer in HPE Morpheus Software.

    DESCRIPTION

    Identifying information displayed on the Load Balancer list page.

    VISIBILITY

    Define Multi-Tenant visibility. Public allows all Tenants to see the load balancer. Private restricts to selected Tenants.

    API HOST

    IP address or FQDN of the Avi Controller.

    API PORT

    Controller API port (default: 443).

    USERNAME

    Avi Controller user with appropriate privileges.

    PASSWORD

    Password for the Avi Controller user.

    INTERNAL IP

    The internal VIP address.

    PUBLIC IP

    The external/public IP address (if applicable).

    VIP ADDRESS

    Virtual IP address for load balancing.

    VIP PORT

    Port the VIP listens on (e.g., 80, 443).

  5. Click SAVE CHANGES

Once connected, HPE Morpheus Software will validate the credentials and begin syncing data from the Avi Controller.

Synced Resources

After successful integration, HPE Morpheus Software periodically syncs the following from the Avi Controller:

Pools

Backend server pools with their members and health status.

Virtual Services

Virtual server configurations including VIP addresses, ports, and pool assignments.

SSL Profiles

TLS/SSL profiles configured on the Avi Controller for certificate management.

Health Monitors

Health check configurations used by pools to verify backend server availability.

Clouds

Avi Cloud configurations that define the infrastructure environment (e.g., VMware, AWS, Azure, OpenStack).

Virtual Servers Tab

The Virtual Servers tab on the Avi load balancer detail page displays all virtual services synced from the controller. Each entry shows:

  • Name — Virtual service name

  • VIP Address — The IP address and port the service listens on

  • Pool — The associated backend pool

  • Status — Operational status (enabled/disabled)

Pools Tab

The Pools tab displays backend server pools:

  • Name — Pool name

  • Members — Number of backend servers in the pool

  • Health Monitor — The health check applied to pool members

  • Status — Pool operational status

Profiles

Avi SSL profiles are synced and available for selection when configuring virtual servers. See Load Balancer Profiles for general profile management.

Status and Monitoring

HPE Morpheus Software monitors the Avi Controller connectivity and updates status:

  • OK — Connected and syncing normally

  • Error — Connection or authentication failure

  • Offline — Avi Controller API is not reachable

A health alarm is raised when connectivity issues are detected.

Note

The Avi integration uses session-based authentication with automatic token refresh. Ensure the configured user account does not have password expiration policies that would interrupt sync operations.

Troubleshooting

  • “error connecting to avi” — Verify the API Host is reachable on the specified port from the HPE Morpheus Software appliance.

  • “unauthorized - invalid credentials” — Confirm the username and password are valid on the Avi Controller.

  • “avi not found - invalid host” — The specified URL may not point to an Avi Controller. Verify the endpoint.

  • Sync not updating — Check that the Avi Controller is online and the configured user has read permissions on all required objects.

Load Balancer Profiles

Overview

Load Balancer Profiles define SSL/TLS and protocol handling configurations that can be applied to virtual servers. Profiles allow you to manage SSL certificate bindings, cipher suites, and protocol settings in a reusable configuration that can be referenced by multiple virtual servers.

Profile management is available for load balancer types that support profile configurations (such as F5 BIG-IP, Avi/NSX ALB, and NSX-T).

Role Requirements

  • Infrastructure: Load Balancers role permission at Full level is required to create, edit, or delete profiles.

  • Infrastructure: Load Balancers role permission at Read level allows viewing profiles only.

Viewing Profiles

  1. Navigate to Infrastructure > Load Balancers

  2. Click the name of a Load Balancer to view its detail page

  3. Select the PROFILES tab

The Profiles tab lists all profiles configured for the load balancer, including:

  • Name — Profile name

  • Description — Profile description

  • Type — The profile type (e.g., Client SSL, Server SSL, HTTP)

  • Service Type — The protocol or service the profile applies to

Creating a Profile

  1. Navigate to Infrastructure > Load Balancers

  2. Click the name of a Load Balancer

  3. Select the PROFILES tab

  4. Click + ADD

  5. Configure the profile fields:

    NAME

    A descriptive name for the profile.

    DESCRIPTION

    Optional description of the profile’s purpose.

    SERVICE TYPE

    The type of profile to create. Available options depend on the load balancer type and may include:

    • Client SSL — Manages SSL/TLS termination for client-facing connections

    • Server SSL — Manages SSL/TLS for backend server connections

    • HTTP — HTTP protocol handling options

    • TCP — TCP connection management

    • UDP — UDP protocol options

    • Persistence — Session persistence configuration

    • Cookie Persistence — Cookie-based session affinity

    CLIENT SSL CERTIFICATE

    Select one or more client SSL certificates from the certificate store. Certificates must be previously uploaded under Infrastructure > Certificates.

    SERVER SSL CERTIFICATE

    Select one or more server SSL certificates for backend connections.

    Note

    Additional fields are displayed based on the load balancer type and the selected service type. These are defined by the provider’s profile option types.

  6. Click SAVE CHANGES

Editing a Profile

  1. Navigate to the Load Balancer detail page

  2. Select the PROFILES tab

  3. Click the edit icon next to the profile

  4. Modify the desired fields

  5. Click SAVE CHANGES

Deleting a Profile

  1. Navigate to the Load Balancer detail page

  2. Select the PROFILES tab

  3. Click the delete icon next to the profile

  4. Confirm the deletion

Warning

Deleting a profile that is currently assigned to a virtual server may disrupt traffic. Ensure no active virtual servers reference the profile before removing it.

Using Profiles with Virtual Servers

When creating or editing a Virtual Server, profiles can be selected from the PROFILES field. Multiple profiles can be applied to a single virtual server. The available profiles are filtered to those belonging to the same load balancer.

See the F5 documentation section for details on how profiles are applied to F5 virtual servers.

Load Balancer Policies and Rules

Overview

Load Balancer Policies define traffic management rules that control how requests are routed, redirected, or modified by the load balancer. Policies contain one or more rules, and each rule can match on specific conditions (such as URI path, hostname, or header values) and perform actions (such as forwarding to a pool, redirecting, or rewriting).

Policy management is available for load balancer types that support policy-based routing (such as F5 BIG-IP and NSX-T).

Role Requirements

  • Infrastructure: Load Balancers role permission at Full level is required to create, edit, or delete policies and rules.

  • Infrastructure: Load Balancers role permission at Read level allows viewing policies and rules only.

Viewing Policies

  1. Navigate to Infrastructure > Load Balancers

  2. Click the name of a Load Balancer to view its detail page

  3. Select the POLICIES tab

The Policies tab lists all policies configured for the load balancer, including:

  • Name — Policy name

  • Description — Policy description

  • Rules — Number of rules defined within the policy

Creating a Policy

  1. Navigate to Infrastructure > Load Balancers

  2. Click the name of a Load Balancer

  3. Select the POLICIES tab

  4. Click + ADD

  5. Configure the policy fields:

    NAME

    A descriptive name for the policy.

    DESCRIPTION

    Optional description of the policy’s purpose.

    Note

    Additional fields are displayed based on the load balancer type. These are defined by the provider’s policy option types.

  6. Click SAVE CHANGES

Deleting a Policy

  1. Navigate to the Load Balancer detail page

  2. Select the POLICIES tab

  3. Click the delete icon next to the policy

  4. Confirm the deletion

Warning

Deleting a policy that is currently assigned to a virtual server may disrupt traffic routing. Ensure no active virtual servers reference the policy before removing it.

Policy Rules

Each policy contains one or more rules that define match conditions and actions. Rules are evaluated in order and the first matching rule’s action is applied.

Viewing Rules

  1. Navigate to the Load Balancer detail page

  2. Select the POLICIES tab

  3. Click the name of a policy to expand its rules list

Creating a Rule

  1. Navigate to the Policy detail view

  2. Click + ADD RULE

  3. Configure the rule fields:

    NAME

    A descriptive name for the rule.

    MATCH CONDITIONS

    Define the criteria that must be met for the rule to apply. Conditions vary by load balancer type and may include:

    • URI Path — Match on request URI path (e.g., /api/*)

    • Hostname — Match on the Host header value

    • HTTP Method — Match on GET, POST, PUT, etc.

    • Header — Match on a specific HTTP header value

    • Source IP — Match on client source IP address or range

    ACTIONS

    Define what happens when the rule matches:

    • Forward to Pool — Send traffic to a specific backend pool

    • Redirect — Return an HTTP redirect response

    • Reject — Return a rejection response

    • Rewrite — Modify the request URI or headers before forwarding

    Note

    Available match conditions and actions depend on the load balancer type and are defined by the provider’s policy rule option types.

  4. Click SAVE CHANGES

Deleting a Rule

  1. Navigate to the Policy detail view

  2. Click the delete icon next to the rule

  3. Confirm the deletion

Using Policies with Virtual Servers

When creating or editing a Virtual Server, policies can be selected from the POLICIES field. The available policies are filtered to those belonging to the same load balancer. Policies are evaluated in the order they are assigned to the virtual server.