skip to content

An ELB target group is created with a target type of instance, ip, lambda or alb. What does each one register, and why must an ECS task running on Fargate use the ip type?

level: middleimportance: should knowfreq 55%

answer

  1. four types, fixed at creation
  2. instance ID versus raw address
  3. containers get their own ENI
  4. awsvpc means no instance to register
  5. one function per group, ALB only

basics

~20 s

Target type fixes what you register: instance registers EC2 instance IDs, ip registers routable private addresses, lambda registers one function, and alb registers an Application Load Balancer behind a Network Load Balancer. Fargate tasks have their own ENI and no instance to register, so they need ip.

solid answer

~50 s

The target type is chosen at target-group creation and cannot be changed afterwards. `instance` registers EC2 instance IDs and the load balancer sends traffic to the primary private address of the primary network interface. `ip` registers individual private IPv4 or IPv6 addresses in the VPC — or private addresses reachable over peering, Transit Gateway, VPN or Direct Connect — which is the only way to reach a backend that is not an EC2 instance in this VPC. `lambda` registers a single function and is supported only by an Application Load Balancer, which invokes it with a JSON event rather than opening a connection; health checks are off by default there. `alb` registers an Application Load Balancer as the target of a Network Load Balancer. A Fargate task uses the `awsvpc` network mode, so it owns an elastic network interface and has no instance ID to register — hence `ip`.

code

bash · 8 lines
bash
aws elbv2 create-target-group \
  --name api-tasks \
  --target-type ip \
  --protocol HTTP --port 8080 \
  --vpc-id vpc-0abc1234def567890 \
  --health-check-path /healthz \
  --health-check-port traffic-port \
  --matcher HttpCode=200

go deeper

for a junior

Know the four names and one sentence each: instance IDs, private IP addresses, a single Lambda function, or an ALB behind an NLB. Say that the type is fixed when the target group is created.

for a middle

Explain why awsvpc network mode and Fargate force ip targets, and what the registered port and the traffic-port health-check setting each override.

for a senior

Weigh the operational cost: ip mode consumes a VPC address per task and can exhaust small subnets, while instance mode adds a forwarding hop and makes health checks probe the host rather than the workload.

for a principal

Own the addressing plan behind the choice — subnet sizing for per-task interfaces, how registration is reconciled when backends are named rather than addressed, and whether the NLB-in-front-of-ALB pattern is worth its extra hop for static IPs or PrivateLink.

## The four target types A target group's `TargetType` is chosen at creation and is immutable — switching means creating a new target group and repointing the listener rule. It determines what a registration record even looks like. **`instance`** — you register an EC2 instance ID plus a port. The load balancer resolves that to the primary private IPv4 address of the instance's primary network interface and connects there. This is the simplest type and the one Auto Scaling groups attach to natively, but it can only ever address instances in the same VPC as the target group. **`ip`** — you register a raw address plus a port. Valid addresses are those in the target group's VPC subnets, or private addresses (RFC 1918 ranges, and RFC 6598 `100.64.0.0/10`) reachable from that VPC over peering, Transit Gateway, VPN or Direct Connect. You cannot register a public address, and you cannot register a DNS name — ELB does not resolve names for you, which is why teams fronting a name-addressed backend end up running a small reconciliation job that re-registers resolved addresses. **`lambda`** — the target group holds exactly one function, and only an Application Load Balancer can forward to it. There is no TCP connection to the function: the ALB synthesises a JSON event containing method, path, headers and body, invokes the function synchronously, and turns the returned object (`statusCode`, `headers`, `body`, `isBase64Encoded`) into the HTTP response. Health checks exist but are disabled by default, and concepts that assume a long-lived backend — slow start, deregistration delay — do not apply. **`alb`** — the target is an Application Load Balancer, and the target group can only be used by a Network Load Balancer. This is the standard way to put a static IP or a PrivateLink endpoint service in front of ALB's HTTP routing. ## Why containers force the ip type ECS tasks using the `awsvpc` network mode get their own elastic network interface with a private address inside the VPC. AWS Fargate supports **only** `awsvpc`, so a Fargate task never shares a host's address — and there is no EC2 instance ID for it in the first place. The ECS service therefore registers each task's IP into an `ip`-type target group and deregisters it when the task stops. The same applies to workloads reached through the VPC CNI, where each pod holds a VPC address that is registered directly. The practical difference is a hop. With `instance` targets and a container behind a host port, traffic lands on the instance and is then forwarded to the container; with `ip` targets it lands on the task's own interface. IP mode removes the extra hop and lets health checks target the task rather than the host — but it consumes VPC addresses per task, which is a real constraint in small subnets. ```bash aws elbv2 create-target-group --name api-tasks --target-type ip \ --protocol HTTP --port 8080 --vpc-id vpc-0abc1234def567890 \ --health-check-path /healthz --matcher HttpCode=200 ``` ## Port and protocol overrides The port supplied at registration overrides the target group's default port, so the same target group can hold the same instance on several ports — the classic way to run multiple containers of one service per host in `bridge` mode. The health check has its own port setting: the special value `traffic-port` means "whatever port this target is registered on", while an explicit number lets you probe a dedicated admin or management port that is not the port serving traffic. Protocol can differ too: an ALB target group can forward over HTTP while probing over HTTP, or forward HTTPS to targets doing their own TLS. ## Choosing Use `instance` for plain EC2 fleets behind an Auto Scaling group — it is the least machinery. Use `ip` when the backend is a Fargate task, a container with its own interface, an on-premises host reached over Direct Connect, or anything else without an instance ID. Use `lambda` for lightweight HTTP endpoints where you want ALB routing without running a server. Use `alb` only in the NLB-in-front-of-ALB pattern.

  • Can you register a public IP address or a DNS name in an ip-type target group?
    No to both. Only addresses in the target group's VPC subnets or private addresses reachable over peering, Transit Gateway, VPN or Direct Connect can be registered, and ELB never resolves hostnames — registration takes literal addresses. Fronting a name-addressed backend requires something outside ELB to resolve the name and reconcile the registrations as they change.
  • Why can the same instance appear twice in one target group?
    Because a registration is an instance-and-port pair, not just an instance. Registering the same instance on two ports lets one host run several containers of the same service in bridge network mode, and each entry is health-checked separately on its own port.
  • What is different about how an ALB delivers a request to a lambda target?
    There is no connection to a server. The ALB builds a JSON event describing the request, invokes the function synchronously, and converts the returned object's statusCode, headers and body into the HTTP response. That is why one function per target group, base64 handling for binary bodies, and the function's own concurrency limits become the relevant concerns rather than ports and draining.

saying these in an interview costs you the question

  • Thinking target type can be changed after creation
  • Registering a public IP or DNS name in an ip target group
  • Assuming Fargate tasks register by instance ID
  • Believing lambda targets work behind a Network Load Balancer
  • Not knowing the registered port overrides the group's default port

context