Traffic from Shared services account to Elastic beanstalk?

0

Hi, I don't want to expose my elasticbeanstalk web application directly from the AWS account it is hosted in, I have a landing zone and a dedicated network account for ingress/egress. I want to host the ALB in my network account and share my TGW using RAM in the elasticbeanstalk account, But not sure how external traffic will be able to reach my elastic beanstalk env.

Shall I add internal ALB in front of elasticbeankstalk because I need end to end SSL also.

1개 답변
2
수락된 답변

Hi,

Yes, you need to add internal ALB. You will route traffic from your TGW to it but also have HA and horizontal scaling for your application. There are many examples available on how to add a centralised firewall with TGW and a separate network account, you can follow them to understand the traffic flow for your ingress. https://medium.com/@deepikakhalarka/traffic-patterns-with-centralized-inspection-using-firewall-appliances-aws-cloud-23cbec8f4b78

profile picture
전문가
답변함 9달 전
profile picture
전문가
검토됨 3달 전
profile pictureAWS
전문가
검토됨 9달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠