Hi, is it possible to add the flags httponly and secure to AWSALB cookie used by ALB to manage stickyness? Thanks!

See below from the documentation, important point here is that these cookies contain no sensitive data.

You can't set the secure flag or HttpOnly flag on your duration-based session stickiness cookies. However, these cookies contain no sensitive data. Note that if you set the secure flag or HttpOnly flag on an application-controlled session stickiness cookie, it is also set on the AWSELB cookie.

