Hi, is it possible to add the flags httponly and secure to AWSALB cookie used by ALB to manage stickyness? Thanks!

asked 2 years ago1.4K views
1 Answer


See below from the documentation, important point here is that these cookies contain no sensitive data.

You can't set the secure flag or HttpOnly flag on your duration-based session stickiness cookies. However, these cookies contain no sensitive data. Note that if you set the secure flag or HttpOnly flag on an application-controlled session stickiness cookie, it is also set on the AWSELB cookie.

AWS
answered 2 years ago

