# The recommended ELB type on AWS EKS

**URL:** <https://discuss.konghq.com/t/the-recommended-elb-type-on-aws-eks/5945>\
**Category:** General\
**Tags:** kubernetes\
**Created:** [April 4, 2020, 2:35pm UTC](https://discuss.konghq.com/t/the-recommended-elb-type-on-aws-eks/5945 "2020-04-04T14:35:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dilarat](https://avatars.discourse-cdn.com/v4/letter/d/f08c70/32.png) [@dilarat](https://discuss.konghq.com/u/dilarat)\
**Post date:** [April 4, 2020, 2:35pm UTC](https://discuss.konghq.com/t/the-recommended-elb-type-on-aws-eks/5945/1 "2020-04-04T14:35:56Z")

</div>

Hi all,

I installed Kong on AWS EKS using Helm 2 charts. While I following the documents on Github for Kong Ingress Controller, realized that the recommended ELB for Kong is L4. I wonder what is the default type for the load balancer without specifying using annotations (i.e [service.beta.kubernetes.io/aws-load-balancer-type:](http://service.beta.kubernetes.io/aws-load-balancer-type:) nlb). The Github link is below:

[https://github.com/Kong/kubernetes-ingress-controller/blob/master/docs/guides/preserve-client-ip.md](https://github.com/Kong/kubernetes-ingress-controller/blob/master/docs/guides/preserve-client-ip.md)

I also wonder how to use Ingress Resources for other services (i.e Kong Admin API). I’m a bit confused whether to use them behind the kong proxy service, or all of them behind an ELB.

I followed the documents and forum but couldn’t find an exact answer for my question. I really want to use Kong Ingress Controller and Kong, but I think need some guidance along with the structure on Kubernetes.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![ajay](https://avatars.discourse-cdn.com/v4/letter/a/f4b2a3/32.png) [@ajay](https://discuss.konghq.com/u/ajay)\
**Post date:** [April 4, 2020, 8:40pm UTC](https://discuss.konghq.com/t/the-recommended-elb-type-on-aws-eks/5945/2 "2020-04-04T20:40:30Z")

</div>

@dilarat by default kubernetes will provision classic load balancer if for a **service** you specify `type: LoadBalancer`.

Secondly why would you want to expose admin api out in public? If you do want, it’s nothing different from others, you simply need an ingress pointing to a service which in turn has your kong pods as upstream.

---

<div class="post-metadata">

**Author:** ![dilarat](https://avatars.discourse-cdn.com/v4/letter/d/f08c70/32.png) [@dilarat](https://discuss.konghq.com/u/dilarat)\
**Post date:** [April 5, 2020, 9:09am UTC](https://discuss.konghq.com/t/the-recommended-elb-type-on-aws-eks/5945/3 "2020-04-05T09:09:49Z")

</div>

Thank you for your collaboration @ajay.  
The structure that I’m using before ingress controller was depends on Admin API to configure Kong. This was costly, as it has a own load balancer. I read in somewhere in the Kong Nation, the ingress resources can be used to expose this services in order to down the cost and to be more convenient. That’s way I asked it for.  
I know the recommended design for the Ingress Controller is using CRDs to configure Kong, and I would like to use them effectively.

---

<div class="post-metadata">

**Author:** ![hbagdi](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/hbagdi/32/562_2.png) [@hbagdi](https://discuss.konghq.com/u/hbagdi)\
**Post date:** [April 7, 2020, 6:09pm UTC](https://discuss.konghq.com/t/the-recommended-elb-type-on-aws-eks/5945/4 "2020-04-07T18:09:51Z")

</div>

You can expose Admin API behind the Kong proxy service.  
You really only need a single LB for kong-proxy service and all the other services can be multiplexed on the same LB.  
Please look into values.yaml in the Helm chart on how to do it.

---

<div class="post-metadata">

**Author:** ![dilarat](https://avatars.discourse-cdn.com/v4/letter/d/f08c70/32.png) [@dilarat](https://discuss.konghq.com/u/dilarat)\
**Post date:** [April 8, 2020, 5:43am UTC](https://discuss.konghq.com/t/the-recommended-elb-type-on-aws-eks/5945/5 "2020-04-08T05:43:38Z")

</div>

Thank you. The helm chart is pretty clear and well documented!

---

<div class="post-metadata">

**Author:** ![ltartarin90](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/ltartarin90/32/3237_2.png) [@ltartarin90](https://discuss.konghq.com/u/ltartarin90)\
**Post date:** [January 28, 2022, 4:57pm UTC](https://discuss.konghq.com/t/the-recommended-elb-type-on-aws-eks/5945/6 "2022-01-28T16:57:46Z")

</div>

Hi, my aim is to deploy Kong Ingress Controller in our K8s cluster.

Do you think it’s feasible to have an AWS ALB (an Ingress AWS ALB Controller) in front of the kong-proxy service?

I mean, I provisioned such resources, and so far I do not see any issue, even if I do not use an AWS NLB.

However, looking at the Kong docs I read:

- ‘For the Ingress Controller to function correctly, it is also required that a L4 (or TCP) Load Balancer is used and not an L7 (HTTP(s)) one.’ ([Kubernetes Ingress Controller Deployment - v2.1.x | Kong Docs](https://docs.konghq.com/kubernetes-ingress-controller/2.1.x/concepts/deployment/#kubernetes-service-types))
- ‘The recommend Load Balancer type for AWS is NLB.’ ([Preserving Client IP Address - v2.0.x | Kong Docs](https://docs.konghq.com/kubernetes-ingress-controller/2.0.x/guides/preserve-client-ip/#eks))

What do you suggest?

Thanks in advance.
