A company is using an Application Load Balancer (ALB) to distribute traffic to EC2 instances. They want to ensure that only authenticated users can access a specific path of their application (e.g., /admin/*) and that users are redirected to an identity provider (IdP) for authentication if they are not authenticated. Which ALB feature should be configured?
- ATarget Group Health Checks
- BPath-based Routing
- CListener Rules with Authentication Actions
- DSticky Sessions
Show answer & explanationAnswer & explanation
Correct answer: C. Listener Rules with Authentication Actions
ALB Listener Rules allow you to define actions based on various conditions, including path patterns. One of the powerful actions is 'Authenticate', which enables integration with identity providers (IdPs) like Amazon Cognito, OIDC, or SAML. This action can be configured to redirect unauthenticated users to the IdP and then forward authenticated requests to a target group, precisely meeting the requirement for path-based authentication.
Why the other options are wrong
- A. Target Group Health Checks monitor the health of registered targets but do not provide authentication functionality.
- B. Path-based routing allows directing traffic to different target groups based on URL paths but doesn't inherently provide authentication and redirection to an IdP; it's a condition for an action, not the action itself.
- D. Sticky Sessions (session affinity) ensure a user's requests are sent to the same target, which is unrelated to authentication at the ALB level.
ALB Listener Authentication
An Application Load Balancer feature that allows for direct authentication of users against an identity provider (IdP) before forwarding requests to backend targets.
- Supports OIDC, Amazon Cognito, and SAML-based IdPs.
- Can be configured as an action in listener rules.
- Enables path-based authentication for different parts of an application.
Memory trick: ALB's Listener Rules are the bouncer at the club, checking IDs for specific areas.