A company has deployed a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application's IP addresses are used by a third-party service to allowlist traffic. The EC2 instances are part of an Auto Scaling group that may scale up and down. The SysOps administrator needs to ensure that the third-party service always has the current IP addresses of the ALB without requiring manual updates. Which solution should the administrator implement?
Trap 1: Use Amazon Route 53 with a simple routing policy pointing to the…
Amazon Route 53 with a simple routing policy only returns the ALB's DNS name as an A/AAAA alias record. The ALB's underlying IP addresses are ephemeral and can change when the load balancer scales or is recreated, so the third party cannot extract a static, allowlisted IP from this DNS response. Simple routing also provides no mechanism to guarantee a fixed IP for the caller's firewall rules, making it invalid for a static-IP allowlisting requirement.
Trap 2: Use an Amazon CloudFront distribution with the ALB as the origin…
CloudFront uses a shared IP range that is not dedicated to a specific distribution. These IPs also change when CloudFront updates its edge locations, so they are not a stable, dedicated set of IPs for allowlisting.
- A
Use AWS Global Accelerator and provide the static IP addresses to the third party
Global Accelerator provides two static IP addresses that serve as a fixed entry point. You can add the ALB as an endpoint, and traffic will be directed to the ALB's current healthy instances, while the static IPs remain unchanged.
- B
Use Amazon Route 53 with a simple routing policy pointing to the ALB DNS name
Why it fails: Amazon Route 53 with a simple routing policy only returns the ALB's DNS name as an A/AAAA alias record. The ALB's underlying IP addresses are ephemeral and can change when the load balancer scales or is recreated, so the third party cannot extract a static, allowlisted IP from this DNS response. Simple routing also provides no mechanism to guarantee a fixed IP for the caller's firewall rules, making it invalid for a static-IP allowlisting requirement.
- C
Use an Amazon CloudFront distribution with the ALB as the origin and provide the CloudFront IP addresses
Why it fails: CloudFront uses a shared IP range that is not dedicated to a specific distribution. These IPs also change when CloudFront updates its edge locations, so they are not a stable, dedicated set of IPs for allowlisting.
- D
Use an AWS Network Load Balancer (NLB) with static IP addresses in front of the ALB
Placing an NLB in front of the ALB does not solve the requirement because the third-party service needs the ALB’s IP addresses, but the NLB’s static IPs belong to the NLB itself, not to the ALB behind it; the ALB’s IPs remain dynamic and unknown to the third party. This option is tempting because an NLB with static IPs is the correct solution when the third party needs a fixed set of IPs for allowlisting, but here the requirement is to expose the ALB’s current IPs, not to front it with another load balancer that obscures them.