SSL and TLS termination
How the load balancer handles encrypted traffic depends on the layer and protocol you pick at creation. There are two TLS modes:
Terminate at the edge (L7 HTTPS)
Create an L7 load balancer with protocol HTTPS. The platform provisions and manages the certificate — there is nothing to upload or renew.
Traffic from the load balancer to your backends is plain HTTP by default. To re-encrypt the hop to a backend, tick Encrypt traffic from the load balancer to this backend on that backend row — the load balancer then connects to it over TLS.
Use termination when you want:
- Managed certificates with no renewal work
- L7 features that need to read the request — path/header rules, sticky sessions
Pass TLS through (L4)
Create an L4 load balancer with protocol tls_passthrough. The load balancer forwards encrypted bytes without decrypting, so:
- Your backends present their own certificate and terminate TLS themselves
- End-to-end encryption is preserved — the load balancer never sees plaintext
- L7 features (path rules, header matches, sticky sessions) are not available, since the traffic can’t be inspected
Choose the health check type accordingly — with passthrough, use a TCP check, or an HTTPS check if the backend exposes a health endpoint over TLS.
Use your own domain
The detail page shows the load balancer’s public endpoint Host. To serve traffic on your own domain, create a DNS record at your DNS provider that points your domain at that endpoint.
