---
title: "STACKIT Application Load Balancer"
description: "Managed Layer-7 HTTP/HTTPS load balancer featuring cookie session stickiness, WebSocket support, and TLS offloading."
scfAsset:
  category: "service"
  managed: true
  marketplaceUrl: "https://marketplace.stackit.cloud/en/products"
  tags: ["Load Balancer", "Layer-7", "HTTP", "TLS Offloading"]
  maintainers:
    - user: "alexander.gabert"
source_url: "https://framework.stackit.cloud/architecture/assetcontainer/stackit/stackit-service-application-load-balancer/"
source_file: "docs/architecture/assetcontainer/stackit/stackit-service-application-load-balancer.mdx"
---

STACKIT Application Load Balancer distributes Layer-7 HTTP/HTTPS web traffic across backend pools.

## Service Overview
- **Layer-7 Routing**: Routes requests based on URL paths, request headers, query parameters, and hostnames.
- **TLS Offloading**: Manages SSL/TLS termination centrally with custom certificate support.
- **High Availability**: Deployed in active/passive HA configurations across availability zones.

## Technical Details
- **Features**: Cookie-based session persistence, WebSockets support, and optional WAF integration.
- **Capacity**: Supports up to 20 listeners, 20 target pools, and 250 targets per target pool.

## Feature Availability

The values below come from the STACKIT documentation and update themselves.

> From the STACKIT docs: [ALB features › Feature overview & availability](https://docs.stackit.cloud/products/network/load-balancing-and-content-delivery/application-load-balancer/basics/features-alb/#feature-overview--availability) (Source updated 03.09.2026, copied 05.10.2026)

The following table outlines which STACKIT ALB features are available and which are still being developed:

| Feature | API | SDK | Terraform | Portal |
| --- | --- | --- | --- | --- |
| Advanced active health checks (HTTP) | Available | Available | WIP | WIP |
| Basic active health checks (TCP) | Available | Available | Available | Available |
| Create/delete ALB | Available | Available | Available | Available |
| Ephemeral IP | Available | Available | Available | Available |
| IP block list | Available | WIP | WIP | WIP |
| L7 load balancing (HTTP/HTTPS) | Available | Available | Available | Available |
| Logs (Loki) | Available | Available | Available | WIP |
| Manual target security groups | Available | Available | Available | Available |
| Metrics (Prometheus) | Available | Available | Available | WIP |
| Plan changes | WIP | WIP | WIP | WIP |
| Private network only deployment | Available | Available | Available | Available |
| Resource labels | Available | WIP | Available | WIP |
| Routing with headers | Available | Available | Available | Available |
| Routing with host | Available | Available | Available | Available |
| Routing with path (prefix/exact) | Available | Available | Available | Available |
| Routing with query parameters | Available | Available | Available | Available |
| Session persistence (cookie) | Available | Available | Available | Available |
| Source IP access control (ACL) | Available | Available | Available | Available |
| TLS offloading | Available | Available | Available | Available |
| TLS bridging | Available | Available | Available | Available |
| Update full ALB | Available | Available | Available | WIP |
| Update target pools only | Available | Available | Available | Available |
| ALB WAF integration | Available | WIP | Available | WIP |
| WebSocket support | Available | Available | Available | Available |

## Limitations & Constraints
- **No TLS Passthrough**: Operates at Layer 7; encrypted end-to-end TLS passthrough requires Network Load Balancers.
- **No Automated Cert Rotation**: Certificates attached manually must be updated before expiration.

<LinkCard title="STACKIT Application Load Balancer Documentation" href="https://docs.stackit.cloud" />
