---
title: "STACKIT Network Load Balancer"
description: "High-performance Layer-4 TCP/UDP network load balancer supporting TLS passthrough and active health checks."
scfAsset:
  category: "service"
  managed: true
  marketplaceUrl: "https://marketplace.stackit.cloud/en/products"
  tags: ["Load Balancer", "Layer-4", "TCP", "UDP", "High Performance"]
  maintainers:
    - user: "alexander.gabert"
source_url: "https://framework.stackit.cloud/architecture/assetcontainer/stackit/stackit-service-network-load-balancer/"
source_file: "docs/architecture/assetcontainer/stackit/stackit-service-network-load-balancer.mdx"
---

STACKIT Network Load Balancer handles high-throughput Layer-4 TCP and UDP traffic balancing.

## Service Overview
- **High Throughput**: Capable of processing millions of raw network requests per second with minimal latency.
- **TLS Passthrough**: Preserves encrypted traffic streams directly down to backend target instances.
- **Flexible Protocols**: Supports custom TCP and UDP application protocols.

## Technical Details
- **Features**: Source IP stickiness, active TCP/UDP health checks, public and private network integration.
- **Automation**: Fully configurable via Terraform Provider, REST API, and STACKIT Portal.

## Feature Availability

The values below come from the STACKIT documentation and update themselves.

> From the STACKIT docs: [NLB features › Feature overview & availability](https://docs.stackit.cloud/products/network/load-balancing-and-content-delivery/network-load-balancer/basics/features-nlb/#feature-overview--availability) (Source updated 09.07.2026, copied 05.10.2026)

The following table outlines the specific transport layer conditions and core features available within the STACKIT Network Load Balancer (NLB):

| Feature | API | SDK | Terraform | Portal |
| --- | --- | --- | --- | --- |
| Advanced active health checks (HTTP) | Available | Available | WIP | Available |
| Basic active health checks (TCP/UDP) | Available | Available | Available | Available |
| Create/delete NLB | Available | Available | Available | Available |
| Ephemeral IP | Available | Available | Available | Available |
| Idle timeout configuration | Available | Available | Available | WIP |
| L4 load balancing (TCP/UDP) | Available | Available | Available | Available |
| Logs (Loki) | Available | Available | Available | WIP |
| Manual target security groups | Available | Available | Available | Available |
| Metrics (Prometheus) | Available | Available | Available | WIP |
| Plan changes | Available | Available | Available | Available |
| Private network only deployment | Available | Available | Available | Available |
| Resource labels | Available | Available | WIP | WIP |
| Session persistence (source IP) | Available | Available | Available | Available |
| Source IP access control (ACL) | Available | Available | Available | Available |
| TCP proxy support | Available | Available | Available | Available |
| TLS passthrough | Available | Available | Available | Available |
| Update full NLB | Available | Available | WIP | WIP |
| Update target pools only | Available | Available | Available | Available |

## Limitations & Constraints
- **No Layer-7 Offloading**: Lacks HTTP header parsing, URL path routing, or SSL/TLS certificate termination.

<LinkCard title="STACKIT Network Load Balancer Documentation" href="https://docs.stackit.cloud" />
