Azure Load Balancer
A Layer 4 (TCP/UDP) load balancing service that distributes incoming traffic across a pool of backend VMs or Scale Set instances, used for high-throughput, protocol-agnostic traffic distribution within a region.
Azure Load Balancer
Load Balancer operates at the transport layer — it doesn't inspect HTTP content, just distributes TCP/UDP connections across healthy backend instances.
Why It Matters in Production
Swiggy's order-matching VM Scale Set sits behind a Standard Load Balancer that distributes raw TCP connections across instances, with health probes automatically removing unresponsive nodes from rotation.
az network lb create --resource-group swiggy-prod-rg \ --name order-matching-lb --sku Standard \ --frontend-ip-name lb-frontend --backend-pool-name order-matching-poolRememberUse Application Gateway instead when you need Layer 7 features like URL-based routing or SSL termination — Load Balancer can't inspect HTTP paths.
Frequently Asked Questions
How is Azure Load Balancer different from Application Gateway?
Azure Load Balancer works at Layer 4, meaning it distributes raw TCP/UDP connections without inspecting HTTP headers, cookies, or URL paths. Application Gateway operates at Layer 7 and can do path-based routing, SSL termination, and WAF filtering. Use Load Balancer when you need high-throughput, protocol-agnostic distribution (databases, custom TCP services, VM scale sets), and reserve Application Gateway for HTTP/HTTPS traffic that needs content-aware routing.
What's a common mistake teams make when configuring Azure Load Balancer health probes?
Pointing the health probe at the same port and path as the app's readiness endpoint but forgetting it fires independently of Kubernetes or app-level health checks. If the probe interval is too aggressive or the probe path returns 200 even when the app is degraded, the load balancer keeps sending traffic to an unhealthy instance. Also easy to miss: a Standard SKU Load Balancer requires an explicit outbound rule or NAT gateway, or backend VMs silently lose outbound internet connectivity.