# Load balancers & API gateways with `aral`

## Load balancer (L4/L7 across your servers)

    aral lb plans
    aral lb create --name web-lb --region hel1
    aral lb get <id>                       # poll; the LB is its own VM with its own IP
    aral lb add-service <id> --port 443 ... # see --help
    aral lb add-target <id> --server-id <server-id>
    aral lb delete <id>

## API gateway (managed reverse proxy / API front door)

    aral api-gateway create --name my-gw --region hel1 --mode shared   # shared edge, instant
    aral api-gateway create --name my-gw --region hel1 --mode dedicated # own VM + IPv6
    aral api-gateway add-route --path-prefix /api --upstream https://backend.example.com <id>
    aral api-gateway routes <id>
    aral api-gateway add-domain <id> api.example.uz          # redirects plain HTTP to HTTPS
    aral api-gateway add-domain <id> legacy.example.uz --no-force-https
    aral api-gateway domains <id>                            # verified + force_https per domain
    aral api-gateway domain-https <id> api.example.uz off    # on|off, takes effect in seconds
    aral api-gateway delete <id>

A PRIVATE upstream (10.x address) is refused until the gateway is attached to
that backend's private network — the error says exactly that. Longest
path-prefix wins across routes.

"Always HTTPS" is per domain and on by default for every newly attached
domain: plain HTTP gets a 308 to the same URL on https. ACME HTTP-01
challenges are never redirected, so certificates keep renewing. Domains
attached before the setting existed stay off until turned on.
