Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Security in Yandex Cloud
  • Key security features
  • Division of responsibility for security
  • Compliance
  • Security measures on the Yandex Cloud side
  • Security tools available to cloud service users
    • All tutorials
      • Hosting a static Gatsby website in Object Storage
      • Storing Apache Airflow™ connections and variables in Yandex Lockbox
      • Deploying a fault-tolerant architecture with preemptible VMs
      • Migrating services from an NLB with VMs as targets to an L7 ALB
      • Migrating services from an NLB with an instance group as a target to an L7 ALB
      • Migrating services from an external NLB to L7 ALB with an internal NLB as a target
    • Obtaining the information you need to request the Russian Ministry of Digital Development to whitelist a resource
  • User support policy during vulnerability scanning
  • Security bulletins
  • Public IP address ranges
  1. Tutorials
  2. Secure virtual environment configuration
  3. Migrating services from an external NLB to L7 ALB with an internal NLB as a target

Migrating services from an external NLB to an L7 ALB with an internal NLB as a target

Written by
Yandex Cloud
Updated at March 31, 2026
View in Markdown

You can migrate the load from a Yandex Network Load Balancer load balancer to a Yandex Application Load Balancer L7 load balancer. A network load balancer distributes traffic across your load balancer pods deployed in a Yandex Managed Service for Kubernetes cluster. If the L7 load balancer does not support your load balancer configuration, you can add an internal network load balancer as a target for your L7. The internal network load balancer will be distributing traffic across NGINX Ingress Controller pods deployed in a Managed Service for Kubernetes cluster; the internal network load balancer's IP address will be specified in the L7 load balancer's target group.

Warning

Do not modify or delete the network load balancer and its child resources created using Managed Service for Kubernetes via the Yandex Cloud interfaces (the management console, Terraform, CLI, or API). This may cause incorrect operation of the cluster.

During the migration process, the L7 load balancer will have a Yandex Smart Web Security security profile connected to it. Here is how an L7 load balancer with a security profile works:

You can create a service migration infrastructure using the following tools:

Was the article helpful?

Previous
Migrating services from an NLB with an instance group as a target to an L7 ALB
Next
Which encryption method should I choose?
© 2026 Direct Cursus Technology L.L.C.