Layer 4 vs Layer 7
Connection-level versus request-level balancing, and what each unlocks.
4 to work through
-
beginner
Six backends sit behind one load balancer: two in zone A and four in zone B. The zone A pair runs at 70% CPU while the zone B four sit at 25%. The load balancer's per-zone request counts are even and no target is unhealthy. What is happening?
2 min answer -
intermediate
A service has widely varying request costs — most complete in 10 ms, some take 5 s. Under round robin some instances are overwhelmed while others idle. What do you change?
2 min answer -
advanced
A chat platform's Layer 7 proxy tier holds millions of WebSocket connections. Every proxy deployment disconnects everyone. What would you change?
2 min answer -
advanced
One instance passes its health checks but serves requests ten times slower than its peers. Why is it still receiving traffic and what would you change?
2 min answer
3 terms in this topic
Health Check Configuration
The interval, timeout, and healthy/unhealthy thresholds that together determine how quickly a failed backend leaves rotation.
conceptLoad Balancer Types
Layer 4 against layer 7, the algorithms that distribute requests, and why "least connections" is usually better than round robin.
conceptLoad Balancing Algorithm
The rule deciding which backend receives a request — round robin, least connections, least response time, or hash-based.
Neighbouring topics
Networking
General material on the network path underneath an architecture.
TCP/IP
Handshakes, congestion control, head-of-line blocking and connection reuse.
HTTP/1.1, HTTP/2 & HTTP/3
Multiplexing, prioritisation and the transport each is built on.
DNS
Resolution, TTL behaviour, traffic steering and failover latency.
TLS & Certificates
Encryption, integrity, authentication, termination points and expiry.
Reverse Proxies
One place for TLS, routing, caching, compression and rate limiting.
Content Delivery Networks
Edge caching, origin offload, spike absorption and dynamic content.
Firewalls & Security Groups
Default-deny, stateful rules, and restricting egress as well as ingress.
NAT & Egress
Outbound-only connectivity, its per-gigabyte cost and its zone binding.
VPC Design
Address planning, peering and the ranges you can never resize.
Subnetting
Tiering, zone binding, and sizing for an address-hungry platform.
Routing & BGP
How traffic finds you, anycast, and route withdrawal as a failure mode.
Service Mesh Networking
Sidecar proxies supplying mTLS, retries and traffic policy.
WebSockets & Realtime
Persistent bidirectional connections and the capacity model they impose.
gRPC Transport
HTTP/2 multiplexing, binary encoding and streaming semantics.
API Gateways
The single entry point, and the business logic that must stay out of it.
Network Performance
Latency floors, bandwidth-delay product, and what no code change fixes.
Private Connectivity
Private endpoints, peering and dedicated links to managed services.
Network Troubleshooting
Flow logs, packet paths, and localising a problem to a hop.