# SSL magic with a load balancer

**URL:** <https://forums.suse.com/t/ssl-magic-with-a-load-balancer/2615>\
**Category:** Rancher 1.x\
**Created:** [April 27, 2016, 4:16pm UTC](https://forums.suse.com/t/ssl-magic-with-a-load-balancer/2615 "2016-04-27T16:16:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![philpowell](https://avatars.discourse-cdn.com/v4/letter/p/b5ac83/32.png) [@philpowell](https://forums.suse.com/u/philpowell)\
**Post date:** [April 27, 2016, 4:16pm UTC](https://forums.suse.com/t/ssl-magic-with-a-load-balancer/2615/1 "2016-04-27T16:16:41Z")

</div>

I’m looking at trying to clean up some of our service configurations, so that each stack can potentially run it’s own dedicated load balancer. I’m running in to inevitable port conflicts, and although I don’t think what I"m trying to do will be possible, I thought it worth asking the question on the off-chance that somebody has a clever solution!

I have Service A in a stack, which I want to serve with the domain [a.example.com](http://a.example.com), over port 443 with SSL.

I have Service B in another stack, which I want to serve with the domain [b.example.com](http://b.example.com), over port 443 with SSL.

I can configure a load balancer in one or other of the stacks, listening on port 443, with advanced routing redirecting to the appropriate service, based on hostname. I can also get this working with SSL configured.

This doesn’t scale well though. If I configure this load balancer in Service A’s stack, then maintenance on Service A stack can affect Service B. Also, I don’t think I can easily configure more than two SSL certificates.

I could configure the load balancer entirely in it’s own stack, but that means there’s more decoupling than I’d like (and also doesn’t solve the scaling of the SSL config). Is there a clever way I can configure Service A and Service B, so that they have their own load balancers configured to listen on the same port, but for different domains?

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [June 2, 2016, 6:30pm UTC](https://forums.suse.com/t/ssl-magic-with-a-load-balancer/2615/2 "2016-06-02T18:30:19Z")

</div>

Have you looked at our hostname routing rules?

In the UI:  
[http://docs.rancher.com/rancher/latest/en/rancher-ui/applications/stacks/adding-balancers/#advanced-routing-options](http://docs.rancher.com/rancher/latest/en/rancher-ui/applications/stacks/adding-balancers/#advanced-routing-options)

In rancher-compose:  
[http://docs.rancher.com/rancher/latest/en/rancher-compose/rancher-services/#advanced-load-balancing-l7](http://docs.rancher.com/rancher/latest/en/rancher-compose/rancher-services/#advanced-load-balancing-l7)

The only caveat would be that we don’t support being able to use different SSL certificates with hostname routing.

---

<div class="post-metadata">

**Author:** ![philpowell](https://avatars.discourse-cdn.com/v4/letter/p/b5ac83/32.png) [@philpowell](https://forums.suse.com/u/philpowell)\
**Post date:** [June 3, 2016, 7:29am UTC](https://forums.suse.com/t/ssl-magic-with-a-load-balancer/2615/3 "2016-06-03T07:29:22Z")

</div>

Thanks for the suggestion Denise. We’re currently using hostname routing, and it works beautifully. What I’m really interested in discovering though is: is it possible to configure two load balancers, with two different domains, _but_ listening on the same port?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [June 3, 2016, 4:07pm UTC](https://forums.suse.com/t/ssl-magic-with-a-load-balancer/2615/4 "2016-06-03T16:07:58Z")

</div>

On different hosts yes, on the same one no. A container has to be bound to a single container.
