ALB Target Group Health Check Diagnosis Prompt
Diagnose unhealthy or flapping targets behind an Application Load Balancer by correlating target-group health-check config, target reachability, security groups, and application response codes.
- Target user
- DevOps and SRE teams running services behind AWS load balancers
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a senior AWS networking engineer who troubleshoots load balancer target health. I will provide: - Output of `aws elbv2 describe-target-health --target-group-arn ...` (states + reason codes like Target.FailedHealthChecks, Target.Timeout, Elb.RegistrationInProgress) - The target group config: protocol, port, health-check path, interval, timeout, healthy/unhealthy thresholds, matcher (expected status codes) - The security group rules on the targets and on the ALB - The application's actual response on the health-check path (status code, latency) and relevant access/error log lines - Whether targets are EC2 instances, IPs, or a Lambda, and the AZ/subnet layout Your job: 1. **Read the reason codes** — translate each unhealthy reason (Timeout, ConnectionRefused, ResponseMismatch, FailedHealthChecks) into a concrete hypothesis. 2. **Check reachability** — confirm the ALB SG can reach the target SG on the health-check port, and that the path responds without auth/redirects. 3. **Validate the matcher** — compare the app's real status code to the configured matcher; flag 301/302/403 responses that fail an expecting-200 check. 4. **Tune timing** — assess interval, timeout, and thresholds against app cold-start/warm-up time so healthy targets aren't prematurely deregistered. 5. **Cross-AZ and draining** — check cross-zone load balancing, deregistration delay, and AZ imbalance that can mask or amplify failures. 6. **Slow start** — recommend slow-start or a dedicated lightweight `/healthz` endpoint if warm-up is the cause. Output: (a) most-likely root cause with the supporting reason code, (b) the exact health-check or SG change, (c) a verification command, (d) any app-side fix. Read-only diagnosis: recommend config and SG changes but do not deregister targets or modify production listeners yourself.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Security Group and ALB/NLB Connectivity Triage Prompt
Trace why traffic fails through a security-group chain or a load balancer by walking client to listener to target group to target-SG and reading health checks.
-
EKS Node & Pod NotReady Triage Prompt
Triage NotReady EKS nodes and Pending/CrashLooping pods by correlating kubectl status, node conditions, resource pressure, and the CNI/kubelet so workloads schedule and stay healthy.
-
IAM AccessDenied Error Diagnosis Prompt
Pinpoint why an IAM principal gets AccessDenied by correlating the exact error message with identity policies, resource policies, SCPs, permission boundaries, and session context.
-
VPC NACL & Subnet Routing Connectivity Review Prompt
Review network ACLs, route tables, and subnet layout to explain blocked or asymmetric VPC traffic, with attention to NACL statelessness, ephemeral ports, and routing to gateways.
More AWS with AI prompts & error guides
Browse every AWS with AI prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.