We recommend new projects start with resources from the AWS provider.
aws-native.route53.getHealthCheck
Explore with Pulumi AI
We recommend new projects start with resources from the AWS provider.
Resource schema for AWS::Route53::HealthCheck.
Using getHealthCheck
Two invocation forms are available. The direct form accepts plain arguments and either blocks until the result value is available, or returns a Promise-wrapped result. The output form accepts Input-wrapped arguments and returns an Output-wrapped result.
function getHealthCheck(args: GetHealthCheckArgs, opts?: InvokeOptions): Promise<GetHealthCheckResult>
function getHealthCheckOutput(args: GetHealthCheckOutputArgs, opts?: InvokeOptions): Output<GetHealthCheckResult>
def get_health_check(health_check_id: Optional[str] = None,
opts: Optional[InvokeOptions] = None) -> GetHealthCheckResult
def get_health_check_output(health_check_id: Optional[pulumi.Input[str]] = None,
opts: Optional[InvokeOptions] = None) -> Output[GetHealthCheckResult]
func LookupHealthCheck(ctx *Context, args *LookupHealthCheckArgs, opts ...InvokeOption) (*LookupHealthCheckResult, error)
func LookupHealthCheckOutput(ctx *Context, args *LookupHealthCheckOutputArgs, opts ...InvokeOption) LookupHealthCheckResultOutput
> Note: This function is named LookupHealthCheck
in the Go SDK.
public static class GetHealthCheck
{
public static Task<GetHealthCheckResult> InvokeAsync(GetHealthCheckArgs args, InvokeOptions? opts = null)
public static Output<GetHealthCheckResult> Invoke(GetHealthCheckInvokeArgs args, InvokeOptions? opts = null)
}
public static CompletableFuture<GetHealthCheckResult> getHealthCheck(GetHealthCheckArgs args, InvokeOptions options)
// Output-based functions aren't available in Java yet
fn::invoke:
function: aws-native:route53:getHealthCheck
arguments:
# arguments dictionary
The following arguments are supported:
- Health
Check stringId - The identifier that Amazon Route 53 assigned to the health check when you created it. When you add or update a resource record set, you use this value to specify which health check to use. The value can be up to 64 characters long.
- Health
Check stringId - The identifier that Amazon Route 53 assigned to the health check when you created it. When you add or update a resource record set, you use this value to specify which health check to use. The value can be up to 64 characters long.
- health
Check StringId - The identifier that Amazon Route 53 assigned to the health check when you created it. When you add or update a resource record set, you use this value to specify which health check to use. The value can be up to 64 characters long.
- health
Check stringId - The identifier that Amazon Route 53 assigned to the health check when you created it. When you add or update a resource record set, you use this value to specify which health check to use. The value can be up to 64 characters long.
- health_
check_ strid - The identifier that Amazon Route 53 assigned to the health check when you created it. When you add or update a resource record set, you use this value to specify which health check to use. The value can be up to 64 characters long.
- health
Check StringId - The identifier that Amazon Route 53 assigned to the health check when you created it. When you add or update a resource record set, you use this value to specify which health check to use. The value can be up to 64 characters long.
getHealthCheck Result
The following output properties are available:
- Health
Check Pulumi.Config Aws Native. Route53. Outputs. Health Check Config Properties - A complex type that contains information about the health check.
- Health
Check stringId - The identifier that Amazon Route 53 assigned to the health check when you created it. When you add or update a resource record set, you use this value to specify which health check to use. The value can be up to 64 characters long.
- List<Pulumi.
Aws Native. Route53. Outputs. Health Check Tag> - An array of key-value pairs to apply to this resource.
- Health
Check HealthConfig Check Config Properties - A complex type that contains information about the health check.
- Health
Check stringId - The identifier that Amazon Route 53 assigned to the health check when you created it. When you add or update a resource record set, you use this value to specify which health check to use. The value can be up to 64 characters long.
- []Health
Check Tag - An array of key-value pairs to apply to this resource.
- health
Check HealthConfig Check Config Properties - A complex type that contains information about the health check.
- health
Check StringId - The identifier that Amazon Route 53 assigned to the health check when you created it. When you add or update a resource record set, you use this value to specify which health check to use. The value can be up to 64 characters long.
- List<Health
Check Tag> - An array of key-value pairs to apply to this resource.
- health
Check HealthConfig Check Config Properties - A complex type that contains information about the health check.
- health
Check stringId - The identifier that Amazon Route 53 assigned to the health check when you created it. When you add or update a resource record set, you use this value to specify which health check to use. The value can be up to 64 characters long.
- Health
Check Tag[] - An array of key-value pairs to apply to this resource.
- health_
check_ Healthconfig Check Config Properties - A complex type that contains information about the health check.
- health_
check_ strid - The identifier that Amazon Route 53 assigned to the health check when you created it. When you add or update a resource record set, you use this value to specify which health check to use. The value can be up to 64 characters long.
- Sequence[Health
Check Tag] - An array of key-value pairs to apply to this resource.
- health
Check Property MapConfig - A complex type that contains information about the health check.
- health
Check StringId - The identifier that Amazon Route 53 assigned to the health check when you created it. When you add or update a resource record set, you use this value to specify which health check to use. The value can be up to 64 characters long.
- List<Property Map>
- An array of key-value pairs to apply to this resource.
Supporting Types
HealthCheckAlarmIdentifier
- Name string
- The name of the CloudWatch alarm that you want Amazon Route 53 health checkers to use to determine whether this health check is healthy.
- Region string
- For the CloudWatch alarm that you want Route 53 health checkers to use to determine whether this health check is healthy, the region that the alarm was created in.
- Name string
- The name of the CloudWatch alarm that you want Amazon Route 53 health checkers to use to determine whether this health check is healthy.
- Region string
- For the CloudWatch alarm that you want Route 53 health checkers to use to determine whether this health check is healthy, the region that the alarm was created in.
- name String
- The name of the CloudWatch alarm that you want Amazon Route 53 health checkers to use to determine whether this health check is healthy.
- region String
- For the CloudWatch alarm that you want Route 53 health checkers to use to determine whether this health check is healthy, the region that the alarm was created in.
- name string
- The name of the CloudWatch alarm that you want Amazon Route 53 health checkers to use to determine whether this health check is healthy.
- region string
- For the CloudWatch alarm that you want Route 53 health checkers to use to determine whether this health check is healthy, the region that the alarm was created in.
- name str
- The name of the CloudWatch alarm that you want Amazon Route 53 health checkers to use to determine whether this health check is healthy.
- region str
- For the CloudWatch alarm that you want Route 53 health checkers to use to determine whether this health check is healthy, the region that the alarm was created in.
- name String
- The name of the CloudWatch alarm that you want Amazon Route 53 health checkers to use to determine whether this health check is healthy.
- region String
- For the CloudWatch alarm that you want Route 53 health checkers to use to determine whether this health check is healthy, the region that the alarm was created in.
HealthCheckConfigProperties
- Type
Pulumi.
Aws Native. Route53. Health Check Config Properties Type The type of health check that you want to create, which indicates how Amazon Route 53 determines whether an endpoint is healthy.
You can't change the value of
Type
after you create a health check.You can create the following types of health checks:
- HTTP : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTP request and waits for an HTTP status code of 200 or greater and less than 400.
- HTTPS : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTPS request and waits for an HTTP status code of 200 or greater and less than 400.
If you specify
HTTPS
for the value ofType
, the endpoint must support TLS v1.0 or later.- HTTP_STR_MATCH : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTP request and searches the first 5,120 bytes of the response body for the string that you specify in
SearchString
. - HTTPS_STR_MATCH : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an
HTTPS
request and searches the first 5,120 bytes of the response body for the string that you specify inSearchString
. - TCP : Route 53 tries to establish a TCP connection.
- CLOUDWATCH_METRIC : The health check is associated with a CloudWatch alarm. If the state of the alarm is
OK
, the health check is considered healthy. If the state isALARM
, the health check is considered unhealthy. If CloudWatch doesn't have sufficient data to determine whether the state isOK
orALARM
, the health check status depends on the setting forInsufficientDataHealthStatus
:Healthy
,Unhealthy
, orLastKnownStatus
.
Route 53 supports CloudWatch alarms with the following features:
- Standard-resolution metrics. High-resolution metrics aren't supported. For more information, see High-Resolution Metrics in the Amazon CloudWatch User Guide .
- Statistics: Average, Minimum, Maximum, Sum, and SampleCount. Extended statistics aren't supported.
- CALCULATED : For health checks that monitor the status of other health checks, Route 53 adds up the number of health checks that Route 53 health checkers consider to be healthy and compares that number with the value of
HealthThreshold
. - RECOVERY_CONTROL : The health check is assocated with a Route53 Application Recovery Controller routing control. If the routing control state is
ON
, the health check is considered healthy. If the state isOFF
, the health check is considered unhealthy.
For more information, see How Route 53 Determines Whether an Endpoint Is Healthy in the Amazon Route 53 Developer Guide .
- Alarm
Identifier Pulumi.Aws Native. Route53. Inputs. Health Check Alarm Identifier - A complex type that identifies the CloudWatch alarm that you want Amazon Route 53 health checkers to use to determine whether the specified health check is healthy.
- Child
Health List<string>Checks - (CALCULATED Health Checks Only) A complex type that contains one
ChildHealthCheck
element for each health check that you want to associate with aCALCULATED
health check. - Enable
Sni bool Specify whether you want Amazon Route 53 to send the value of
FullyQualifiedDomainName
to the endpoint in theclient_hello
message during TLS negotiation. This allows the endpoint to respond toHTTPS
health check requests with the applicable SSL/TLS certificate.Some endpoints require that
HTTPS
requests include the host name in theclient_hello
message. If you don't enable SNI, the status of the health check will beSSL alert handshake_failure
. A health check can also have that status for other reasons. If SNI is enabled and you're still getting the error, check the SSL/TLS configuration on your endpoint and confirm that your certificate is valid.The SSL/TLS certificate on your endpoint includes a domain name in the
Common Name
field and possibly several more in theSubject Alternative Names
field. One of the domain names in the certificate should match the value that you specify forFullyQualifiedDomainName
. If the endpoint responds to theclient_hello
message with a certificate that does not include the domain name that you specified inFullyQualifiedDomainName
, a health checker will retry the handshake. In the second attempt, the health checker will omitFullyQualifiedDomainName
from theclient_hello
message.- Failure
Threshold int The number of consecutive health checks that an endpoint must pass or fail for Amazon Route 53 to change the current status of the endpoint from unhealthy to healthy or vice versa. For more information, see How Amazon Route 53 Determines Whether an Endpoint Is Healthy in the Amazon Route 53 Developer Guide .
If you don't specify a value for
FailureThreshold
, the default value is three health checks.- Fully
Qualified stringDomain Name Amazon Route 53 behavior depends on whether you specify a value for
IPAddress
.If you specify a value for
IPAddress
:Amazon Route 53 sends health check requests to the specified IPv4 or IPv6 address and passes the value of
FullyQualifiedDomainName
in theHost
header for all health checks except TCP health checks. This is typically the fully qualified DNS name of the endpoint on which you want Route 53 to perform health checks.When Route 53 checks the health of an endpoint, here is how it constructs the
Host
header:- If you specify a value of
80
forPort
andHTTP
orHTTP_STR_MATCH
forType
, Route 53 passes the value ofFullyQualifiedDomainName
to the endpoint in the Host header. - If you specify a value of
443
forPort
andHTTPS
orHTTPS_STR_MATCH
forType
, Route 53 passes the value ofFullyQualifiedDomainName
to the endpoint in theHost
header. - If you specify another value for
Port
and any value exceptTCP
forType
, Route 53 passesFullyQualifiedDomainName:Port
to the endpoint in theHost
header.
If you don't specify a value for
FullyQualifiedDomainName
, Route 53 substitutes the value ofIPAddress
in theHost
header in each of the preceding cases.If you don't specify a value for
IPAddress
:Route 53 sends a DNS request to the domain that you specify for
FullyQualifiedDomainName
at the interval that you specify forRequestInterval
. Using an IPv4 address that DNS returns, Route 53 then checks the health of the endpoint.If you don't specify a value for
IPAddress
, Route 53 uses only IPv4 to send health checks to the endpoint. If there's no record with a type of A for the name that you specify forFullyQualifiedDomainName
, the health check fails with a "DNS resolution failed" error.If you want to check the health of multiple records that have the same name and type, such as multiple weighted records, and if you choose to specify the endpoint only by
FullyQualifiedDomainName
, we recommend that you create a separate health check for each endpoint. For example, create a health check for each HTTP server that is serving content for www.example.com. For the value ofFullyQualifiedDomainName
, specify the domain name of the server (such as us-east-2-www.example.com), not the name of the records (www.example.com).In this configuration, if you create a health check for which the value of
FullyQualifiedDomainName
matches the name of the records and you then associate the health check with those records, health check results will be unpredictable.In addition, if the value that you specify for
Type
isHTTP
,HTTPS
,HTTP_STR_MATCH
, orHTTPS_STR_MATCH
, Route 53 passes the value ofFullyQualifiedDomainName
in theHost
header, as it does when you specify a value forIPAddress
. If the value ofType
isTCP
, Route 53 doesn't pass aHost
header.- If you specify a value of
- Health
Threshold int The number of child health checks that are associated with a
CALCULATED
health check that Amazon Route 53 must consider healthy for theCALCULATED
health check to be considered healthy. To specify the child health checks that you want to associate with aCALCULATED
health check, use the ChildHealthChecks element.Note the following:
- If you specify a number greater than the number of child health checks, Route 53 always considers this health check to be unhealthy.
- If you specify
0
, Route 53 always considers this health check to be healthy.
- Insufficient
Data Pulumi.Health Status Aws Native. Route53. Health Check Config Properties Insufficient Data Health Status - When CloudWatch has insufficient data about the metric to determine the alarm state, the status that you want Amazon Route 53 to assign to the health check:
Healthy
: Route 53 considers the health check to be healthy.Unhealthy
: Route 53 considers the health check to be unhealthy.LastKnownStatus
: Route 53 uses the status of the health check from the last time that CloudWatch had sufficient data to determine the alarm state. For new health checks that have no last known status, the default status for the health check is healthy.
- Inverted bool
- Specify whether you want Amazon Route 53 to invert the status of a health check, for example, to consider a health check unhealthy when it otherwise would be considered healthy.
- Ip
Address string The IPv4 or IPv6 IP address of the endpoint that you want Amazon Route 53 to perform health checks on. If you don't specify a value for
IPAddress
, Route 53 sends a DNS request to resolve the domain name that you specify inFullyQualifiedDomainName
at the interval that you specify inRequestInterval
. Using an IP address returned by DNS, Route 53 then checks the health of the endpoint.Use one of the following formats for the value of
IPAddress
:- IPv4 address : four values between 0 and 255, separated by periods (.), for example,
192.0.2.44
. - IPv6 address : eight groups of four hexadecimal values, separated by colons (:), for example,
2001:0db8:85a3:0000:0000:abcd:0001:2345
. You can also shorten IPv6 addresses as described in RFC 5952, for example,2001:db8:85a3::abcd:1:2345
.
If the endpoint is an EC2 instance, we recommend that you create an Elastic IP address, associate it with your EC2 instance, and specify the Elastic IP address for
IPAddress
. This ensures that the IP address of your instance will never change.For more information, see FullyQualifiedDomainName .
Constraints: Route 53 can't check the health of endpoints for which the IP address is in local, private, non-routable, or multicast ranges. For more information about IP addresses for which you can't create health checks, see the following documents:
- RFC 5735, Special Use IPv4 Addresses
- RFC 6598, IANA-Reserved IPv4 Prefix for Shared Address Space
- RFC 5156, Special-Use IPv6 Addresses
When the value of
Type
isCALCULATED
orCLOUDWATCH_METRIC
, omitIPAddress
.- IPv4 address : four values between 0 and 255, separated by periods (.), for example,
- Measure
Latency bool Specify whether you want Amazon Route 53 to measure the latency between health checkers in multiple AWS regions and your endpoint, and to display CloudWatch latency graphs on the Health Checks page in the Route 53 console.
You can't change the value of
MeasureLatency
after you create a health check.- Port int
The port on the endpoint that you want Amazon Route 53 to perform health checks on.
Don't specify a value for
Port
when you specify a value for Type ofCLOUDWATCH_METRIC
orCALCULATED
.- Regions List<string>
A complex type that contains one
Region
element for each region from which you want Amazon Route 53 health checkers to check the specified endpoint.If you don't specify any regions, Route 53 health checkers automatically performs checks from all of the regions that are listed under Valid Values .
If you update a health check to remove a region that has been performing health checks, Route 53 will briefly continue to perform checks from that region to ensure that some health checkers are always checking the endpoint (for example, if you replace three regions with four different regions).
- Request
Interval int The number of seconds between the time that Amazon Route 53 gets a response from your endpoint and the time that it sends the next health check request. Each Route 53 health checker makes requests at this interval.
You can't change the value of
RequestInterval
after you create a health check.If you don't specify a value for
RequestInterval
, the default value is30
seconds.- Resource
Path string - The path, if any, that you want Amazon Route 53 to request when performing health checks. The path can be any value for which your endpoint will return an HTTP status code of 2xx or 3xx when the endpoint is healthy, for example, the file /docs/route53-health-check.html. You can also include query string parameters, for example,
/welcome.html?language=jp&login=y
. - Routing
Control stringArn The Amazon Resource Name (ARN) for the Route 53 Application Recovery Controller routing control.
For more information about Route 53 Application Recovery Controller, see Route 53 Application Recovery Controller Developer Guide. .
- Search
String string If the value of Type is
HTTP_STR_MATCH
orHTTPS_STR_MATCH
, the string that you want Amazon Route 53 to search for in the response body from the specified resource. If the string appears in the response body, Route 53 considers the resource healthy.Route 53 considers case when searching for
SearchString
in the response body.
- Type
Health
Check Config Properties Type The type of health check that you want to create, which indicates how Amazon Route 53 determines whether an endpoint is healthy.
You can't change the value of
Type
after you create a health check.You can create the following types of health checks:
- HTTP : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTP request and waits for an HTTP status code of 200 or greater and less than 400.
- HTTPS : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTPS request and waits for an HTTP status code of 200 or greater and less than 400.
If you specify
HTTPS
for the value ofType
, the endpoint must support TLS v1.0 or later.- HTTP_STR_MATCH : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTP request and searches the first 5,120 bytes of the response body for the string that you specify in
SearchString
. - HTTPS_STR_MATCH : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an
HTTPS
request and searches the first 5,120 bytes of the response body for the string that you specify inSearchString
. - TCP : Route 53 tries to establish a TCP connection.
- CLOUDWATCH_METRIC : The health check is associated with a CloudWatch alarm. If the state of the alarm is
OK
, the health check is considered healthy. If the state isALARM
, the health check is considered unhealthy. If CloudWatch doesn't have sufficient data to determine whether the state isOK
orALARM
, the health check status depends on the setting forInsufficientDataHealthStatus
:Healthy
,Unhealthy
, orLastKnownStatus
.
Route 53 supports CloudWatch alarms with the following features:
- Standard-resolution metrics. High-resolution metrics aren't supported. For more information, see High-Resolution Metrics in the Amazon CloudWatch User Guide .
- Statistics: Average, Minimum, Maximum, Sum, and SampleCount. Extended statistics aren't supported.
- CALCULATED : For health checks that monitor the status of other health checks, Route 53 adds up the number of health checks that Route 53 health checkers consider to be healthy and compares that number with the value of
HealthThreshold
. - RECOVERY_CONTROL : The health check is assocated with a Route53 Application Recovery Controller routing control. If the routing control state is
ON
, the health check is considered healthy. If the state isOFF
, the health check is considered unhealthy.
For more information, see How Route 53 Determines Whether an Endpoint Is Healthy in the Amazon Route 53 Developer Guide .
- Alarm
Identifier HealthCheck Alarm Identifier - A complex type that identifies the CloudWatch alarm that you want Amazon Route 53 health checkers to use to determine whether the specified health check is healthy.
- Child
Health []stringChecks - (CALCULATED Health Checks Only) A complex type that contains one
ChildHealthCheck
element for each health check that you want to associate with aCALCULATED
health check. - Enable
Sni bool Specify whether you want Amazon Route 53 to send the value of
FullyQualifiedDomainName
to the endpoint in theclient_hello
message during TLS negotiation. This allows the endpoint to respond toHTTPS
health check requests with the applicable SSL/TLS certificate.Some endpoints require that
HTTPS
requests include the host name in theclient_hello
message. If you don't enable SNI, the status of the health check will beSSL alert handshake_failure
. A health check can also have that status for other reasons. If SNI is enabled and you're still getting the error, check the SSL/TLS configuration on your endpoint and confirm that your certificate is valid.The SSL/TLS certificate on your endpoint includes a domain name in the
Common Name
field and possibly several more in theSubject Alternative Names
field. One of the domain names in the certificate should match the value that you specify forFullyQualifiedDomainName
. If the endpoint responds to theclient_hello
message with a certificate that does not include the domain name that you specified inFullyQualifiedDomainName
, a health checker will retry the handshake. In the second attempt, the health checker will omitFullyQualifiedDomainName
from theclient_hello
message.- Failure
Threshold int The number of consecutive health checks that an endpoint must pass or fail for Amazon Route 53 to change the current status of the endpoint from unhealthy to healthy or vice versa. For more information, see How Amazon Route 53 Determines Whether an Endpoint Is Healthy in the Amazon Route 53 Developer Guide .
If you don't specify a value for
FailureThreshold
, the default value is three health checks.- Fully
Qualified stringDomain Name Amazon Route 53 behavior depends on whether you specify a value for
IPAddress
.If you specify a value for
IPAddress
:Amazon Route 53 sends health check requests to the specified IPv4 or IPv6 address and passes the value of
FullyQualifiedDomainName
in theHost
header for all health checks except TCP health checks. This is typically the fully qualified DNS name of the endpoint on which you want Route 53 to perform health checks.When Route 53 checks the health of an endpoint, here is how it constructs the
Host
header:- If you specify a value of
80
forPort
andHTTP
orHTTP_STR_MATCH
forType
, Route 53 passes the value ofFullyQualifiedDomainName
to the endpoint in the Host header. - If you specify a value of
443
forPort
andHTTPS
orHTTPS_STR_MATCH
forType
, Route 53 passes the value ofFullyQualifiedDomainName
to the endpoint in theHost
header. - If you specify another value for
Port
and any value exceptTCP
forType
, Route 53 passesFullyQualifiedDomainName:Port
to the endpoint in theHost
header.
If you don't specify a value for
FullyQualifiedDomainName
, Route 53 substitutes the value ofIPAddress
in theHost
header in each of the preceding cases.If you don't specify a value for
IPAddress
:Route 53 sends a DNS request to the domain that you specify for
FullyQualifiedDomainName
at the interval that you specify forRequestInterval
. Using an IPv4 address that DNS returns, Route 53 then checks the health of the endpoint.If you don't specify a value for
IPAddress
, Route 53 uses only IPv4 to send health checks to the endpoint. If there's no record with a type of A for the name that you specify forFullyQualifiedDomainName
, the health check fails with a "DNS resolution failed" error.If you want to check the health of multiple records that have the same name and type, such as multiple weighted records, and if you choose to specify the endpoint only by
FullyQualifiedDomainName
, we recommend that you create a separate health check for each endpoint. For example, create a health check for each HTTP server that is serving content for www.example.com. For the value ofFullyQualifiedDomainName
, specify the domain name of the server (such as us-east-2-www.example.com), not the name of the records (www.example.com).In this configuration, if you create a health check for which the value of
FullyQualifiedDomainName
matches the name of the records and you then associate the health check with those records, health check results will be unpredictable.In addition, if the value that you specify for
Type
isHTTP
,HTTPS
,HTTP_STR_MATCH
, orHTTPS_STR_MATCH
, Route 53 passes the value ofFullyQualifiedDomainName
in theHost
header, as it does when you specify a value forIPAddress
. If the value ofType
isTCP
, Route 53 doesn't pass aHost
header.- If you specify a value of
- Health
Threshold int The number of child health checks that are associated with a
CALCULATED
health check that Amazon Route 53 must consider healthy for theCALCULATED
health check to be considered healthy. To specify the child health checks that you want to associate with aCALCULATED
health check, use the ChildHealthChecks element.Note the following:
- If you specify a number greater than the number of child health checks, Route 53 always considers this health check to be unhealthy.
- If you specify
0
, Route 53 always considers this health check to be healthy.
- Insufficient
Data HealthHealth Status Check Config Properties Insufficient Data Health Status - When CloudWatch has insufficient data about the metric to determine the alarm state, the status that you want Amazon Route 53 to assign to the health check:
Healthy
: Route 53 considers the health check to be healthy.Unhealthy
: Route 53 considers the health check to be unhealthy.LastKnownStatus
: Route 53 uses the status of the health check from the last time that CloudWatch had sufficient data to determine the alarm state. For new health checks that have no last known status, the default status for the health check is healthy.
- Inverted bool
- Specify whether you want Amazon Route 53 to invert the status of a health check, for example, to consider a health check unhealthy when it otherwise would be considered healthy.
- Ip
Address string The IPv4 or IPv6 IP address of the endpoint that you want Amazon Route 53 to perform health checks on. If you don't specify a value for
IPAddress
, Route 53 sends a DNS request to resolve the domain name that you specify inFullyQualifiedDomainName
at the interval that you specify inRequestInterval
. Using an IP address returned by DNS, Route 53 then checks the health of the endpoint.Use one of the following formats for the value of
IPAddress
:- IPv4 address : four values between 0 and 255, separated by periods (.), for example,
192.0.2.44
. - IPv6 address : eight groups of four hexadecimal values, separated by colons (:), for example,
2001:0db8:85a3:0000:0000:abcd:0001:2345
. You can also shorten IPv6 addresses as described in RFC 5952, for example,2001:db8:85a3::abcd:1:2345
.
If the endpoint is an EC2 instance, we recommend that you create an Elastic IP address, associate it with your EC2 instance, and specify the Elastic IP address for
IPAddress
. This ensures that the IP address of your instance will never change.For more information, see FullyQualifiedDomainName .
Constraints: Route 53 can't check the health of endpoints for which the IP address is in local, private, non-routable, or multicast ranges. For more information about IP addresses for which you can't create health checks, see the following documents:
- RFC 5735, Special Use IPv4 Addresses
- RFC 6598, IANA-Reserved IPv4 Prefix for Shared Address Space
- RFC 5156, Special-Use IPv6 Addresses
When the value of
Type
isCALCULATED
orCLOUDWATCH_METRIC
, omitIPAddress
.- IPv4 address : four values between 0 and 255, separated by periods (.), for example,
- Measure
Latency bool Specify whether you want Amazon Route 53 to measure the latency between health checkers in multiple AWS regions and your endpoint, and to display CloudWatch latency graphs on the Health Checks page in the Route 53 console.
You can't change the value of
MeasureLatency
after you create a health check.- Port int
The port on the endpoint that you want Amazon Route 53 to perform health checks on.
Don't specify a value for
Port
when you specify a value for Type ofCLOUDWATCH_METRIC
orCALCULATED
.- Regions []string
A complex type that contains one
Region
element for each region from which you want Amazon Route 53 health checkers to check the specified endpoint.If you don't specify any regions, Route 53 health checkers automatically performs checks from all of the regions that are listed under Valid Values .
If you update a health check to remove a region that has been performing health checks, Route 53 will briefly continue to perform checks from that region to ensure that some health checkers are always checking the endpoint (for example, if you replace three regions with four different regions).
- Request
Interval int The number of seconds between the time that Amazon Route 53 gets a response from your endpoint and the time that it sends the next health check request. Each Route 53 health checker makes requests at this interval.
You can't change the value of
RequestInterval
after you create a health check.If you don't specify a value for
RequestInterval
, the default value is30
seconds.- Resource
Path string - The path, if any, that you want Amazon Route 53 to request when performing health checks. The path can be any value for which your endpoint will return an HTTP status code of 2xx or 3xx when the endpoint is healthy, for example, the file /docs/route53-health-check.html. You can also include query string parameters, for example,
/welcome.html?language=jp&login=y
. - Routing
Control stringArn The Amazon Resource Name (ARN) for the Route 53 Application Recovery Controller routing control.
For more information about Route 53 Application Recovery Controller, see Route 53 Application Recovery Controller Developer Guide. .
- Search
String string If the value of Type is
HTTP_STR_MATCH
orHTTPS_STR_MATCH
, the string that you want Amazon Route 53 to search for in the response body from the specified resource. If the string appears in the response body, Route 53 considers the resource healthy.Route 53 considers case when searching for
SearchString
in the response body.
- type
Health
Check Config Properties Type The type of health check that you want to create, which indicates how Amazon Route 53 determines whether an endpoint is healthy.
You can't change the value of
Type
after you create a health check.You can create the following types of health checks:
- HTTP : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTP request and waits for an HTTP status code of 200 or greater and less than 400.
- HTTPS : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTPS request and waits for an HTTP status code of 200 or greater and less than 400.
If you specify
HTTPS
for the value ofType
, the endpoint must support TLS v1.0 or later.- HTTP_STR_MATCH : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTP request and searches the first 5,120 bytes of the response body for the string that you specify in
SearchString
. - HTTPS_STR_MATCH : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an
HTTPS
request and searches the first 5,120 bytes of the response body for the string that you specify inSearchString
. - TCP : Route 53 tries to establish a TCP connection.
- CLOUDWATCH_METRIC : The health check is associated with a CloudWatch alarm. If the state of the alarm is
OK
, the health check is considered healthy. If the state isALARM
, the health check is considered unhealthy. If CloudWatch doesn't have sufficient data to determine whether the state isOK
orALARM
, the health check status depends on the setting forInsufficientDataHealthStatus
:Healthy
,Unhealthy
, orLastKnownStatus
.
Route 53 supports CloudWatch alarms with the following features:
- Standard-resolution metrics. High-resolution metrics aren't supported. For more information, see High-Resolution Metrics in the Amazon CloudWatch User Guide .
- Statistics: Average, Minimum, Maximum, Sum, and SampleCount. Extended statistics aren't supported.
- CALCULATED : For health checks that monitor the status of other health checks, Route 53 adds up the number of health checks that Route 53 health checkers consider to be healthy and compares that number with the value of
HealthThreshold
. - RECOVERY_CONTROL : The health check is assocated with a Route53 Application Recovery Controller routing control. If the routing control state is
ON
, the health check is considered healthy. If the state isOFF
, the health check is considered unhealthy.
For more information, see How Route 53 Determines Whether an Endpoint Is Healthy in the Amazon Route 53 Developer Guide .
- alarm
Identifier HealthCheck Alarm Identifier - A complex type that identifies the CloudWatch alarm that you want Amazon Route 53 health checkers to use to determine whether the specified health check is healthy.
- child
Health List<String>Checks - (CALCULATED Health Checks Only) A complex type that contains one
ChildHealthCheck
element for each health check that you want to associate with aCALCULATED
health check. - enable
Sni Boolean Specify whether you want Amazon Route 53 to send the value of
FullyQualifiedDomainName
to the endpoint in theclient_hello
message during TLS negotiation. This allows the endpoint to respond toHTTPS
health check requests with the applicable SSL/TLS certificate.Some endpoints require that
HTTPS
requests include the host name in theclient_hello
message. If you don't enable SNI, the status of the health check will beSSL alert handshake_failure
. A health check can also have that status for other reasons. If SNI is enabled and you're still getting the error, check the SSL/TLS configuration on your endpoint and confirm that your certificate is valid.The SSL/TLS certificate on your endpoint includes a domain name in the
Common Name
field and possibly several more in theSubject Alternative Names
field. One of the domain names in the certificate should match the value that you specify forFullyQualifiedDomainName
. If the endpoint responds to theclient_hello
message with a certificate that does not include the domain name that you specified inFullyQualifiedDomainName
, a health checker will retry the handshake. In the second attempt, the health checker will omitFullyQualifiedDomainName
from theclient_hello
message.- failure
Threshold Integer The number of consecutive health checks that an endpoint must pass or fail for Amazon Route 53 to change the current status of the endpoint from unhealthy to healthy or vice versa. For more information, see How Amazon Route 53 Determines Whether an Endpoint Is Healthy in the Amazon Route 53 Developer Guide .
If you don't specify a value for
FailureThreshold
, the default value is three health checks.- fully
Qualified StringDomain Name Amazon Route 53 behavior depends on whether you specify a value for
IPAddress
.If you specify a value for
IPAddress
:Amazon Route 53 sends health check requests to the specified IPv4 or IPv6 address and passes the value of
FullyQualifiedDomainName
in theHost
header for all health checks except TCP health checks. This is typically the fully qualified DNS name of the endpoint on which you want Route 53 to perform health checks.When Route 53 checks the health of an endpoint, here is how it constructs the
Host
header:- If you specify a value of
80
forPort
andHTTP
orHTTP_STR_MATCH
forType
, Route 53 passes the value ofFullyQualifiedDomainName
to the endpoint in the Host header. - If you specify a value of
443
forPort
andHTTPS
orHTTPS_STR_MATCH
forType
, Route 53 passes the value ofFullyQualifiedDomainName
to the endpoint in theHost
header. - If you specify another value for
Port
and any value exceptTCP
forType
, Route 53 passesFullyQualifiedDomainName:Port
to the endpoint in theHost
header.
If you don't specify a value for
FullyQualifiedDomainName
, Route 53 substitutes the value ofIPAddress
in theHost
header in each of the preceding cases.If you don't specify a value for
IPAddress
:Route 53 sends a DNS request to the domain that you specify for
FullyQualifiedDomainName
at the interval that you specify forRequestInterval
. Using an IPv4 address that DNS returns, Route 53 then checks the health of the endpoint.If you don't specify a value for
IPAddress
, Route 53 uses only IPv4 to send health checks to the endpoint. If there's no record with a type of A for the name that you specify forFullyQualifiedDomainName
, the health check fails with a "DNS resolution failed" error.If you want to check the health of multiple records that have the same name and type, such as multiple weighted records, and if you choose to specify the endpoint only by
FullyQualifiedDomainName
, we recommend that you create a separate health check for each endpoint. For example, create a health check for each HTTP server that is serving content for www.example.com. For the value ofFullyQualifiedDomainName
, specify the domain name of the server (such as us-east-2-www.example.com), not the name of the records (www.example.com).In this configuration, if you create a health check for which the value of
FullyQualifiedDomainName
matches the name of the records and you then associate the health check with those records, health check results will be unpredictable.In addition, if the value that you specify for
Type
isHTTP
,HTTPS
,HTTP_STR_MATCH
, orHTTPS_STR_MATCH
, Route 53 passes the value ofFullyQualifiedDomainName
in theHost
header, as it does when you specify a value forIPAddress
. If the value ofType
isTCP
, Route 53 doesn't pass aHost
header.- If you specify a value of
- health
Threshold Integer The number of child health checks that are associated with a
CALCULATED
health check that Amazon Route 53 must consider healthy for theCALCULATED
health check to be considered healthy. To specify the child health checks that you want to associate with aCALCULATED
health check, use the ChildHealthChecks element.Note the following:
- If you specify a number greater than the number of child health checks, Route 53 always considers this health check to be unhealthy.
- If you specify
0
, Route 53 always considers this health check to be healthy.
- insufficient
Data HealthHealth Status Check Config Properties Insufficient Data Health Status - When CloudWatch has insufficient data about the metric to determine the alarm state, the status that you want Amazon Route 53 to assign to the health check:
Healthy
: Route 53 considers the health check to be healthy.Unhealthy
: Route 53 considers the health check to be unhealthy.LastKnownStatus
: Route 53 uses the status of the health check from the last time that CloudWatch had sufficient data to determine the alarm state. For new health checks that have no last known status, the default status for the health check is healthy.
- inverted Boolean
- Specify whether you want Amazon Route 53 to invert the status of a health check, for example, to consider a health check unhealthy when it otherwise would be considered healthy.
- ip
Address String The IPv4 or IPv6 IP address of the endpoint that you want Amazon Route 53 to perform health checks on. If you don't specify a value for
IPAddress
, Route 53 sends a DNS request to resolve the domain name that you specify inFullyQualifiedDomainName
at the interval that you specify inRequestInterval
. Using an IP address returned by DNS, Route 53 then checks the health of the endpoint.Use one of the following formats for the value of
IPAddress
:- IPv4 address : four values between 0 and 255, separated by periods (.), for example,
192.0.2.44
. - IPv6 address : eight groups of four hexadecimal values, separated by colons (:), for example,
2001:0db8:85a3:0000:0000:abcd:0001:2345
. You can also shorten IPv6 addresses as described in RFC 5952, for example,2001:db8:85a3::abcd:1:2345
.
If the endpoint is an EC2 instance, we recommend that you create an Elastic IP address, associate it with your EC2 instance, and specify the Elastic IP address for
IPAddress
. This ensures that the IP address of your instance will never change.For more information, see FullyQualifiedDomainName .
Constraints: Route 53 can't check the health of endpoints for which the IP address is in local, private, non-routable, or multicast ranges. For more information about IP addresses for which you can't create health checks, see the following documents:
- RFC 5735, Special Use IPv4 Addresses
- RFC 6598, IANA-Reserved IPv4 Prefix for Shared Address Space
- RFC 5156, Special-Use IPv6 Addresses
When the value of
Type
isCALCULATED
orCLOUDWATCH_METRIC
, omitIPAddress
.- IPv4 address : four values between 0 and 255, separated by periods (.), for example,
- measure
Latency Boolean Specify whether you want Amazon Route 53 to measure the latency between health checkers in multiple AWS regions and your endpoint, and to display CloudWatch latency graphs on the Health Checks page in the Route 53 console.
You can't change the value of
MeasureLatency
after you create a health check.- port Integer
The port on the endpoint that you want Amazon Route 53 to perform health checks on.
Don't specify a value for
Port
when you specify a value for Type ofCLOUDWATCH_METRIC
orCALCULATED
.- regions List<String>
A complex type that contains one
Region
element for each region from which you want Amazon Route 53 health checkers to check the specified endpoint.If you don't specify any regions, Route 53 health checkers automatically performs checks from all of the regions that are listed under Valid Values .
If you update a health check to remove a region that has been performing health checks, Route 53 will briefly continue to perform checks from that region to ensure that some health checkers are always checking the endpoint (for example, if you replace three regions with four different regions).
- request
Interval Integer The number of seconds between the time that Amazon Route 53 gets a response from your endpoint and the time that it sends the next health check request. Each Route 53 health checker makes requests at this interval.
You can't change the value of
RequestInterval
after you create a health check.If you don't specify a value for
RequestInterval
, the default value is30
seconds.- resource
Path String - The path, if any, that you want Amazon Route 53 to request when performing health checks. The path can be any value for which your endpoint will return an HTTP status code of 2xx or 3xx when the endpoint is healthy, for example, the file /docs/route53-health-check.html. You can also include query string parameters, for example,
/welcome.html?language=jp&login=y
. - routing
Control StringArn The Amazon Resource Name (ARN) for the Route 53 Application Recovery Controller routing control.
For more information about Route 53 Application Recovery Controller, see Route 53 Application Recovery Controller Developer Guide. .
- search
String String If the value of Type is
HTTP_STR_MATCH
orHTTPS_STR_MATCH
, the string that you want Amazon Route 53 to search for in the response body from the specified resource. If the string appears in the response body, Route 53 considers the resource healthy.Route 53 considers case when searching for
SearchString
in the response body.
- type
Health
Check Config Properties Type The type of health check that you want to create, which indicates how Amazon Route 53 determines whether an endpoint is healthy.
You can't change the value of
Type
after you create a health check.You can create the following types of health checks:
- HTTP : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTP request and waits for an HTTP status code of 200 or greater and less than 400.
- HTTPS : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTPS request and waits for an HTTP status code of 200 or greater and less than 400.
If you specify
HTTPS
for the value ofType
, the endpoint must support TLS v1.0 or later.- HTTP_STR_MATCH : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTP request and searches the first 5,120 bytes of the response body for the string that you specify in
SearchString
. - HTTPS_STR_MATCH : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an
HTTPS
request and searches the first 5,120 bytes of the response body for the string that you specify inSearchString
. - TCP : Route 53 tries to establish a TCP connection.
- CLOUDWATCH_METRIC : The health check is associated with a CloudWatch alarm. If the state of the alarm is
OK
, the health check is considered healthy. If the state isALARM
, the health check is considered unhealthy. If CloudWatch doesn't have sufficient data to determine whether the state isOK
orALARM
, the health check status depends on the setting forInsufficientDataHealthStatus
:Healthy
,Unhealthy
, orLastKnownStatus
.
Route 53 supports CloudWatch alarms with the following features:
- Standard-resolution metrics. High-resolution metrics aren't supported. For more information, see High-Resolution Metrics in the Amazon CloudWatch User Guide .
- Statistics: Average, Minimum, Maximum, Sum, and SampleCount. Extended statistics aren't supported.
- CALCULATED : For health checks that monitor the status of other health checks, Route 53 adds up the number of health checks that Route 53 health checkers consider to be healthy and compares that number with the value of
HealthThreshold
. - RECOVERY_CONTROL : The health check is assocated with a Route53 Application Recovery Controller routing control. If the routing control state is
ON
, the health check is considered healthy. If the state isOFF
, the health check is considered unhealthy.
For more information, see How Route 53 Determines Whether an Endpoint Is Healthy in the Amazon Route 53 Developer Guide .
- alarm
Identifier HealthCheck Alarm Identifier - A complex type that identifies the CloudWatch alarm that you want Amazon Route 53 health checkers to use to determine whether the specified health check is healthy.
- child
Health string[]Checks - (CALCULATED Health Checks Only) A complex type that contains one
ChildHealthCheck
element for each health check that you want to associate with aCALCULATED
health check. - enable
Sni boolean Specify whether you want Amazon Route 53 to send the value of
FullyQualifiedDomainName
to the endpoint in theclient_hello
message during TLS negotiation. This allows the endpoint to respond toHTTPS
health check requests with the applicable SSL/TLS certificate.Some endpoints require that
HTTPS
requests include the host name in theclient_hello
message. If you don't enable SNI, the status of the health check will beSSL alert handshake_failure
. A health check can also have that status for other reasons. If SNI is enabled and you're still getting the error, check the SSL/TLS configuration on your endpoint and confirm that your certificate is valid.The SSL/TLS certificate on your endpoint includes a domain name in the
Common Name
field and possibly several more in theSubject Alternative Names
field. One of the domain names in the certificate should match the value that you specify forFullyQualifiedDomainName
. If the endpoint responds to theclient_hello
message with a certificate that does not include the domain name that you specified inFullyQualifiedDomainName
, a health checker will retry the handshake. In the second attempt, the health checker will omitFullyQualifiedDomainName
from theclient_hello
message.- failure
Threshold number The number of consecutive health checks that an endpoint must pass or fail for Amazon Route 53 to change the current status of the endpoint from unhealthy to healthy or vice versa. For more information, see How Amazon Route 53 Determines Whether an Endpoint Is Healthy in the Amazon Route 53 Developer Guide .
If you don't specify a value for
FailureThreshold
, the default value is three health checks.- fully
Qualified stringDomain Name Amazon Route 53 behavior depends on whether you specify a value for
IPAddress
.If you specify a value for
IPAddress
:Amazon Route 53 sends health check requests to the specified IPv4 or IPv6 address and passes the value of
FullyQualifiedDomainName
in theHost
header for all health checks except TCP health checks. This is typically the fully qualified DNS name of the endpoint on which you want Route 53 to perform health checks.When Route 53 checks the health of an endpoint, here is how it constructs the
Host
header:- If you specify a value of
80
forPort
andHTTP
orHTTP_STR_MATCH
forType
, Route 53 passes the value ofFullyQualifiedDomainName
to the endpoint in the Host header. - If you specify a value of
443
forPort
andHTTPS
orHTTPS_STR_MATCH
forType
, Route 53 passes the value ofFullyQualifiedDomainName
to the endpoint in theHost
header. - If you specify another value for
Port
and any value exceptTCP
forType
, Route 53 passesFullyQualifiedDomainName:Port
to the endpoint in theHost
header.
If you don't specify a value for
FullyQualifiedDomainName
, Route 53 substitutes the value ofIPAddress
in theHost
header in each of the preceding cases.If you don't specify a value for
IPAddress
:Route 53 sends a DNS request to the domain that you specify for
FullyQualifiedDomainName
at the interval that you specify forRequestInterval
. Using an IPv4 address that DNS returns, Route 53 then checks the health of the endpoint.If you don't specify a value for
IPAddress
, Route 53 uses only IPv4 to send health checks to the endpoint. If there's no record with a type of A for the name that you specify forFullyQualifiedDomainName
, the health check fails with a "DNS resolution failed" error.If you want to check the health of multiple records that have the same name and type, such as multiple weighted records, and if you choose to specify the endpoint only by
FullyQualifiedDomainName
, we recommend that you create a separate health check for each endpoint. For example, create a health check for each HTTP server that is serving content for www.example.com. For the value ofFullyQualifiedDomainName
, specify the domain name of the server (such as us-east-2-www.example.com), not the name of the records (www.example.com).In this configuration, if you create a health check for which the value of
FullyQualifiedDomainName
matches the name of the records and you then associate the health check with those records, health check results will be unpredictable.In addition, if the value that you specify for
Type
isHTTP
,HTTPS
,HTTP_STR_MATCH
, orHTTPS_STR_MATCH
, Route 53 passes the value ofFullyQualifiedDomainName
in theHost
header, as it does when you specify a value forIPAddress
. If the value ofType
isTCP
, Route 53 doesn't pass aHost
header.- If you specify a value of
- health
Threshold number The number of child health checks that are associated with a
CALCULATED
health check that Amazon Route 53 must consider healthy for theCALCULATED
health check to be considered healthy. To specify the child health checks that you want to associate with aCALCULATED
health check, use the ChildHealthChecks element.Note the following:
- If you specify a number greater than the number of child health checks, Route 53 always considers this health check to be unhealthy.
- If you specify
0
, Route 53 always considers this health check to be healthy.
- insufficient
Data HealthHealth Status Check Config Properties Insufficient Data Health Status - When CloudWatch has insufficient data about the metric to determine the alarm state, the status that you want Amazon Route 53 to assign to the health check:
Healthy
: Route 53 considers the health check to be healthy.Unhealthy
: Route 53 considers the health check to be unhealthy.LastKnownStatus
: Route 53 uses the status of the health check from the last time that CloudWatch had sufficient data to determine the alarm state. For new health checks that have no last known status, the default status for the health check is healthy.
- inverted boolean
- Specify whether you want Amazon Route 53 to invert the status of a health check, for example, to consider a health check unhealthy when it otherwise would be considered healthy.
- ip
Address string The IPv4 or IPv6 IP address of the endpoint that you want Amazon Route 53 to perform health checks on. If you don't specify a value for
IPAddress
, Route 53 sends a DNS request to resolve the domain name that you specify inFullyQualifiedDomainName
at the interval that you specify inRequestInterval
. Using an IP address returned by DNS, Route 53 then checks the health of the endpoint.Use one of the following formats for the value of
IPAddress
:- IPv4 address : four values between 0 and 255, separated by periods (.), for example,
192.0.2.44
. - IPv6 address : eight groups of four hexadecimal values, separated by colons (:), for example,
2001:0db8:85a3:0000:0000:abcd:0001:2345
. You can also shorten IPv6 addresses as described in RFC 5952, for example,2001:db8:85a3::abcd:1:2345
.
If the endpoint is an EC2 instance, we recommend that you create an Elastic IP address, associate it with your EC2 instance, and specify the Elastic IP address for
IPAddress
. This ensures that the IP address of your instance will never change.For more information, see FullyQualifiedDomainName .
Constraints: Route 53 can't check the health of endpoints for which the IP address is in local, private, non-routable, or multicast ranges. For more information about IP addresses for which you can't create health checks, see the following documents:
- RFC 5735, Special Use IPv4 Addresses
- RFC 6598, IANA-Reserved IPv4 Prefix for Shared Address Space
- RFC 5156, Special-Use IPv6 Addresses
When the value of
Type
isCALCULATED
orCLOUDWATCH_METRIC
, omitIPAddress
.- IPv4 address : four values between 0 and 255, separated by periods (.), for example,
- measure
Latency boolean Specify whether you want Amazon Route 53 to measure the latency between health checkers in multiple AWS regions and your endpoint, and to display CloudWatch latency graphs on the Health Checks page in the Route 53 console.
You can't change the value of
MeasureLatency
after you create a health check.- port number
The port on the endpoint that you want Amazon Route 53 to perform health checks on.
Don't specify a value for
Port
when you specify a value for Type ofCLOUDWATCH_METRIC
orCALCULATED
.- regions string[]
A complex type that contains one
Region
element for each region from which you want Amazon Route 53 health checkers to check the specified endpoint.If you don't specify any regions, Route 53 health checkers automatically performs checks from all of the regions that are listed under Valid Values .
If you update a health check to remove a region that has been performing health checks, Route 53 will briefly continue to perform checks from that region to ensure that some health checkers are always checking the endpoint (for example, if you replace three regions with four different regions).
- request
Interval number The number of seconds between the time that Amazon Route 53 gets a response from your endpoint and the time that it sends the next health check request. Each Route 53 health checker makes requests at this interval.
You can't change the value of
RequestInterval
after you create a health check.If you don't specify a value for
RequestInterval
, the default value is30
seconds.- resource
Path string - The path, if any, that you want Amazon Route 53 to request when performing health checks. The path can be any value for which your endpoint will return an HTTP status code of 2xx or 3xx when the endpoint is healthy, for example, the file /docs/route53-health-check.html. You can also include query string parameters, for example,
/welcome.html?language=jp&login=y
. - routing
Control stringArn The Amazon Resource Name (ARN) for the Route 53 Application Recovery Controller routing control.
For more information about Route 53 Application Recovery Controller, see Route 53 Application Recovery Controller Developer Guide. .
- search
String string If the value of Type is
HTTP_STR_MATCH
orHTTPS_STR_MATCH
, the string that you want Amazon Route 53 to search for in the response body from the specified resource. If the string appears in the response body, Route 53 considers the resource healthy.Route 53 considers case when searching for
SearchString
in the response body.
- type
Health
Check Config Properties Type The type of health check that you want to create, which indicates how Amazon Route 53 determines whether an endpoint is healthy.
You can't change the value of
Type
after you create a health check.You can create the following types of health checks:
- HTTP : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTP request and waits for an HTTP status code of 200 or greater and less than 400.
- HTTPS : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTPS request and waits for an HTTP status code of 200 or greater and less than 400.
If you specify
HTTPS
for the value ofType
, the endpoint must support TLS v1.0 or later.- HTTP_STR_MATCH : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTP request and searches the first 5,120 bytes of the response body for the string that you specify in
SearchString
. - HTTPS_STR_MATCH : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an
HTTPS
request and searches the first 5,120 bytes of the response body for the string that you specify inSearchString
. - TCP : Route 53 tries to establish a TCP connection.
- CLOUDWATCH_METRIC : The health check is associated with a CloudWatch alarm. If the state of the alarm is
OK
, the health check is considered healthy. If the state isALARM
, the health check is considered unhealthy. If CloudWatch doesn't have sufficient data to determine whether the state isOK
orALARM
, the health check status depends on the setting forInsufficientDataHealthStatus
:Healthy
,Unhealthy
, orLastKnownStatus
.
Route 53 supports CloudWatch alarms with the following features:
- Standard-resolution metrics. High-resolution metrics aren't supported. For more information, see High-Resolution Metrics in the Amazon CloudWatch User Guide .
- Statistics: Average, Minimum, Maximum, Sum, and SampleCount. Extended statistics aren't supported.
- CALCULATED : For health checks that monitor the status of other health checks, Route 53 adds up the number of health checks that Route 53 health checkers consider to be healthy and compares that number with the value of
HealthThreshold
. - RECOVERY_CONTROL : The health check is assocated with a Route53 Application Recovery Controller routing control. If the routing control state is
ON
, the health check is considered healthy. If the state isOFF
, the health check is considered unhealthy.
For more information, see How Route 53 Determines Whether an Endpoint Is Healthy in the Amazon Route 53 Developer Guide .
- alarm_
identifier HealthCheck Alarm Identifier - A complex type that identifies the CloudWatch alarm that you want Amazon Route 53 health checkers to use to determine whether the specified health check is healthy.
- child_
health_ Sequence[str]checks - (CALCULATED Health Checks Only) A complex type that contains one
ChildHealthCheck
element for each health check that you want to associate with aCALCULATED
health check. - enable_
sni bool Specify whether you want Amazon Route 53 to send the value of
FullyQualifiedDomainName
to the endpoint in theclient_hello
message during TLS negotiation. This allows the endpoint to respond toHTTPS
health check requests with the applicable SSL/TLS certificate.Some endpoints require that
HTTPS
requests include the host name in theclient_hello
message. If you don't enable SNI, the status of the health check will beSSL alert handshake_failure
. A health check can also have that status for other reasons. If SNI is enabled and you're still getting the error, check the SSL/TLS configuration on your endpoint and confirm that your certificate is valid.The SSL/TLS certificate on your endpoint includes a domain name in the
Common Name
field and possibly several more in theSubject Alternative Names
field. One of the domain names in the certificate should match the value that you specify forFullyQualifiedDomainName
. If the endpoint responds to theclient_hello
message with a certificate that does not include the domain name that you specified inFullyQualifiedDomainName
, a health checker will retry the handshake. In the second attempt, the health checker will omitFullyQualifiedDomainName
from theclient_hello
message.- failure_
threshold int The number of consecutive health checks that an endpoint must pass or fail for Amazon Route 53 to change the current status of the endpoint from unhealthy to healthy or vice versa. For more information, see How Amazon Route 53 Determines Whether an Endpoint Is Healthy in the Amazon Route 53 Developer Guide .
If you don't specify a value for
FailureThreshold
, the default value is three health checks.- fully_
qualified_ strdomain_ name Amazon Route 53 behavior depends on whether you specify a value for
IPAddress
.If you specify a value for
IPAddress
:Amazon Route 53 sends health check requests to the specified IPv4 or IPv6 address and passes the value of
FullyQualifiedDomainName
in theHost
header for all health checks except TCP health checks. This is typically the fully qualified DNS name of the endpoint on which you want Route 53 to perform health checks.When Route 53 checks the health of an endpoint, here is how it constructs the
Host
header:- If you specify a value of
80
forPort
andHTTP
orHTTP_STR_MATCH
forType
, Route 53 passes the value ofFullyQualifiedDomainName
to the endpoint in the Host header. - If you specify a value of
443
forPort
andHTTPS
orHTTPS_STR_MATCH
forType
, Route 53 passes the value ofFullyQualifiedDomainName
to the endpoint in theHost
header. - If you specify another value for
Port
and any value exceptTCP
forType
, Route 53 passesFullyQualifiedDomainName:Port
to the endpoint in theHost
header.
If you don't specify a value for
FullyQualifiedDomainName
, Route 53 substitutes the value ofIPAddress
in theHost
header in each of the preceding cases.If you don't specify a value for
IPAddress
:Route 53 sends a DNS request to the domain that you specify for
FullyQualifiedDomainName
at the interval that you specify forRequestInterval
. Using an IPv4 address that DNS returns, Route 53 then checks the health of the endpoint.If you don't specify a value for
IPAddress
, Route 53 uses only IPv4 to send health checks to the endpoint. If there's no record with a type of A for the name that you specify forFullyQualifiedDomainName
, the health check fails with a "DNS resolution failed" error.If you want to check the health of multiple records that have the same name and type, such as multiple weighted records, and if you choose to specify the endpoint only by
FullyQualifiedDomainName
, we recommend that you create a separate health check for each endpoint. For example, create a health check for each HTTP server that is serving content for www.example.com. For the value ofFullyQualifiedDomainName
, specify the domain name of the server (such as us-east-2-www.example.com), not the name of the records (www.example.com).In this configuration, if you create a health check for which the value of
FullyQualifiedDomainName
matches the name of the records and you then associate the health check with those records, health check results will be unpredictable.In addition, if the value that you specify for
Type
isHTTP
,HTTPS
,HTTP_STR_MATCH
, orHTTPS_STR_MATCH
, Route 53 passes the value ofFullyQualifiedDomainName
in theHost
header, as it does when you specify a value forIPAddress
. If the value ofType
isTCP
, Route 53 doesn't pass aHost
header.- If you specify a value of
- health_
threshold int The number of child health checks that are associated with a
CALCULATED
health check that Amazon Route 53 must consider healthy for theCALCULATED
health check to be considered healthy. To specify the child health checks that you want to associate with aCALCULATED
health check, use the ChildHealthChecks element.Note the following:
- If you specify a number greater than the number of child health checks, Route 53 always considers this health check to be unhealthy.
- If you specify
0
, Route 53 always considers this health check to be healthy.
- insufficient_
data_ Healthhealth_ status Check Config Properties Insufficient Data Health Status - When CloudWatch has insufficient data about the metric to determine the alarm state, the status that you want Amazon Route 53 to assign to the health check:
Healthy
: Route 53 considers the health check to be healthy.Unhealthy
: Route 53 considers the health check to be unhealthy.LastKnownStatus
: Route 53 uses the status of the health check from the last time that CloudWatch had sufficient data to determine the alarm state. For new health checks that have no last known status, the default status for the health check is healthy.
- inverted bool
- Specify whether you want Amazon Route 53 to invert the status of a health check, for example, to consider a health check unhealthy when it otherwise would be considered healthy.
- ip_
address str The IPv4 or IPv6 IP address of the endpoint that you want Amazon Route 53 to perform health checks on. If you don't specify a value for
IPAddress
, Route 53 sends a DNS request to resolve the domain name that you specify inFullyQualifiedDomainName
at the interval that you specify inRequestInterval
. Using an IP address returned by DNS, Route 53 then checks the health of the endpoint.Use one of the following formats for the value of
IPAddress
:- IPv4 address : four values between 0 and 255, separated by periods (.), for example,
192.0.2.44
. - IPv6 address : eight groups of four hexadecimal values, separated by colons (:), for example,
2001:0db8:85a3:0000:0000:abcd:0001:2345
. You can also shorten IPv6 addresses as described in RFC 5952, for example,2001:db8:85a3::abcd:1:2345
.
If the endpoint is an EC2 instance, we recommend that you create an Elastic IP address, associate it with your EC2 instance, and specify the Elastic IP address for
IPAddress
. This ensures that the IP address of your instance will never change.For more information, see FullyQualifiedDomainName .
Constraints: Route 53 can't check the health of endpoints for which the IP address is in local, private, non-routable, or multicast ranges. For more information about IP addresses for which you can't create health checks, see the following documents:
- RFC 5735, Special Use IPv4 Addresses
- RFC 6598, IANA-Reserved IPv4 Prefix for Shared Address Space
- RFC 5156, Special-Use IPv6 Addresses
When the value of
Type
isCALCULATED
orCLOUDWATCH_METRIC
, omitIPAddress
.- IPv4 address : four values between 0 and 255, separated by periods (.), for example,
- measure_
latency bool Specify whether you want Amazon Route 53 to measure the latency between health checkers in multiple AWS regions and your endpoint, and to display CloudWatch latency graphs on the Health Checks page in the Route 53 console.
You can't change the value of
MeasureLatency
after you create a health check.- port int
The port on the endpoint that you want Amazon Route 53 to perform health checks on.
Don't specify a value for
Port
when you specify a value for Type ofCLOUDWATCH_METRIC
orCALCULATED
.- regions Sequence[str]
A complex type that contains one
Region
element for each region from which you want Amazon Route 53 health checkers to check the specified endpoint.If you don't specify any regions, Route 53 health checkers automatically performs checks from all of the regions that are listed under Valid Values .
If you update a health check to remove a region that has been performing health checks, Route 53 will briefly continue to perform checks from that region to ensure that some health checkers are always checking the endpoint (for example, if you replace three regions with four different regions).
- request_
interval int The number of seconds between the time that Amazon Route 53 gets a response from your endpoint and the time that it sends the next health check request. Each Route 53 health checker makes requests at this interval.
You can't change the value of
RequestInterval
after you create a health check.If you don't specify a value for
RequestInterval
, the default value is30
seconds.- resource_
path str - The path, if any, that you want Amazon Route 53 to request when performing health checks. The path can be any value for which your endpoint will return an HTTP status code of 2xx or 3xx when the endpoint is healthy, for example, the file /docs/route53-health-check.html. You can also include query string parameters, for example,
/welcome.html?language=jp&login=y
. - routing_
control_ strarn The Amazon Resource Name (ARN) for the Route 53 Application Recovery Controller routing control.
For more information about Route 53 Application Recovery Controller, see Route 53 Application Recovery Controller Developer Guide. .
- search_
string str If the value of Type is
HTTP_STR_MATCH
orHTTPS_STR_MATCH
, the string that you want Amazon Route 53 to search for in the response body from the specified resource. If the string appears in the response body, Route 53 considers the resource healthy.Route 53 considers case when searching for
SearchString
in the response body.
- type "CALCULATED" | "CLOUDWATCH_METRIC" | "HTTP" | "HTTP_STR_MATCH" | "HTTPS" | "HTTPS_STR_MATCH" | "TCP" | "RECOVERY_CONTROL"
The type of health check that you want to create, which indicates how Amazon Route 53 determines whether an endpoint is healthy.
You can't change the value of
Type
after you create a health check.You can create the following types of health checks:
- HTTP : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTP request and waits for an HTTP status code of 200 or greater and less than 400.
- HTTPS : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTPS request and waits for an HTTP status code of 200 or greater and less than 400.
If you specify
HTTPS
for the value ofType
, the endpoint must support TLS v1.0 or later.- HTTP_STR_MATCH : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an HTTP request and searches the first 5,120 bytes of the response body for the string that you specify in
SearchString
. - HTTPS_STR_MATCH : Route 53 tries to establish a TCP connection. If successful, Route 53 submits an
HTTPS
request and searches the first 5,120 bytes of the response body for the string that you specify inSearchString
. - TCP : Route 53 tries to establish a TCP connection.
- CLOUDWATCH_METRIC : The health check is associated with a CloudWatch alarm. If the state of the alarm is
OK
, the health check is considered healthy. If the state isALARM
, the health check is considered unhealthy. If CloudWatch doesn't have sufficient data to determine whether the state isOK
orALARM
, the health check status depends on the setting forInsufficientDataHealthStatus
:Healthy
,Unhealthy
, orLastKnownStatus
.
Route 53 supports CloudWatch alarms with the following features:
- Standard-resolution metrics. High-resolution metrics aren't supported. For more information, see High-Resolution Metrics in the Amazon CloudWatch User Guide .
- Statistics: Average, Minimum, Maximum, Sum, and SampleCount. Extended statistics aren't supported.
- CALCULATED : For health checks that monitor the status of other health checks, Route 53 adds up the number of health checks that Route 53 health checkers consider to be healthy and compares that number with the value of
HealthThreshold
. - RECOVERY_CONTROL : The health check is assocated with a Route53 Application Recovery Controller routing control. If the routing control state is
ON
, the health check is considered healthy. If the state isOFF
, the health check is considered unhealthy.
For more information, see How Route 53 Determines Whether an Endpoint Is Healthy in the Amazon Route 53 Developer Guide .
- alarm
Identifier Property Map - A complex type that identifies the CloudWatch alarm that you want Amazon Route 53 health checkers to use to determine whether the specified health check is healthy.
- child
Health List<String>Checks - (CALCULATED Health Checks Only) A complex type that contains one
ChildHealthCheck
element for each health check that you want to associate with aCALCULATED
health check. - enable
Sni Boolean Specify whether you want Amazon Route 53 to send the value of
FullyQualifiedDomainName
to the endpoint in theclient_hello
message during TLS negotiation. This allows the endpoint to respond toHTTPS
health check requests with the applicable SSL/TLS certificate.Some endpoints require that
HTTPS
requests include the host name in theclient_hello
message. If you don't enable SNI, the status of the health check will beSSL alert handshake_failure
. A health check can also have that status for other reasons. If SNI is enabled and you're still getting the error, check the SSL/TLS configuration on your endpoint and confirm that your certificate is valid.The SSL/TLS certificate on your endpoint includes a domain name in the
Common Name
field and possibly several more in theSubject Alternative Names
field. One of the domain names in the certificate should match the value that you specify forFullyQualifiedDomainName
. If the endpoint responds to theclient_hello
message with a certificate that does not include the domain name that you specified inFullyQualifiedDomainName
, a health checker will retry the handshake. In the second attempt, the health checker will omitFullyQualifiedDomainName
from theclient_hello
message.- failure
Threshold Number The number of consecutive health checks that an endpoint must pass or fail for Amazon Route 53 to change the current status of the endpoint from unhealthy to healthy or vice versa. For more information, see How Amazon Route 53 Determines Whether an Endpoint Is Healthy in the Amazon Route 53 Developer Guide .
If you don't specify a value for
FailureThreshold
, the default value is three health checks.- fully
Qualified StringDomain Name Amazon Route 53 behavior depends on whether you specify a value for
IPAddress
.If you specify a value for
IPAddress
:Amazon Route 53 sends health check requests to the specified IPv4 or IPv6 address and passes the value of
FullyQualifiedDomainName
in theHost
header for all health checks except TCP health checks. This is typically the fully qualified DNS name of the endpoint on which you want Route 53 to perform health checks.When Route 53 checks the health of an endpoint, here is how it constructs the
Host
header:- If you specify a value of
80
forPort
andHTTP
orHTTP_STR_MATCH
forType
, Route 53 passes the value ofFullyQualifiedDomainName
to the endpoint in the Host header. - If you specify a value of
443
forPort
andHTTPS
orHTTPS_STR_MATCH
forType
, Route 53 passes the value ofFullyQualifiedDomainName
to the endpoint in theHost
header. - If you specify another value for
Port
and any value exceptTCP
forType
, Route 53 passesFullyQualifiedDomainName:Port
to the endpoint in theHost
header.
If you don't specify a value for
FullyQualifiedDomainName
, Route 53 substitutes the value ofIPAddress
in theHost
header in each of the preceding cases.If you don't specify a value for
IPAddress
:Route 53 sends a DNS request to the domain that you specify for
FullyQualifiedDomainName
at the interval that you specify forRequestInterval
. Using an IPv4 address that DNS returns, Route 53 then checks the health of the endpoint.If you don't specify a value for
IPAddress
, Route 53 uses only IPv4 to send health checks to the endpoint. If there's no record with a type of A for the name that you specify forFullyQualifiedDomainName
, the health check fails with a "DNS resolution failed" error.If you want to check the health of multiple records that have the same name and type, such as multiple weighted records, and if you choose to specify the endpoint only by
FullyQualifiedDomainName
, we recommend that you create a separate health check for each endpoint. For example, create a health check for each HTTP server that is serving content for www.example.com. For the value ofFullyQualifiedDomainName
, specify the domain name of the server (such as us-east-2-www.example.com), not the name of the records (www.example.com).In this configuration, if you create a health check for which the value of
FullyQualifiedDomainName
matches the name of the records and you then associate the health check with those records, health check results will be unpredictable.In addition, if the value that you specify for
Type
isHTTP
,HTTPS
,HTTP_STR_MATCH
, orHTTPS_STR_MATCH
, Route 53 passes the value ofFullyQualifiedDomainName
in theHost
header, as it does when you specify a value forIPAddress
. If the value ofType
isTCP
, Route 53 doesn't pass aHost
header.- If you specify a value of
- health
Threshold Number The number of child health checks that are associated with a
CALCULATED
health check that Amazon Route 53 must consider healthy for theCALCULATED
health check to be considered healthy. To specify the child health checks that you want to associate with aCALCULATED
health check, use the ChildHealthChecks element.Note the following:
- If you specify a number greater than the number of child health checks, Route 53 always considers this health check to be unhealthy.
- If you specify
0
, Route 53 always considers this health check to be healthy.
- insufficient
Data "Healthy" | "LastHealth Status Known Status" | "Unhealthy" - When CloudWatch has insufficient data about the metric to determine the alarm state, the status that you want Amazon Route 53 to assign to the health check:
Healthy
: Route 53 considers the health check to be healthy.Unhealthy
: Route 53 considers the health check to be unhealthy.LastKnownStatus
: Route 53 uses the status of the health check from the last time that CloudWatch had sufficient data to determine the alarm state. For new health checks that have no last known status, the default status for the health check is healthy.
- inverted Boolean
- Specify whether you want Amazon Route 53 to invert the status of a health check, for example, to consider a health check unhealthy when it otherwise would be considered healthy.
- ip
Address String The IPv4 or IPv6 IP address of the endpoint that you want Amazon Route 53 to perform health checks on. If you don't specify a value for
IPAddress
, Route 53 sends a DNS request to resolve the domain name that you specify inFullyQualifiedDomainName
at the interval that you specify inRequestInterval
. Using an IP address returned by DNS, Route 53 then checks the health of the endpoint.Use one of the following formats for the value of
IPAddress
:- IPv4 address : four values between 0 and 255, separated by periods (.), for example,
192.0.2.44
. - IPv6 address : eight groups of four hexadecimal values, separated by colons (:), for example,
2001:0db8:85a3:0000:0000:abcd:0001:2345
. You can also shorten IPv6 addresses as described in RFC 5952, for example,2001:db8:85a3::abcd:1:2345
.
If the endpoint is an EC2 instance, we recommend that you create an Elastic IP address, associate it with your EC2 instance, and specify the Elastic IP address for
IPAddress
. This ensures that the IP address of your instance will never change.For more information, see FullyQualifiedDomainName .
Constraints: Route 53 can't check the health of endpoints for which the IP address is in local, private, non-routable, or multicast ranges. For more information about IP addresses for which you can't create health checks, see the following documents:
- RFC 5735, Special Use IPv4 Addresses
- RFC 6598, IANA-Reserved IPv4 Prefix for Shared Address Space
- RFC 5156, Special-Use IPv6 Addresses
When the value of
Type
isCALCULATED
orCLOUDWATCH_METRIC
, omitIPAddress
.- IPv4 address : four values between 0 and 255, separated by periods (.), for example,
- measure
Latency Boolean Specify whether you want Amazon Route 53 to measure the latency between health checkers in multiple AWS regions and your endpoint, and to display CloudWatch latency graphs on the Health Checks page in the Route 53 console.
You can't change the value of
MeasureLatency
after you create a health check.- port Number
The port on the endpoint that you want Amazon Route 53 to perform health checks on.
Don't specify a value for
Port
when you specify a value for Type ofCLOUDWATCH_METRIC
orCALCULATED
.- regions List<String>
A complex type that contains one
Region
element for each region from which you want Amazon Route 53 health checkers to check the specified endpoint.If you don't specify any regions, Route 53 health checkers automatically performs checks from all of the regions that are listed under Valid Values .
If you update a health check to remove a region that has been performing health checks, Route 53 will briefly continue to perform checks from that region to ensure that some health checkers are always checking the endpoint (for example, if you replace three regions with four different regions).
- request
Interval Number The number of seconds between the time that Amazon Route 53 gets a response from your endpoint and the time that it sends the next health check request. Each Route 53 health checker makes requests at this interval.
You can't change the value of
RequestInterval
after you create a health check.If you don't specify a value for
RequestInterval
, the default value is30
seconds.- resource
Path String - The path, if any, that you want Amazon Route 53 to request when performing health checks. The path can be any value for which your endpoint will return an HTTP status code of 2xx or 3xx when the endpoint is healthy, for example, the file /docs/route53-health-check.html. You can also include query string parameters, for example,
/welcome.html?language=jp&login=y
. - routing
Control StringArn The Amazon Resource Name (ARN) for the Route 53 Application Recovery Controller routing control.
For more information about Route 53 Application Recovery Controller, see Route 53 Application Recovery Controller Developer Guide. .
- search
String String If the value of Type is
HTTP_STR_MATCH
orHTTPS_STR_MATCH
, the string that you want Amazon Route 53 to search for in the response body from the specified resource. If the string appears in the response body, Route 53 considers the resource healthy.Route 53 considers case when searching for
SearchString
in the response body.
HealthCheckConfigPropertiesInsufficientDataHealthStatus
HealthCheckConfigPropertiesType
HealthCheckTag
Package Details
- Repository
- AWS Native pulumi/pulumi-aws-native
- License
- Apache-2.0
We recommend new projects start with resources from the AWS provider.