What you get
Take a server out without taking the site down.
Pools
Targets with health checks
Group machines by service. A TCP or HTTP check every few seconds takes a failing target out and brings it back.
Routing
By hostname and path
app.example.com to one pool, /api/ to another. Rules are evaluated most specific first.
HTTPS
Certificates handled
A Let's Encrypt certificate per hostname, requested as soon as DNS points to the load balancer, renewed automatically.
Maintenance
Drain a target
No new connections to it, current ones finish. Update the machine, then put it back.
Visibility
Statistics and usage
Requests by response code, traffic and sessions over 1 hour to 7 days, plus the cost of the current month.
Managed
Nothing to operate
FFxF runs, patches and monitors the load balancer. You only describe where traffic goes.
In practice
A pool, an HTTPS listener, two rules.
Create the load balancer in a private network, add your machines to a pool, open an HTTPS listener and point your DNS at it. The console, the API and the MCP server work the same way.
curl -s -X PUT https://api.ffxf.net/v1/load-balancers/1/pools/1/targets \
-H "Authorization: Bearer $FFXF_TOKEN" \
-H "Content-Type: application/json" \
-d '{"targets": [{"vm": 4821, "port": 3000}, {"vm": 4822, "port": 3000}]}'
curl -s -X POST https://api.ffxf.net/v1/load-balancers/1/listeners \
-H "Authorization: Bearer $FFXF_TOKEN" \
-H "Content-Type: application/json" \
-d '{"port": 443, "protocol": "https", "default_pool": 1, "redirect_https": true}'
Limits
What to know before you start.
| Item | Rule |
|---|---|
| Load balancers per account | 3, more on request from the console |
| Per load balancer | 10 pools, 25 targets per pool, 5 listeners, 25 rules per listener |
| HTTPS hostnames | 15 per load balancer, one certificate each |
| Open ports | 80, 443 and your listeners, each restrictable to allowed sources |
| Traffic | Counted on the target machines, within their included bandwidth |
| Price | 0.010 CAD an hour (about 7.30 CAD a month) |
FFxF · Montréal
Put your servers behind one address.
Create a load balancer in your private network, then add your machines and an HTTPS listener.


