Application Load Balancer has no healthy targets

Severity
High
Service
Application Load Balancer
Check ID
ALB_NO_HEALTHY_TARGETS

What this check finds

An ALB with no healthy registered targets is incurring the base ALB charge (~$0.0225/ALB-hour, ~$16.50/month) while unable to serve traffic. All requests will return a 503. This typically indicates a misconfigured target group or abandoned load balancer.

Passing looks like: ALB has healthy targets.

How to fix it

Investigate why targets are unhealthy: check the target group health check path, security group rules allowing traffic from the ALB, and whether the target instances/IPs are running. If the ALB is no longer needed, delete it and the associated target groups.

AWS console

EC2 → Load Balancers → select ALB → Target groups tab → select target group → Targets tab.

Compliance

This is an operational hygiene check. It flags something worth tidying rather than a control an auditor asks for, so it is not mapped to a compliance framework.

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only