All Products
Search
Document Center

Server Load Balancer:Implement hybrid disaster recovery with an ALB multi-cluster gateway

Last Updated:Sep 14, 2026

If your workloads run in an on-premises data center or a third-party public cloud Kubernetes cluster, you can use ACK One multi-cluster gateways to build a hybrid or cross-cloud disaster recovery system with automatic smooth failover. This topic explains how to quickly build a same-city active-active hybrid disaster recovery system with ACK One.

Architecture

Three core components: a Fleet instance (with optional GitOps), a cloud ACK cluster, and a registered cluster connected to your on-premises environment.

image

How the components connect:

  1. All Alibaba Cloud resources share a single VPC. An ACK cluster runs in availability zone (AZ) 1; a registered cluster sits in AZ 2.

  2. Your on-premises cluster (or third-party platform cluster) connects to the registered cluster via a leased line between the data center and the VPC.

  3. Both clusters are associated with the Fleet instance. ACK One GitOps distributes the application to both.

  4. On the Fleet instance, an AlbConfig creates an ALB multi-cluster gateway. A Fleet-level Ingress defines routing rules for north-south traffic and zone-disaster recovery.

Prerequisites

Before you begin:

  • A Fleet instance, ACK cluster, and registered cluster in the same VPC but different availability zones

  • Non-overlapping node and pod CIDR blocks between the ACK cluster and the on-premises Kubernetes cluster (Network design for Fleet management)

  • A leased line connecting your on-premises data center to the VPC

  • The on-premises cluster's container network type (underlay or overlay) is determined — this affects the required Service type

Network type Required Service type When to use
Underlay ClusterIP Pod IPs are directly routable from the on-premises network
Overlay NodePort Pod IPs are not routable; traffic must enter through node ports

Design the network and create clusters

  1. Create a Fleet instance, an ACK cluster, and a registered cluster in the same VPC but different availability zones.

  2. Verify that node and pod CIDR blocks do not overlap between the ACK cluster and the on-premises Kubernetes cluster.

Connect to Alibaba Cloud

  1. Connect the on-premises Kubernetes cluster to the registered cluster (Create a registered cluster).

    To migrate workloads to Alibaba Cloud with elastic resources: Build a hybrid cloud cluster and add ECS instances to the cluster and Schedule pods to elastic container instances that are deployed as virtual nodes. To improve availability against traffic spikes: Create ECIs across zones.
  2. Connect the on-premises network to the VPC. See Network connectivity and Overview of hybrid networks.

  3. Associate the registered cluster and ACK cluster with the Fleet instance (Manage associated clusters).

Distribute the application to multiple clusters

These ApplicationSet examples use the web-demo app. Create a multi-cluster application covers advanced options.

Underlay network

All clusters use ClusterIP Services. Apply the following ApplicationSet:

apiVersion: argoproj.io/v1alpha1
kind: ApplicationSet
metadata:
  name: appset-web-demo-undelay
  namespace: argocd
spec:
  template:
    metadata:
      name: '{{.metadata.annotations.cluster_id}}-web-demo'
      namespace: argocd
    spec:
      destination:
        name: '{{.name}}'
        namespace: gateway-demo
      project: default
      source:
        repoURL: https://github.com/AliyunContainerService/gitops-demo.git
        path: manifests/helm/web-demo
        targetRevision: main
        helm:
          valueFiles:
            - values.yaml
          parameters:
            - name: envCluster
              value: '{{.metadata.annotations.cluster_name}}'
      syncPolicy:
        automated: {}
        syncOptions:
          - CreateNamespace=true
  generators:
    - clusters:
        selector:
          matchExpressions:
            - values:
                - cluster
              key: argocd.argoproj.io/secret-type
              operator: In
            - values:
                - in-cluster
              key: name
              operator: NotIn
  goTemplateOptions:
    - missingkey=error
  syncPolicy:
    preserveResourcesOnDeletion: false
  goTemplate: true

Overlay network

The on-premises cluster uses NodePort Services; the ACK cluster uses ClusterIP Services. Label each cluster before applying the ApplicationSet.

  1. In Argo CD, go to Settings > Clusters and add these labels:

    • On-premises cluster: cluster: idc

    • ACK cluster: cluster: ack

  2. Apply the following ApplicationSet:

apiVersion: argoproj.io/v1alpha1
kind: ApplicationSet
metadata:
  name: appset-web-demo-overlay
  namespace: argocd
spec:
  template:
    metadata:
      name: '{{.metadata.annotations.cluster_id}}-web-demo-overlay'
      namespace: argocd
    spec:
      destination:
        name: '{{.name}}'
        namespace: gateway-demo
      project: default
      source:
        repoURL: https://github.com/AliyunContainerService/gitops-demo.git
        path: manifests/helm/web-demo
        targetRevision: main
        helm:
          valueFiles:
            - values.yaml
          parameters:
            - name: isNodePort
              value: "{{.values.isNodePort}}"
            - name: envCluster
              value: '{{.metadata.annotations.cluster_name}}'
      syncPolicy:
        automated: {}
        syncOptions:
          - CreateNamespace=true
  generators:
    - clusters:
        selector:
          matchLabels:
            cluster: 'idc'
        # A key-value map for arbitrary parameters
        values:
          isNodePort: "true"
    - clusters:
        selector:
          matchLabels:
            cluster: 'ack'
        values:
          isNodePort: "false"
  goTemplateOptions:
    - missingkey=error
  syncPolicy:
    preserveResourcesOnDeletion: false
  goTemplate: true

Configure the ALB multi-cluster gateway

After deploying the application to both clusters:

  1. On the Fleet instance, create an AlbConfig to provision the ALB multi-cluster gateway and add both clusters to it.

  2. Create routing rules and Ingresses on the Fleet instance for active zone-redundancy.

Build a zone-disaster recovery system covers the full configuration walkthrough.

Next steps