# Load balancing agent connections using TLS

**URL:** <https://discourse.sensu.io/t/load-balancing-agent-connections-using-tls/2384>\
**Category:** Sensu Go\
**Tags:** tls\
**Created:** [January 12, 2021, 9:15pm UTC](https://discourse.sensu.io/t/load-balancing-agent-connections-using-tls/2384 "2021-01-12T21:15:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![aaronsachs](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.sensu.io/aaronsachs/32/47_2.png) [@aaronsachs](https://discourse.sensu.io/u/aaronsachs)\
**Post date:** [January 12, 2021, 9:15pm UTC](https://discourse.sensu.io/t/load-balancing-agent-connections-using-tls/2384/1 "2021-01-12T21:15:10Z")

</div>

Greetings folks,

I’ve been working on load balancing my agent connections via an Nginx load balancer and have been using @jspaleta 's [Jef Practice: Nginx loadbalancer for Sensu Go cluster](https://discourse.sensu.io/t/jef-practice-nginx-loadbalancer-for-sensu-go-cluster/1601), but don’t seem to have much luck getting the connection to work correctly. Here’s what I’m presently using:

```auto
upstream sensu_agent {
   ip_hash;
   server sensu00.sachshaus.net:8081;
   server sensu01.sachshaus.net:8081;
   server sensu02.sachshaus.net:8081;
}

server {
    listen *:8081;

    location / {
        # redirect all HTTP traffic to sensu_agent_ws loadbalancer defined above:
        proxy_pass https://sensu_agent;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

        # WebSocket support (nginx 1.4)
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
    }
}

```

I might be mistakenly thinking that just subbing `https` for `http` in the `proxy_pass` directive would work, but I’m curious if anyone’s got any pointers or anything different that they’re doing, as I’m getting the following:

```auto
Jan 12 21:02:04 logs01.sachshaus.net sensu-agent[126175]: {"component":"agent","error":"tls: first record does not look like a TLS handshake","level":"error","msg":"reconnection attempt failed","time":"2021-01-12T21:02:04Z"}

```

Which leads me to think I’ve not configured Nginx correctly.

---

<div class="post-metadata">

**Author:** ![aaronsachs](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.sensu.io/aaronsachs/32/47_2.png) [@aaronsachs](https://discourse.sensu.io/u/aaronsachs)\
**Post date:** [January 12, 2021, 9:36pm UTC](https://discourse.sensu.io/t/load-balancing-agent-connections-using-tls/2384/2 "2021-01-12T21:36:57Z")

</div>

NVM, definitely a misconfig on my end.

---

<div class="post-metadata">

**Author:** ![calebhailey](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.sensu.io/calebhailey/32/46_2.png) [@calebhailey](https://discourse.sensu.io/u/calebhailey)\
**Post date:** [January 13, 2021, 1:58am UTC](https://discourse.sensu.io/t/load-balancing-agent-connections-using-tls/2384/3 "2021-01-13T01:58:52Z")

</div>

Hi there, @aaronsachs 👋 I hope you’re well!

We have a built-in agent connection load balancing solution coming soon, so let us know how this goes for you and whether a built-in solution would be preferred. 🙂

---

<div class="post-metadata">

**Author:** ![aaronsachs](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.sensu.io/aaronsachs/32/47_2.png) [@aaronsachs](https://discourse.sensu.io/u/aaronsachs)\
**Post date:** [January 21, 2021, 7:59pm UTC](https://discourse.sensu.io/t/load-balancing-agent-connections-using-tls/2384/4 "2021-01-21T19:59:45Z")

</div>

Howdy! Doing well and apparently missed your reply 🤦‍♂️ . Nginx load balancing seems to be working well, since I’m pushing a bunch of other traffic through it. I’m curious about the upcoming feature, though. Are y’all going to randomizing the connection strings from the agent configs, or taking a different approach?

---

<div class="post-metadata">

**Author:** ![calebhailey](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.sensu.io/calebhailey/32/46_2.png) [@calebhailey](https://discourse.sensu.io/u/calebhailey)\
**Post date:** [July 22, 2021, 6:24pm UTC](https://discourse.sensu.io/t/load-balancing-agent-connections-using-tls/2384/5 "2021-07-22T18:24:06Z")

</div>

Sensu Go 6.3.0 was released on May 26th and features new built-in rate limiting.

[https://docs.sensu.io/sensu-go/latest/release-notes/#630-release-notes](https://docs.sensu.io/sensu-go/latest/release-notes/#630-release-notes)

For more information see the [Sensu Backend `--agent-burst-limit` and `--agent-rate-limit` flags](https://docs.sensu.io/sensu-go/6.3/observability-pipeline/observe-schedule/backend/#configuration-via-flags).

I hope this helps!
