Two distribution levels
Traffic dial controls the portion of traffic already directed to a Regional endpoint group, not a global percentage of every listener. If 600 connections would reach the group, a 25% dial nominally represents 150. Within the group, weights 40 and 120 divide that portion one to three. These calculations help discuss gradual release but do not guarantee exact request, byte or load counts. Documentation allows weight exceptions to preserve availability, including collisions with preserved IP. State denominator, window and measured signal in reporting. Do not compare connection percentage with consumption percentage without considering different operation durations and costs. Validate the actual application effect alongside routing configuration.
Draining and affinity
Changing the dial affects new connections and does not terminate existing ones. A long TCP session can remain on the previous version after the dashboard shows zero dial. Define draining criteria using time, active sessions and in-flight work, plus a rollback decision deadline. Source IP affinity also does not replicate application state. It uses addresses to guide selection, and edge changes with a different preferred Region can break affinity. A service storing state only in local memory needs a recovery strategy for that transition. Test new and persistent connections separately; success in one does not establish behavior in the other or guarantee that a previous write was acknowledged.
Failover is not an access rule
When a group has no healthy positive-weight endpoints, the service seeks alternatives. During this mechanism it can ignore traffic dial and consider a zero-dial Region. If it finds no eligible healthy endpoint among the attempted groups, fail-open behavior can select an endpoint in the closest group. Therefore, neither zero dial nor a failed health check proves isolation. An unapproved release needs explicit controls preventing access, including during Regional failure. Document eligible destinations and perform negative tests with the security owner. In committee reporting, separate traffic reduction, operational unavailability and authorized blocking; these are different outcomes and should not share one green status marker.
Health and ports are separate contracts
For ALB/NLB endpoints, configure health checks in Elastic Load Balancing; GA probe parameters apply to EC2 and Elastic IP. An ALB needs at least one healthy target in every target group for its documented health condition. For EC2 with a UDP listener, confirm the TCP server and port required by probes. A 443-to-8443 override changes user traffic, not the health-check port. Validate both listeners and permissions. An override endpoint port cannot overlap accelerator listener ranges or be reused by another override from a different port. Put these dependencies into the pipeline and functional window checklist before changing real traffic, with evidence from both the probe and application paths.
Preserved IP and competing paths
Preserving IP has endpoint-specific requirements. Elastic IP endpoints do not support it; NLBs have additional conditions, including security groups and TLS-listener restrictions. Confirm compatibility before designing rules around client addresses. When preservation is active, allowlists must account for actual authorized sources. A private endpoint can receive GA traffic with an IGW attached to the VPC without requiring a public IP or subnet IGW route. This distinction avoids exposing an unnecessary direct path. If one resource receives direct and accelerator traffic, connection collisions can occur. Distinct final ports are a documented mitigation for certain scenarios, but must be configured and tested throughout the path rather than changed only in one console field.
Lifecycle and partner commitments
AWS-assigned static IPs remain while the accelerator exists, even when disabled. Disabling stops acceptance and routing, but deletion loses those addresses. Recreating with the same name is not rollback preserving partner allowlists. Before the window, identify external owners, change lead times and a recovery alternative that actually restores access. Management calls use us-west-2 although the service routes to endpoints in other Regions; do not confuse management plane with data location. Acceptance should combine configuration, observed distribution, drained sessions, functional health and partner access. Also record the condition for stopping the change when these proofs cannot be gathered within reserved time and who is authorized to execute the recovery plan.
def nominal_share(candidate_connections, dial, weights):
assert 0 <= dial <= 100 and all(w >= 0 for w in weights)
assert sum(weights) > 0
regional = candidate_connections * dial / 100
return [regional * w / sum(weights) for w in weights]
assert nominal_share(600, 25, [40, 120]) == [37.5, 112.5]
assert nominal_share(600, 100, [40, 120]) == [150, 450]
assert nominal_share(600, 0, [40, 120]) == [0, 0]
assert nominal_share(100, 100, [1, 3]) == [25, 75]
assert nominal_share(100, 100, [0, 3]) == [0, 100]
print("five nominal-share checks passed; failover and sessions are not modeled")
600 Region-candidate connections × 25% dial = 150 nominal; weights 40/120 represent 37.5/112.5 in expectation, not guaranteed counts or draining of old sessions.
Common pitfalls
Using zero dial as isolation; assuming overrides apply to health checks; recreating the accelerator as guaranteed-IP rollback.
Related topics: Health checks and failover · Capacity and continuity
A distribution change needs session, access and recovery evidence beyond configuration values.
Reference: Traffic dials · ANS-C01