Health checks failed ☁️ AWS

ALB target unhealthy: Health checks failed with these codes: [404] / Request timed out

The load balancer’s health checks to your targets fail, so it stops sending traffic (and returns 502/503 if no targets are healthy).

Seen on: AWS

Meaning

Health checks hit the target’s port and path. A 404/301/401 on the health path, the app listening on another port, security groups blocking the ALB, or a slow start beyond the grace period mark targets unhealthy.

Common causes

  • Health check path returns non-200 (404, redirect to https, auth required)
  • Wrong port or app not listening
  • Security group doesn’t allow traffic from the ALB
  • App slower to start than the grace period

⚡ Quick fix

  1. Use a dedicated /health path that returns 200 without auth
  2. Allow the ALB security group on the target port
  3. Adjust matcher codes/grace period

Detailed fix by platform

AWS CLI

  1. aws elbv2 describe-target-health --target-group-arn $TG --query 'TargetHealthDescriptions[].[Target.Id,TargetHealth.State,TargetHealth.Description]'

How to diagnose

  1. Reason — TargetHealth.Description
  2. Path — curl -i target:port/health from inside the VPC
  3. SG — Inbound from ALB SG?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.