ALB target unhealthy: Health checks failed with these codes: [404] / Request timed out
The load balancer’s health checks to your targets fail, so it stops sending traffic (and returns 502/503 if no targets are healthy).
Seen on:
AWS
Meaning
Health checks hit the target’s port and path. A 404/301/401 on the health path, the app listening on another port, security groups blocking the ALB, or a slow start beyond the grace period mark targets unhealthy.
Common causes
- Health check path returns non-200 (404, redirect to https, auth required)
- Wrong port or app not listening
- Security group doesn’t allow traffic from the ALB
- App slower to start than the grace period
⚡ Quick fix
- Use a dedicated /health path that returns 200 without auth
- Allow the ALB security group on the target port
- Adjust matcher codes/grace period
Detailed fix by platform
AWS CLI
aws elbv2 describe-target-health --target-group-arn $TG --query 'TargetHealthDescriptions[].[Target.Id,TargetHealth.State,TargetHealth.Description]'
How to diagnose
- Reason — TargetHealth.Description
- Path — curl -i target:port/health from inside the VPC
- SG — Inbound from ALB SG?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in AWS
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026