---
name: azion-redirect-http-to-https
description: >-
  Redirect every request made over plain HTTP to HTTPS with one Request Phase rule, on a workload that has HTTPS turned on.
---

# Redirect HTTP to HTTPS

You redirect every request made over plain HTTP to HTTPS with a rule on the application, from Azion Console, the API, or the Azion CLI. For the certificate that HTTPS on your own domain needs, refer to [Request a Let's Encrypt certificate](/en/documentation/guides/application-security/tls-and-certificates/how-to-generate-a-lets-encrypt-certificate/).

The *Redirect HTTP to HTTPS* behavior redirects a request made over HTTP to HTTPS, and does nothing to a request already made over HTTPS. The rule therefore matches every path, with no condition on the scheme. The behavior requires HTTPS turned on in the protocol settings of the workload that delivers the application.

```mermaid
%%{init: {"layout": "dagre", "themeVariables": {"fontSize": "13px"}, "flowchart": {"nodeSpacing": 12, "rankSpacing": 12, "padding": 6, "wrappingWidth": 70, "minNodeWidth": 40, "useMaxWidth": true}}}%%
flowchart TD
  Req["A request reaches the application"] --> Rule["The rule matches every path"]
  Rule --> Scheme{"Was the request made over HTTP?"}
  Scheme -->|"yes"| Redirect["The client is redirected to HTTPS"]
  Scheme -->|"no"| Continue["The request continues unchanged"]
```

1. Every request matches the rule, because its criterion is `${uri}` *starts with* `/`.
2. A request made over HTTP is redirected to HTTPS.
3. A request made over HTTPS continues to the rules that follow, unchanged.

---

## Prerequisites

- An application served by a workload. To create them, refer to [Applications quickstart](/en/documentation/platform/applications/quickstart/).
- **HTTPS support** turned on in the workload's **Protocol Settings**, with a certificate that covers the workload's domains. To have Azion request and renew one, refer to [Request a Let's Encrypt certificate](/en/documentation/guides/application-security/tls-and-certificates/how-to-generate-a-lets-encrypt-certificate/). For the HTTPS ports and the TLS fields, refer to [Workload settings](/en/documentation/platform/workloads/settings/#tls).
- A [personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/), for the API procedures.
- The [Azion CLI](/en/documentation/devtools/cli/) installed and authorized, for the CLI procedures.

The examples create the rule on the application `<application-id>`, served on `www.example.com`. Replace them with your values.

---

## Create the redirect rule

The rule needs no Product on the application: `${uri}` reads the path without Application Accelerator, and the behavior takes no argument.

**Console**

To create the rule in Azion Console:

1. **Go to the Rules Engine tab**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**, then go to the **Rules Engine** tab.

2. **Select + Rule**

3. **Name the rule**

   Enter a name that identifies the redirect. For example: `redirect to HTTPS`.

4. **Select Request Phase**

5. **Match every path**

   In the **Criteria** section, set the criterion to `${uri}` *starts with* `/`.

6. **In the Behaviors section, select Redirect HTTP to HTTPS**

7. **Select Save**

The rule appears in the **Request** list of the **Rules Engine** tab.

**API**

The criteria carry `${uri}`, which a shell expands, so the body is sent from a file. To create the rule:

1. **Write the rule to a file**

   Save the following as `rule.json`:

   ```json
   {
     "name": "redirect to HTTPS",
     "active": true,
     "criteria": [[{ "variable": "${uri}", "conditional": "if", "operator": "starts_with", "argument": "/" }]],
     "behaviors": [{ "type": "redirect_http_to_https" }]
   }
   ```

2. **Send the create request**

   ```bash
   curl --request POST \
     --url https://api.azion.com/v4/workspace/applications/<application-id>/request_rules \
     --header 'Accept: application/json' \
     --header 'Authorization: Token <personal-token>' \
     --header 'Content-Type: application/json' \
     --data @rule.json
   ```

The API answers `202` with `"state": "pending"` and the rule as it was stored, with its `id` and its `order` in the phase.

**CLI**

The CLI reads the rule from a JSON file. To create the rule:

1. **Write the rule to a file**

   Save the following as `rule.json`:

   ```json
   {
     "name": "redirect to HTTPS",
     "active": true,
     "criteria": [[{ "variable": "${uri}", "conditional": "if", "operator": "starts_with", "argument": "/" }]],
     "behaviors": [{ "type": "redirect_http_to_https" }]
   }
   ```

2. **Create the rule**

   ```bash
   azion create rules-engine --application-id <application-id> --phase request --file rule.json
   ```

   The command prints the ID of the rule:

   ```text
   Created Rules Engine with ID <rule-id>
   ```

Every request made over HTTP is redirected to HTTPS, and every HTTPS request continues unchanged. A new rule takes a few minutes to reach every data center.

> **Caution**
>
> When the origin redirects HTTPS requests back to HTTP, the two redirects form a loop that ends in a `500` error. Set the connector's **Transport Protocol Policy** to *Force HTTP*, so Azion reaches the origin over HTTP, or remove the redirect. For the fixes, refer to [HTTP status codes](/en/documentation/fundamentals/http-status-codes/#500-internal-server-error).

---

## Place the redirect before rules that end the processing

The platform creates a new rule at the end of its phase. A rule before it whose behavior ends the processing, such as *Deliver*, *Deny (403 Forbidden)*, or *Finish Request Phase*, stops the rules after it, so the requests that rule matches are never redirected. When the list holds such a rule, move the redirect rule ahead of it.

**Console**

To move the rule in Azion Console:

1. **Go to the Rules Engine tab**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**, then go to the **Rules Engine** tab.

2. **Move the rule**

   In the **Request** list, move `redirect to HTTPS` above every rule that ends the processing.

**API**

To set the order, send the rule IDs of the phase in their new order, the redirect rule first, in the `order` array:

```bash
curl --request PUT \
  --url https://api.azion.com/v4/workspace/applications/<application-id>/request_rules/order \
  --header 'Accept: application/json' \
  --header 'Authorization: Token <personal-token>' \
  --header 'Content-Type: application/json' \
  --data '{ "order": [<redirect-rule-id>, <other-rule-id>] }'
```

The list names every rule of the phase, and each rule's `order` field then holds its new position, starting at `0`.

**CLI**

To set the order, pass every rule ID of the phase, the redirect rule first:

```bash
azion update rules-engine-order --application-id <application-id> --phase request --rule-ids "<redirect-rule-id>,<other-rule-id>"
```

The command confirms the new order:

```text
Ordered Rules Engine of Application with ID <application-id>
```

The redirect rule runs before any rule that ends the processing, so every request made over HTTP reaches it. To see which rules ran on a request, turn on [Debug Rules](/en/documentation/platform/applications/main-settings/#debug-rules).

---

## Next steps

- [Rules Engine for Applications](/en/documentation/platform/applications/rules-engine.md#redirect-http-to-https): The Redirect HTTP to HTTPS behavior and every other behavior a rule can run.
- [Workload settings](/en/documentation/platform/workloads/settings.md#tls): The certificate, the minimum TLS version, and the cipher suite a workload presents.
- [Request a Let's Encrypt certificate](/en/documentation/guides/application-security/tls-and-certificates/how-to-generate-a-lets-encrypt-certificate.md): Get a certificate for the workload's domains that Azion renews for you.
- [Prepare regulated web applications for security audits](/en/documentation/use-cases/secure-applications-and-networks/prepare-regulated-web-applications-for-security-audits.md): Enforce HTTPS as one of the controls an audit asks for.
