Redirect HTTP to HTTPS
Redirect every request made over plain HTTP to HTTPS with one Request Phase rule, on a workload that has HTTPS turned on.
You redirect every request made over plain HTTP to HTTPS with a rule on the application, from Azion Console, the API, or the Azion CLI. For the certificate that HTTPS on your own domain needs, refer to Request a Let’s Encrypt certificate.
The Redirect HTTP to HTTPS behavior redirects a request made over HTTP to HTTPS, and does nothing to a request already made over HTTPS. The rule therefore matches every path, with no condition on the scheme. The behavior requires HTTPS turned on in the protocol settings of the workload that delivers the application.
- Every request matches the rule, because its criterion is
${uri}starts with/. - A request made over HTTP is redirected to HTTPS.
- A request made over HTTPS continues to the rules that follow, unchanged.
Prerequisites
- An application served by a workload. To create them, refer to Applications quickstart.
- HTTPS support turned on in the workload’s Protocol Settings, with a certificate that covers the workload’s domains. To have Azion request and renew one, refer to Request a Let’s Encrypt certificate. For the HTTPS ports and the TLS fields, refer to Workload settings.
- A personal token, for the API procedures.
- The Azion CLI installed and authorized, for the CLI procedures.
The examples create the rule on the application <application-id>, served on www.example.com. Replace them with your values.
Create the redirect rule
The rule needs no Product on the application: ${uri} reads the path without Application Accelerator, and the behavior takes no argument.
To create the rule in Azion Console:
Access Azion Console > Applications > your application, then go to the Rules Engine tab.
Enter a name that identifies the redirect. For example: redirect to HTTPS.
In the Criteria section, set the criterion to ${uri} starts with /.
The rule appears in the Request list of the Rules Engine tab.
Every request made over HTTP is redirected to HTTPS, and every HTTPS request continues unchanged. A new rule takes a few minutes to reach every data center.
Place the redirect before rules that end the processing
The platform creates a new rule at the end of its phase. A rule before it whose behavior ends the processing, such as Deliver, Deny (403 Forbidden), or Finish Request Phase, stops the rules after it, so the requests that rule matches are never redirected. When the list holds such a rule, move the redirect rule ahead of it.
To move the rule in Azion Console:
Access Azion Console > Applications > your application, then go to the Rules Engine tab.
In the Request list, move redirect to HTTPS above every rule that ends the processing.
The redirect rule runs before any rule that ends the processing, so every request made over HTTP reaches it. To see which rules ran on a request, turn on Debug Rules.