ibgib
I’m currently in the process of deploying ibgib, and I just finished configuring my DNS
.
Now I’m trying to set up https redirection so that (http://)www.ibgib.com will automatically redirect to https://www.ibgib.com. What is the “proper” way to implement this?
I know of the force_ssl option in the endpoint configuration, which I’ve tried turning on (with hsts: true), however this does not seem to do the redirect. But this could be that I do not have my docker setup properly configured. Is setting this supposed to do the redirect? Or am I supposed to accomplish this another way, perhaps with nginx? And if nginx is the way to go, could I then completely remove the http config setting from my endpoint config? ![]()
Additional Background
I’m currently using distillery to produce a release and then docker (engine, compose, machine) with a “simple” setup of my release container + a postgres container deployed to aws ec2. My full-ish (foolish?
) ongoing deployment notes can be found in my deploy issue for anyone else looking to go elixir + docker + aws.
Trending in Questions
Other Trending Topics
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #deployment
- #library
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #channels
- #elixirconf
- #exunit
- #discussion
- #code-sync
- #javascript
- #podcasts
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixir-ls
- #blog-post
- #phoenix_html
- #iex
- #graphql
- #ai
- #genstage
- #elixirconf-us
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #api
- #forms
- #metaprogramming
- #security
- #hex










First 10 of 26 Posts
josevalim
FWIW, in my experience Plug.SSL, which is what Phoenix uses behind the scenes for
force_ssl: [hsts: true], works fine.ibgib
Thanks @josevalim. I think that may be the sanity check that I’m looking for, as reading the docs it seems obvious what it should do…but I’m just not seeing it happening!
It is probably a docker configuration issue that I just haven’t been able to pin down yet.
ibgib
Well, I couldn’t get the
I would hazard a guess that it may be because of the rewrite not working with the docker-machine vm and/or aws configuration. 
force_sslto work as expected.I was however able to get it (mostly) working with a very basic, customized

https+wwwredirect nginx container. I forked this from anhttps-only redirect container, and customized it for also forcingwwwas well.I say “mostly” because both ibgib.com and www.ibgib.com redirect as expected to
https://www.ibgib.com. Also if you type inhttps://www.ibgib.comdirectly it will work as well (*). However, if you type inhttps://ibgib.com, explicitly stating thehttpsand giving a naked URL, it doesn’t properly redirect to thewwwversion, but at this point I’m fine with that, as I’ll have to reconfigure this stuff anyway in a later release.I just wanted to post my results for anyone else going the distillery + docker (engine, compose, machine) route.
Thanks again!
(*) This may seem like a given to devops/deployment gurus, but I found plenty of (mis)configurations where this doesn’t work
.
logicmason
It’s not working for me either. I’ve tried both what was in the phoenix guides and
force_ssl: [hsts: true]and read the docs for Plug.SSL without seeing any clear reason it’s not working.If I type in 应用宝官网-全网最新最热手机应用游戏下载, it loads with https. If I type 应用宝官网-全网最新最热手机应用游戏下载, it loads without. What I want is for the https route to load, even if the user doesn’t type https into the location bar of their browser.
I’m not using a proxy. It’s just a normal install of phoenix.
Here’s my prod.exs config:
chensan
I’m offloading the SSL termination to HAProxy, you can do the redirect easy in haproxy.cfg:
Your server just listen on
127.0.0.1:4200, no need to care about theforce_ssl.You still need the
httpconfig, check http://www.phoenixframework.org/docs/serving-your-application-behind-a-proxy.ibgib
Yes, FWIW this is what I ended up doing as well with ibGib using nginx. I ended up terminating the SSL at the proxy, redirect 301, etc.
pshoukry
Did anyone ever find a solution for this, I am still seeing the same problem on docker, AWS, distillery.
Ankhers
I am currently using
force_ssl: [rewrite_on: [:x_forwarded_proto]]for my application running on AWS (ECS specifically) and it is working fine.pshoukry
Solved it for me.
Nagasaki45
Thanks @pshoukry! It solved the problem for me (EC2, no proxy, just iptables routing).