ibgib

ibgib

I’m currently in the process of deploying ibgib, and I just finished configuring my DNS :eyes: :checkered_flag:.

Now I’m trying to set up https redirection so that (http://)www.ibgib.com will automatically redirect to https://www.ibgib.com. What is the “proper” way to implement this?

I know of the force_ssl option in the endpoint configuration, which I’ve tried turning on (with hsts: true), however this does not seem to do the redirect. But this could be that I do not have my docker setup properly configured. Is setting this supposed to do the redirect? Or am I supposed to accomplish this another way, perhaps with nginx? And if nginx is the way to go, could I then completely remove the http config setting from my endpoint config? :thinking:

Additional Background

I’m currently using distillery to produce a release and then docker (engine, compose, machine) with a “simple” setup of my release container + a postgres container deployed to aws ec2. My full-ish (foolish? :confused:) ongoing deployment notes can be found in my deploy issue for anyone else looking to go elixir + docker + aws.

Showing Posts 1 to 10

josevalim

josevalim

Creator of Elixir

FWIW, in my experience Plug.SSL, which is what Phoenix uses behind the scenes for force_ssl: [hsts: true], works fine.

ibgib

ibgib OP

Thanks @josevalim. I think that may be the sanity check that I’m looking for, as reading the docs it seems obvious what it should do…but I’m just not seeing it happening! :see_no_evil:

It is probably a docker configuration issue that I just haven’t been able to pin down yet. :pushpin:

ibgib

ibgib OP

Well, I couldn’t get the force_ssl to work as expected. :slight_frown: I would hazard a guess that it may be because of the rewrite not working with the docker-machine vm and/or aws configuration. :grey_question:

I was however able to get it (mostly) working with a very basic, customized https + www redirect nginx container. I forked this from an https-only redirect container, and customized it for also forcing www as well. :smile: :cookie:

I say “mostly” because both ibgib.com and www.ibgib.com redirect as expected to https://www.ibgib.com. Also if you type in https://www.ibgib.com directly it will work as well (*). However, if you type in https://ibgib.com, explicitly stating the https and giving a naked URL, it doesn’t properly redirect to the www version, but at this point I’m fine with that, as I’ll have to reconfigure this stuff anyway in a later release. :sweat_smile:

I just wanted to post my results for anyone else going the distillery + docker (engine, compose, machine) route.

Thanks again! :smile:

(*) This may seem like a given to devops/deployment gurus, but I found plenty of (mis)configurations where this doesn’t work :wink:.

logicmason

logicmason

It’s not working for me either. I’ve tried both what was in the phoenix guides and force_ssl: [hsts: true] and read the docs for Plug.SSL without seeing any clear reason it’s not working.

If I type in 应用宝官网-全网最新最热手机应用游戏下载, it loads with https. If I type 应用宝官网-全网最新最热手机应用游戏下载, it loads without. What I want is for the https route to load, even if the user doesn’t type https into the location bar of their browser.

I’m not using a proxy. It’s just a normal install of phoenix.

Here’s my prod.exs config:

config :myapp, Myapp.Endpoint,
  server: true,
  url: [scheme: "https", host: "myapp.com", port: 443],
  http: [compress: true, port: 80],
  https: [compress: true, port: 443,
  force_ssl: [hsts: true],
    otp_app: :myapp,
    keyfile: "/etc/letsencrypt/live/myapp.com/privkey.pem",
    certfile: "/etc/letsencrypt/live/myapp.com/cert.pem"],
  cache_static_manifest: "priv/static/manifest.json"
chensan

chensan

I’m offloading the SSL termination to HAProxy, you can do the redirect easy in haproxy.cfg:

frontend http-in-website
  bind 0.0.0.0:80
  redirect scheme https code 301 if !{ ssl_fc }

frontend https-in-website
  bind 0.0.0.0:443 ssl crt /etc/haproxy/ssl
  default_backend servers-website

backend servers-website
  server w1 127.0.0.1:4200 check maxconn 4000

Your server just listen on 127.0.0.1:4200, no need to care about the force_ssl.

You still need the http config, check http://www.phoenixframework.org/docs/serving-your-application-behind-a-proxy.

ibgib

ibgib OP

Yes, FWIW this is what I ended up doing as well with ibGib using nginx. I ended up terminating the SSL at the proxy, redirect 301, etc.

pshoukry

pshoukry

Did anyone ever find a solution for this, I am still seeing the same problem on docker, AWS, distillery.

Ankhers

Ankhers

I am currently using force_ssl: [rewrite_on: [:x_forwarded_proto]] for my application running on AWS (ECS specifically) and it is working fine.

pshoukry

pshoukry

force_ssl: [hsts: true, host: nil]

Solved it for me.

Nagasaki45

Nagasaki45

Thanks @pshoukry! It solved the problem for me (EC2, no proxy, just iptables routing).

Where Next? Top

Trending in Questions Top

katta
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
achenet
Hello, I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind. However, when I launch mix phx.server, I get an error...
New
bradley
I really like the adapter patterns that ecto, nebulex, waffle, etc. use and would love find something similar for a key management servic...
New
unaware8150
Hello folks! So at work, we are seeing some situations where we have to define some “fixed” strings that are used across the codebase in...
New
Cxx-mlr
I’m working on a small exercise involving update_in/3, and I came up with this solution: data = %{ name: "Periodic Table", category:...
New
Alvinkariuki
How Can I Optimise Compile Time Dependencies I have been building an elixir application for about 2 years now. Many modules and files ha...
New
dillonoconnor
Is there any way to avoid the Hologram compiler running when using iex? It seems like the front-end code could potentially be disregarded...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New
KristerV
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
mudasobwa
I fully migrated to my own harness from Anthropic/Gemini and I think it’s time to share it. Welcome DSH, the DeepSeek Harness, fully writ...
New
mcass19
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews