You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

HTTP转HTTPS重定向失效,如何强制所有通信走HTTPS?

Got it, let's figure out why your HTTP requests aren't redirecting to HTTPS and fix this step by step. The issue is almost certainly tied to how your Application Load Balancer (ALB) is handling HTTP traffic, or how your Nginx server is interpreting request context from the ALB.

方案1: 直接在ALB层配置HTTP→HTTPS重定向(推荐)

This is the most efficient approach because the redirect happens at the load balancer level—no need to send HTTP traffic all the way to your EC2 instances, saving resources and reducing latency.

Here's how to set it up:

  • Log into the AWS Console, navigate to your ALB's Listeners configuration page
  • Find the listener for port 80, click "Edit listener"
  • Change the default action from "Forward to target group" to "Redirect"
  • Configure the redirect settings:
    • Target protocol: HTTPS
    • Target port: 443
    • Status code: Pick 301 Moved Permanently (best for SEO and permanent redirects) or 302 Found if you need a temporary redirect
  • Save the configuration

Once this is done, all HTTP requests will be redirected to HTTPS directly by the ALB—they won't even reach your Nginx server, which completely solves the problem.

方案2: 在Nginx中处理重定向(当需要ALB转发HTTP流量到后端时)

If you have a specific reason to have the ALB forward HTTP traffic to your EC2 instances (like custom logic you need to run on HTTP requests), you'll need to adjust your Nginx config. The key here is that the ALB passes the original request's protocol via the X-Forwarded-Proto header, but Nginx only sees the protocol used between the ALB and itself (usually HTTP, if your target group uses HTTP).

Update your Nginx HTTP server block (listening on port 80) with this rule:

server {
    listen 80;
    server_name your-domain-name.com;

    # Check the original request protocol from the ALB
    if ($http_x_forwarded_proto = 'http') {
        return 301 https://$host$request_uri;
    }

    # If you don't need any other HTTP logic, you can also just return a 444 here
    # return 444;
}

If your ALB target group forwards traffic to Nginx's 443 port instead, add the same X-Forwarded-Proto check to your HTTPS server block:

server {
    listen 443 ssl;
    server_name your-domain-name.com;

    # ... existing SSL config ...

    if ($http_x_forwarded_proto = 'http') {
        return 301 https://$host$request_uri;
    }

    # ... rest of your config ...
}

Also, make sure your Nginx server is actually listening on the port your ALB target group is forwarding to (80 or 443).

Quick Troubleshooting Checks
  • Double-check your ALB's port 80 listener: If it's set to forward to your target group instead of redirecting, that's probably why HTTP requests aren't being redirected
  • Use your browser's DevTools to inspect the HTTP request response: If you get a 200 OK, the traffic is reaching Nginx but the redirect rule isn't triggering. Check Nginx's access logs to see if the X-Forwarded-Proto header is present
  • Confirm your target group is pointing to the correct port on your EC2 instances (and that Nginx is listening on that port)

内容的提问来源于stack exchange,提问作者Roni Baby

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 06:42:49