You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

HAProxy hdr_dom(host)配置:子域名app.drawmessage.com意外HTTPS重定向问题

Troubleshooting Unintended HTTPS Redirect for app.drawmessage.com in HAProxy

Hey there! Let's break down why your app.drawmessage.com subdomain is getting forced into HTTPS when it shouldn't be, even though your main drawmessage.com redirect rules are supposed to exclude it. Below are the most common culprits and actionable fixes:

1. Check for Global/Default HTTPS Redirect Rules

A super common issue is a broad global or frontend-level redirect rule that applies to all domains, including your subdomain. For example, if you have something like this in your config:

redirect scheme https if !{ ssl_fc }

This will force every non-HTTPS request to redirect, regardless of the subdomain. To fix this, add an ACL to exclude app.drawmessage.com:

# Define the subdomain exception first
acl is_app_subdomain hdr(host) -i app.drawmessage.com
# Only redirect to HTTPS if it's NOT the app subdomain
redirect scheme https if !{ ssl_fc } !is_app_subdomain

2. Verify Your Main Domain ACL Precision

If your special redirect for drawmessage.com uses a too-broad ACL, it might accidentally match subdomains. For example, using hdr(host) -m sub drawmessage.com will match all subdomains (including app.), not just the root domain. Instead, use a precise match for the root domain:

# Match ONLY the root drawmessage.com domain, not subdomains
acl is_main_root_domain hdr(host) -i drawmessage.com
# Apply your special redirect only to the root domain
redirect location /your-special-path if is_main_root_domain { your-condition }

3. Fix Rule Execution Order

HAProxy processes rules top-to-bottom—if your subdomain exception is placed after the HTTPS redirect rule, it won't trigger. Make sure you handle the subdomain first, before any redirect rules for the main domain:

frontend http_frontend
    bind *:80

    # First: Route the app subdomain without redirects
    acl is_app_subdomain hdr(host) -i app.drawmessage.com
    use_backend app_backend if is_app_subdomain

    # Then: Handle main domain www redirect
    acl is_www_main hdr(host) -i www.drawmessage.com
    redirect location http://drawmessage.com%[capture.req.uri] if is_www_main

    # Finally: Apply main domain HTTPS and special redirects
    acl is_main_domain hdr(host) -i drawmessage.com
    redirect scheme https if is_main_domain !{ ssl_fc }
    redirect location /your-special-path if is_main_domain { your-condition }

4. Eliminate Cross-Config Interference

Since you have multiple HAProxy configs, double-check that no other frontend or backend block is matching app.drawmessage.com accidentally. For example, a wildcard domain rule like hdr(host) -m reg ^.*\.drawmessage.com$ would catch your app subdomain and apply unintended redirects. Ensure all ACLs are targeted to their specific domains.

5. Test and Validate

  • First, validate your config syntax to avoid errors:
    haproxy -c -f /etc/haproxy/haproxy.cfg
    
  • Then test with curl to confirm the redirect behavior is fixed:
    curl -I http://app.drawmessage.com
    
    You should see a 200 OK response (or a redirect to the correct non-HTTPS backend) instead of a 301/302 to HTTPS.

内容的提问来源于stack exchange,提问作者Király István

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 07:45:06