HAProxy hdr_dom(host)配置:子域名app.drawmessage.com意外HTTPS重定向问题
Hey there! Let's break down why your app.drawmessage.com subdomain is getting forced into HTTPS when it shouldn't be, even though your main drawmessage.com redirect rules are supposed to exclude it. Below are the most common culprits and actionable fixes:
1. Check for Global/Default HTTPS Redirect Rules
A super common issue is a broad global or frontend-level redirect rule that applies to all domains, including your subdomain. For example, if you have something like this in your config:
redirect scheme https if !{ ssl_fc }
This will force every non-HTTPS request to redirect, regardless of the subdomain. To fix this, add an ACL to exclude app.drawmessage.com:
# Define the subdomain exception first acl is_app_subdomain hdr(host) -i app.drawmessage.com # Only redirect to HTTPS if it's NOT the app subdomain redirect scheme https if !{ ssl_fc } !is_app_subdomain
2. Verify Your Main Domain ACL Precision
If your special redirect for drawmessage.com uses a too-broad ACL, it might accidentally match subdomains. For example, using hdr(host) -m sub drawmessage.com will match all subdomains (including app.), not just the root domain. Instead, use a precise match for the root domain:
# Match ONLY the root drawmessage.com domain, not subdomains acl is_main_root_domain hdr(host) -i drawmessage.com # Apply your special redirect only to the root domain redirect location /your-special-path if is_main_root_domain { your-condition }
3. Fix Rule Execution Order
HAProxy processes rules top-to-bottom—if your subdomain exception is placed after the HTTPS redirect rule, it won't trigger. Make sure you handle the subdomain first, before any redirect rules for the main domain:
frontend http_frontend bind *:80 # First: Route the app subdomain without redirects acl is_app_subdomain hdr(host) -i app.drawmessage.com use_backend app_backend if is_app_subdomain # Then: Handle main domain www redirect acl is_www_main hdr(host) -i www.drawmessage.com redirect location http://drawmessage.com%[capture.req.uri] if is_www_main # Finally: Apply main domain HTTPS and special redirects acl is_main_domain hdr(host) -i drawmessage.com redirect scheme https if is_main_domain !{ ssl_fc } redirect location /your-special-path if is_main_domain { your-condition }
4. Eliminate Cross-Config Interference
Since you have multiple HAProxy configs, double-check that no other frontend or backend block is matching app.drawmessage.com accidentally. For example, a wildcard domain rule like hdr(host) -m reg ^.*\.drawmessage.com$ would catch your app subdomain and apply unintended redirects. Ensure all ACLs are targeted to their specific domains.
5. Test and Validate
- First, validate your config syntax to avoid errors:
haproxy -c -f /etc/haproxy/haproxy.cfg - Then test with
curlto confirm the redirect behavior is fixed:
You should see acurl -I http://app.drawmessage.com200 OKresponse (or a redirect to the correct non-HTTPS backend) instead of a301/302to HTTPS.
内容的提问来源于stack exchange,提问作者Király István

