Enforcing HTTPS Redirection in Traefik with RedirectScheme Middleware
Learn how to enforce HTTPS redirection in Traefik using the RedirectScheme middleware, with a complete Docker Compose example and production considerations.
21 Oct 2025, 21:43 UTC

The problem: plain HTTP slipping through
When you expose services behind Traefik, clients often hit the HTTP entry point first. Unless the application itself forces TLS, the request travels unencrypted. Adding a redirect in every container is tedious and error‑prone.
Thesis: let Traefik do the heavy lifting
Traefik’s RedirectScheme middleware can be attached to a router (or globally) and will automatically return a 301/302 response that points the client to the same host and path over HTTPS. The middleware runs before any other middleware that might rewrite the URI, so the redirect always reflects the original request.
Configuration steps
- Define an HTTP entry point (usually port 80) and an HTTPS entry point (port 443) in Traefik’s static configuration.
- Create a middleware resource of type
redirectschemewithscheme: httpsandpermanent: truefor a 301 redirect. - Attach the middleware to the desired router(s) via labels (Docker provider) or dynamic configuration.
- Configure a TLS certificate resolver (e.g., Let’s Encrypt) so the HTTPS entry point can serve a valid certificate.
Worked Docker Compose example
The following compose file spins up Traefik and a simple whoami service. The whoami router gets the redirect-scheme middleware, and Traefik obtains a Let’s Encrypt certificate using the TLS‑ALPN challenge.
version: '3.8'
services:
traefik:
image: traefik:v3.0
command:
- "--api.insecure=true"
- "--providers.docker=true"
- "--entrypoints.web.address=:80"
- "--entrypoints.websecure.address=:443"
- "--certificatesresolvers.le.acme.tlschallenge=true"
- "--certificatesresolvers.le.acme.email=[contact removed]"
- "--certificatesresolvers.le.acme.storage=/letsencrypt/acme.json"
ports:
- "80:80"
- "443:443"
volumes:
- "/var/run/docker.sock:/var/run/docker.sock:ro"
- "letsencrypt:/letsencrypt"
networks:
- proxy
whoami:
image: traefik/whoami
labels:
- "traefik.enable=true"
- "traefik.http.routers.whoami.rule=Host(`whoami.example.com`)"
- "traefik.http.routers.whoami.entrypoints=web"
- "traefik.http.routers.whoami.middlewares=redirect-scheme@docker"
- "traefik.http.middlewares.redirect-scheme.redirectscheme.scheme=https"
- "traefik.http.middlewares.redirect-scheme.redirectscheme.permanent=true"
- "traefik.http.routers.whoami-secure.rule=Host(`whoami.example.com`)"
- "traefik.http.routers.whoami-secure.entrypoints=websecure"
- "traefik.http.routers.whoami-secure.tls.certresolver=le"
networks:
- proxy
networks:
proxy:
external: true
volumes:
letsencrypt:
Run the stack on a host that has Docker and Docker Compose installed (requires root or membership in the docker group):
docker compose up -d
Verification
- From a client machine, request the HTTP endpoint:
Expect acurl -I http://whoami.example.com/301 Moved Permanently(or302ifpermanent:false) with aLocation: https://whoami.example.com/header. - Check Traefik logs for middleware execution and certificate acquisition:
docker compose logs traefik | grep -E 'redirectscheme|acme' - Confirm the HTTPS endpoint works:
Should returncurl -I https://whoami.example.com/200 OKand present a certificate issued by Let’s Encrypt (or your test CA).
Trade‑offs and limitations
- Extra hop: Every HTTP request incurs a redirect round‑trip before the client reaches the service over TLS.
- Redirect loops: If another middleware rewrites the host or path before
RedirectScheme, the redirect may point to an unexpected URL, causing a loop. PlaceRedirectSchemefirst in the middleware chain. - Let’s Encrypt rate limits: Frequent redeploys that trigger new certificate orders can hit the 50‑certificates‑per‑week limit per domain. Use the staging resolver (
caServer: https://acme-staging-v02.api.letsencrypt.org/directory) for testing, or a self‑signed certificate for local development.
Actionable closing
Add the RedirectScheme middleware to any router that must be HTTPS‑only. Test with curl -I and watch Traefik logs for the first few deployments. Once verified, you can safely remove any application‑level HTTP‑to‑HTTPS logic, reducing code duplication and ensuring consistent enforcement across all services.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.