HSTS Mistakes in Quarkus and How to Fix Them
HTTP Strict Transport Security looks simple: send one header, browsers stop using HTTP, done. That’s the theory. In real Quarkus apps, HSTS usually goes wrong in boring, expensive ways: wrong environment, wrong proxy setup, bad preload assumptions, or turning it on before the whole domain is actually HTTPS-ready. If you’re building Java services with Quarkus, these are the mistakes I see most often and how to fix them without breaking production. ...