HSTS for Server-Sent Events: A Production Fix

A lot of teams treat Server-Sent Events like “just another endpoint.” That’s how you end up with a perfectly secure app shell over HTTPS and a quietly fragile event stream still hanging onto old HTTP assumptions. I’ve seen this play out in production: the page loads fine, login works, API calls are on HTTPS, HSTS is enabled on the main site, and yet live updates randomly fail, especially after deploys, browser restarts, or when users hit older bookmarked URLs. The culprit was SSE over an incomplete HTTPS setup. ...

September 6, 2026 · 7 min · headertest.com

HSTS for Envoy Proxy: Options, Pros, and Cons

If you run Envoy at the edge, HSTS is one of those headers you should set deliberately instead of “getting around to it later”. It is simple on paper: tell browsers to always use HTTPS for your site. In practice, the question is where to inject it in an Envoy-based stack, and that choice affects operability, consistency, and the blast radius of mistakes. For Envoy, there are a few common approaches: ...

July 19, 2026 · 7 min · headertest.com

HSTS for Railway Deployments: Pros, Cons, and Setup

HSTS on Railway sounds simple: add a header, force HTTPS, done. In practice, the right place to set it depends on how you deploy, whether you use Railway’s edge, and how much control you actually have over redirects and custom domains. If you run production apps on Railway, HSTS is usually worth enabling. But it’s one of those headers that can absolutely hurt you if you switch it on carelessly, especially with preload or a long max-age before your subdomains are ready. ...

May 20, 2026 · 7 min · headertest.com