HTTP Strict Transport Security tells supporting browsers to use HTTPS for future requests to a host. A parent policy that includes subdomains extends that behavior beyond the application being released. The operator must inventory active and delegated hostnames, certificates, redirects, and legacy endpoints before broadening scope. Start with a short lifetime on the intended host, verify HTTPS paths and certificate renewal, then lengthen it in stages. Preload is a separate, harder-to-reverse commitment; it requires domain-wide readiness and an explicit owner. An HSTS header delivered only over an insecure response is not an effective setup path.
HSTS rollout: inventory every hostname before extending transport policy
Operational decision
A site has the public portal, an editorial CMS host, and a legacy upload host. The portal is already HTTPS-only, but the upload host still answers on HTTP for an old client. The team must migrate that client and test the upload host before sending includeSubDomains from the parent domain. It first applies a short host-only lifetime, checks browser upgrade behavior and certificate renewal, then considers a longer lifetime. The release record lists each hostname and its TLS owner. A rollback of application code cannot instantly erase HSTS state held by browsers, so the transport decision uses a longer planning window than a template deployment.
Transport rollout ledger
Hosts: portal, editorial CMS, upload endpoint
Each host: HTTPS response, valid certificate, redirect, renewal owner
Phase 1: short host-only lifetime
Phase 2: longer lifetime after client checks
Parent includeSubDomains: only after every child host passes
Preload: separately reviewed domain-wide decisionCost and verification
Inventorying H hostnames costs O(H) checks per validation pass, with extra work for delegated zones and third-party endpoints. Longer lifetimes reduce downgrade exposure but also lengthen recovery from a mistaken policy in browsers that have already cached it. Certificate and DNS monitoring should continue after rollout; a browser enforcing HSTS cannot fall back to HTTP during an outage. Measure failed handshakes by hostname and client cohort, not just the main site's successful responses.
Common Mistakes
- Do not apply includeSubDomains without a domain inventory.
- Do not treat an application rollback as an HSTS cache rollback.
- Do not pursue preload before verifying every affected hostname.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- DNS cutovers: budget for resolver caches and mixed destinations
- Certificate renewal: verify the served certificate after issuance
- TLS chain delivery: test the clients that actually connect
