The default connection to your web server should be HTTPS, not HTTP. HSTS is an option to set this up properly.
When the domain is registered to use HSTS their browser will use a TLS connection the first time they ever connect to your website.
> You want those redirected to a HSTS enabled HTTPS connection immediately
Websites that depend on advertising probably do as they often want to support very old browsers. Otherwise there's no real need for a redirect/connection upgrade IMO.
If you don't want to add your domain to the preload list, you will have to (automatically) redirect/upgrade users to HTTPS, or bounce them.
[0] - https://hstspreload.org/
which has the following requirements: 1. Serve a valid certificate. 2. Redirect from HTTP to HTTPS on the same host, if you are listening on port 80.
oops.
> if you are listening on port 80
You don’t have to accept trafic on the http port for HSTS preloading. But iff you do you must redirect it.
This rule makes sense; at least you should never serve content over http.
For things like that, that are very easily solvable other way I don't expect Amazon to work on them anytime soon, if ever.
Also if you use API GW/CloudFront they would do that for you too.
It would make sense to do it in the load balancer, you want to do the redirect as soon as possible. So if you want to do it the correct way you get the option of paying for both ALB and CF.