It's easy to solve in the application, but then I need to have an http and https endpoint in my application, just for this redirect, already behind the ALB.
I mean, if they can build in authentication redirects on the load balancer, how hard is it then to add a simple http -> https redirect, so this http traffic never has to 'touch' my application.