already handle this with a `HSTS` header and at cloudflare, but why not: https://github.com/bendrucker/hapi-require-https