Patrol handles two pieces of site infrastructure that should be explicit and dependable: maintenance access and canonical HTTPS routing. Put the public site offline deliberately, or keep requests on the correct secure domain.
Send public visitors to a project-owned offline page or response while approved users continue to work. Access rules can account for signed-in users, IP addresses, and the routes that must remain reachable.
Force HTTPS, choose the primary domain, limit where secure routing applies, and set the redirect status that fits the deployment. The rules remain application-aware rather than depending on one web-server configuration.
Available for Craft 4 and 5. Get it from the plugin store.