As an extension to user2100689’s answer, in Rails 3+ you can use config.force_ssl = true
in config/environments/production.rb
The line can just be uncommented as follows
# Force all access to the app over SSL, use Strict-Transport-Security, and use secure cookies.
config.force_ssl = true