diff --git a/ansible/roles/haproxy-config/templates/haproxy_single_service_listen.cfg.j2 b/ansible/roles/haproxy-config/templates/haproxy_single_service_listen.cfg.j2
index d8a3dccfccd7c27bad922564bc40fc75ff0c932a..b1b133dadf7b9e545d7261d07bd66ef7193c9009 100644
--- a/ansible/roles/haproxy-config/templates/haproxy_single_service_listen.cfg.j2
+++ b/ansible/roles/haproxy-config/templates/haproxy_single_service_listen.cfg.j2
@@ -46,7 +46,7 @@ listen {{ service_name }}
         {% if service_mode == 'http' %}
             {% set tls_option = internal_tls_bind_info %}
     {# Replace the XFP header for internal https requests #}
-        http-request set-header X-Forwarded-Proto https if { ssl_fc }
+    http-request set-header X-Forwarded-Proto https if { ssl_fc }
         {% endif %}
     {% endif %}
     {{ "bind %s:%s %s"|e|format(vip_address, service_port, tls_option)|trim() }}