diff --git a/apps/templates/nextcloud-helm.yaml b/apps/templates/nextcloud-helm.yaml index aa73889..97c4003 100644 --- a/apps/templates/nextcloud-helm.yaml +++ b/apps/templates/nextcloud-helm.yaml @@ -43,9 +43,39 @@ spec: 'trusted_proxies' => ['10.0.0.0/8', '192.168.1.1/32'], ); nginx: + ## You need to set an fpm version of the image for nextcloud if you want to use nginx! + enabled: true + + image: + repository: nginx + tag: alpine + pullPolicy: IfNotPresent + + containerPort: 80 + # This configures nginx to listen on either IPv4, IPv6 or both + ipFamilies: + - IPv4 + # - IPv6 config: - headers: - Strict-Transport-Security: "max-age=15768001; includeSubDomains;" + # This generates the default nginx config as per the nextcloud documentation + default: true + headers: + # -- HSTS settings + # WARNING: Only add the preload option once you read about + # the consequences in https://hstspreload.org/. This option + # will add the domain to a hardcoded list that is shipped + # in all major browsers and getting removed from this list + # could take several months. + # Example: + # "Strict-Transport-Security": "max-age=15768000; includeSubDomains; preload;" + "Strict-Transport-Security": "max-age=15768000; includeSubDomains;" + "Referrer-Policy": "no-referrer" + "X-Content-Type-Options": "nosniff" + "X-Download-Options": "noopen" + "X-Frame-Options": "SAMEORIGIN" + "X-Permitted-Cross-Domain-Policies": "none" + "X-Robots-Tag": "noindex, nofollow" + "X-XSS-Protection": "1; mode=block" phpClientHttpsFix: enabled: true protocol: https