mirror of
https://github.com/rubenhensen/k8scd.git
synced 2026-09-18 10:32:55 +02:00
Add HSTS header and discovery config 13
This commit is contained in:
@@ -43,9 +43,39 @@ spec:
|
|||||||
'trusted_proxies' => ['10.0.0.0/8', '192.168.1.1/32'],
|
'trusted_proxies' => ['10.0.0.0/8', '192.168.1.1/32'],
|
||||||
);
|
);
|
||||||
nginx:
|
nginx:
|
||||||
|
## You need to set an fpm version of the image for nextcloud if you want to use nginx!
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: nginx
|
||||||
|
tag: alpine
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
|
||||||
|
containerPort: 80
|
||||||
|
# This configures nginx to listen on either IPv4, IPv6 or both
|
||||||
|
ipFamilies:
|
||||||
|
- IPv4
|
||||||
|
# - IPv6
|
||||||
config:
|
config:
|
||||||
headers:
|
# This generates the default nginx config as per the nextcloud documentation
|
||||||
Strict-Transport-Security: "max-age=15768001; includeSubDomains;"
|
default: true
|
||||||
|
headers:
|
||||||
|
# -- HSTS settings
|
||||||
|
# WARNING: Only add the preload option once you read about
|
||||||
|
# the consequences in https://hstspreload.org/. This option
|
||||||
|
# will add the domain to a hardcoded list that is shipped
|
||||||
|
# in all major browsers and getting removed from this list
|
||||||
|
# could take several months.
|
||||||
|
# Example:
|
||||||
|
# "Strict-Transport-Security": "max-age=15768000; includeSubDomains; preload;"
|
||||||
|
"Strict-Transport-Security": "max-age=15768000; includeSubDomains;"
|
||||||
|
"Referrer-Policy": "no-referrer"
|
||||||
|
"X-Content-Type-Options": "nosniff"
|
||||||
|
"X-Download-Options": "noopen"
|
||||||
|
"X-Frame-Options": "SAMEORIGIN"
|
||||||
|
"X-Permitted-Cross-Domain-Policies": "none"
|
||||||
|
"X-Robots-Tag": "noindex, nofollow"
|
||||||
|
"X-XSS-Protection": "1; mode=block"
|
||||||
phpClientHttpsFix:
|
phpClientHttpsFix:
|
||||||
enabled: true
|
enabled: true
|
||||||
protocol: https
|
protocol: https
|
||||||
|
|||||||
Reference in New Issue
Block a user