mirror of
https://github.com/rubenhensen/k8scd.git
synced 2026-09-17 02:12:55 +02:00
Add HSTS header and discovery config 16
This commit is contained in:
@@ -42,40 +42,6 @@ spec:
|
|||||||
$CONFIG = array (
|
$CONFIG = array (
|
||||||
'trusted_proxies' => ['10.0.0.0/8', '192.168.1.1/32'],
|
'trusted_proxies' => ['10.0.0.0/8', '192.168.1.1/32'],
|
||||||
);
|
);
|
||||||
# nginx:
|
|
||||||
# ## You need to set an fpm version of the image for nextcloud if you want to use nginx!
|
|
||||||
# enabled: true
|
|
||||||
|
|
||||||
# image:
|
|
||||||
# repository: nginx
|
|
||||||
# tag: alpine
|
|
||||||
# pullPolicy: IfNotPresent
|
|
||||||
|
|
||||||
# containerPort: 80
|
|
||||||
# # This configures nginx to listen on either IPv4, IPv6 or both
|
|
||||||
# ipFamilies:
|
|
||||||
# - IPv4
|
|
||||||
# # - IPv6
|
|
||||||
# config:
|
|
||||||
# # This generates the default nginx config as per the nextcloud documentation
|
|
||||||
# default: true
|
|
||||||
# headers:
|
|
||||||
# # -- HSTS settings
|
|
||||||
# # WARNING: Only add the preload option once you read about
|
|
||||||
# # the consequences in https://hstspreload.org/. This option
|
|
||||||
# # will add the domain to a hardcoded list that is shipped
|
|
||||||
# # in all major browsers and getting removed from this list
|
|
||||||
# # could take several months.
|
|
||||||
# # Example:
|
|
||||||
# # "Strict-Transport-Security": "max-age=15768000; includeSubDomains; preload;"
|
|
||||||
# "Strict-Transport-Security": "max-age=15768000; includeSubDomains;"
|
|
||||||
# "Referrer-Policy": "no-referrer"
|
|
||||||
# "X-Content-Type-Options": "nosniff"
|
|
||||||
# "X-Download-Options": "noopen"
|
|
||||||
# "X-Frame-Options": "SAMEORIGIN"
|
|
||||||
# "X-Permitted-Cross-Domain-Policies": "none"
|
|
||||||
# "X-Robots-Tag": "noindex, nofollow"
|
|
||||||
# "X-XSS-Protection": "1; mode=block"
|
|
||||||
phpClientHttpsFix:
|
phpClientHttpsFix:
|
||||||
enabled: true
|
enabled: true
|
||||||
protocol: https
|
protocol: https
|
||||||
@@ -86,7 +52,7 @@ spec:
|
|||||||
nginx.ingress.kubernetes.io/proxy-body-size: 100G
|
nginx.ingress.kubernetes.io/proxy-body-size: 100G
|
||||||
nginx.ingress.kubernetes.io/configuration-snippet: |
|
nginx.ingress.kubernetes.io/configuration-snippet: |
|
||||||
more_set_headers "Strict-Transport-Security: max-age=15768001; includeSubDomains";
|
more_set_headers "Strict-Transport-Security: max-age=15768001; includeSubDomains";
|
||||||
more_set_headers "strict-transport-security: max-age=15552002; includeSubDomains";
|
more_set_headers "X-Forwarded-Strict-Transport-Security: $upstream_http_strict_transport_security";
|
||||||
# kubernetes.io/tls-acme: "true"
|
# kubernetes.io/tls-acme: "true"
|
||||||
cert-manager.io/cluster-issuer: prod-cluster-issuer
|
cert-manager.io/cluster-issuer: prod-cluster-issuer
|
||||||
# # Keep this in sync with the README.md:
|
# # Keep this in sync with the README.md:
|
||||||
|
|||||||
Reference in New Issue
Block a user