traefik: harden websecure defaults (crowdsec, headers, tls12)

This commit is contained in:
2026-02-07 02:15:13 +08:00
parent 2d7c788202
commit dc2c7f46ae
10 changed files with 90 additions and 1 deletions

View File

@@ -0,0 +1,12 @@
http:
middlewares:
secure-headers:
headers:
contentTypeNosniff: true
frameDeny: true
referrerPolicy: "strict-origin-when-cross-origin"
# Intentionally no HSTS (per requirement).
customResponseHeaders:
server: ""
x-powered-by: ""