traefik: harden websecure defaults (crowdsec, headers, tls12)
This commit is contained in:
12
dynamic.d/middlewares/secure-headers.yml
Normal file
12
dynamic.d/middlewares/secure-headers.yml
Normal file
@@ -0,0 +1,12 @@
|
||||
http:
|
||||
middlewares:
|
||||
secure-headers:
|
||||
headers:
|
||||
contentTypeNosniff: true
|
||||
frameDeny: true
|
||||
referrerPolicy: "strict-origin-when-cross-origin"
|
||||
# Intentionally no HSTS (per requirement).
|
||||
customResponseHeaders:
|
||||
server: ""
|
||||
x-powered-by: ""
|
||||
|
||||
Reference in New Issue
Block a user