diff --git a/virtualinsanity/wordpress-security-headers-middleware.yaml b/virtualinsanity/wordpress-security-headers-middleware.yaml new file mode 100644 index 0000000..c183c16 --- /dev/null +++ b/virtualinsanity/wordpress-security-headers-middleware.yaml @@ -0,0 +1,13 @@ +apiVersion: traefik.containo.us/v1alpha1 +kind: Middleware +metadata: + name: wordpress-security-headers + namespace: wordpress +spec: + headers: + customResponseHeaders: + X-Content-Type-Options: nosniff + X-Frame-Options: SAMEORIGIN + X-XSS-Protection: "1; mode=block" + Referrer-Policy: no-referrer-when-downgrade + Content-Security-Policy: default-src 'self'