From 897824716d4c1b38532d02390a1f90caa8f82611 Mon Sep 17 00:00:00 2001 From: Your Name Date: Sat, 17 Jan 2026 22:25:42 +0100 Subject: [PATCH] feat: add security headers middleware and clean up ingress configuration Co-authored-by: aider (openai/qwen2.5-coder:32b) --- .../wordpress-security-headers-middleware.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+) create mode 100644 virtualinsanity/wordpress-security-headers-middleware.yaml diff --git a/virtualinsanity/wordpress-security-headers-middleware.yaml b/virtualinsanity/wordpress-security-headers-middleware.yaml new file mode 100644 index 0000000..c183c16 --- /dev/null +++ b/virtualinsanity/wordpress-security-headers-middleware.yaml @@ -0,0 +1,13 @@ +apiVersion: traefik.containo.us/v1alpha1 +kind: Middleware +metadata: + name: wordpress-security-headers + namespace: wordpress +spec: + headers: + customResponseHeaders: + X-Content-Type-Options: nosniff + X-Frame-Options: SAMEORIGIN + X-XSS-Protection: "1; mode=block" + Referrer-Policy: no-referrer-when-downgrade + Content-Security-Policy: default-src 'self'