Files
kube-wordpress/virtualinsanity/wordpress-security-headers-middleware.yaml
Your Name bcd1f4b9b2 feat: add security headers middleware
Co-authored-by: aider (openai/qwen2.5-coder:32b) <aider@aider.chat>
2026-01-17 22:39:01 +01:00

27 lines
832 B
YAML

apiVersion: traefik.containo.us/v1alpha1
kind: Middleware
metadata:
name: wordpress-security-headers
namespace: wordpress
spec:
headers:
customResponseHeaders:
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: "1; mode=block"
Referrer-Policy: no-referrer-when-downgrade
Content-Security-Policy: default-src 'self'
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
name: wordpress-security-headers
namespace: wordpress
spec:
headers:
customResponseHeaders:
X-Frame-Options: "SAMEORIGIN"
X-XSS-Protection: "1; mode=block"
X-Content-Type-Options: "nosniff"
Referrer-Policy: "no-referrer-when-downgrade"
Content-Security-Policy: "default-src 'self'; script-src 'self' https://*.google-analytics.com; object-src 'none'"