Add HSTS headers to all web services

This commit is contained in:
polyfloyd 2024-06-11 20:00:40 +02:00
parent 5ae55c6c5b
commit 8a8216d78e
6 changed files with 11 additions and 7 deletions

View file

@ -31,7 +31,7 @@ all:
mqtt.bitlair.nl:
monitoring:
hosts:
monitoring.bitlair.nl:
dashboard.bitlair.nl:
music:
hosts:
music.bitlair.nl:

View file

@ -12,6 +12,10 @@ server {
ssl_certificate_key "/var/lib/dehydrated/certs/{{ etherpad_domain }}/privkey.pem";
{% endif %}
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";
add_header X-Frame-Options DENY;
add_header X-Content-Type-Options nosniff;
location / {
proxy_pass http://127.0.0.1:9001/;
include proxy_params;

View file

@ -13,6 +13,9 @@ server {
ssl_certificate_key "/var/lib/dehydrated/certs/{{ git_server_domain }}/privkey.pem";
{% endif %}
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";
add_header X-Frame-Options DENY;
add_header X-Content-Type-Options nosniff;
add_header X-Robots-Tag noindex;
location / {

View file

@ -58,11 +58,6 @@ versions_to_keep = 20
enabled = true
path = /var/lib/grafana/dashboards
# Alerting
[alerting]
enabled = true
execute_alerts = True
# SMTP and email config
# Logging

View file

@ -10,6 +10,9 @@ server {
ssl_certificate_key "/var/lib/dehydrated/certs/{{ monitoring_domain }}/privkey.pem";
{% endif %}
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";
add_header X-Frame-Options DENY;
add_header X-Content-Type-Options nosniff;
add_header X-Robots-Tag noindex;
location / {

View file

@ -16,7 +16,6 @@ server {
ssl_certificate_key "/var/lib/dehydrated/certs/{{ www_domain }}/privkey.pem";
{% endif %}
# SSL settings from https://cipherli.st/ - AK47 15 jan 2017
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";
add_header X-Frame-Options DENY;
add_header X-Content-Type-Options nosniff;