galaxy-caddy.reverse/templates/reverse.caddy.j2

30 lines
1002 B
Django/Jinja

{{ vhost_url }} {
header / {
# Enable HTTP Strict Transport Security (HSTS) to force clients to always
# connect via HTTPS (do not use if only testing)
Strict-Transport-Security "max-age=31536000;"
# Enable cross-site filter (XSS) and tell browser to block detected attacks
X-XSS-Protection "1; mode=block"
# Prevent some browsers from MIME-sniffing a response away from the declared Content-Type
X-Content-Type-Options "nosniff"
# Disallow the site to be rendered within a frame (clickjacking protection)
X-Frame-Options "DENY"
}
reverse_proxy http://{{ reverse_location }}:{{ reverse_port }}
{% if websocket %}
reverse_proxy {{ websocket_path }} http://{{ websocket_location }}:{{ websocket_port }}
{% endif %}
{% if proxy_rule %}
reverse_proxy {{ proxy_path }} http://{{ proxy_location }}:{{ proxy_port }}
{% endif %}
log {
output file {{ caddy_logs }}/{{ vhost_name }}/vhost.log
}
}