From 506a0cabd20dbdad7201420374254a1f61713ef8 Mon Sep 17 00:00:00 2001 From: Benoit Date: Tue, 11 Feb 2025 15:27:53 +0900 Subject: [PATCH] Add vaultwarden --- 03frontends.cfg | 2 ++ 05backends.cfg | 10 ++++++++++ 2 files changed, 12 insertions(+) diff --git a/03frontends.cfg b/03frontends.cfg index 58e457b..124e2c7 100644 --- a/03frontends.cfg +++ b/03frontends.cfg @@ -309,6 +309,7 @@ frontend frontend_default acl laminar hdr(host) -i laminar.benoit.jp.net acl linkding hdr(host) -i linkding.benoit.jp.net acl mastodon hdr(host) -i mastodon.benoit.jp.net + acl vaultwarden hdr(host) -i vaultwarden.benoit.jp.net http-request deny if adguard !JP !SG !letsencrypt @@ -319,5 +320,6 @@ frontend frontend_default use_backend letsencrypt if letsencrypt use_backend linkding if linkding use_backend mastodon if mastodon + use_backend vaultwarden if vaultwarden default_backend default diff --git a/05backends.cfg b/05backends.cfg index 5a82a2b..73ec5ad 100644 --- a/05backends.cfg +++ b/05backends.cfg @@ -64,3 +64,13 @@ backend adguard http-response set-header Referrer-Policy "strict-origin-when-cross-origin" http-response set-header Cross-Origin-Resource-Policy "same-origin" server adguard adguard.incus:3000 check + +backend vaultwarden + # set HSTS for one year after all responses + http-response set-header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" + # add some Security headers + http-response set-header X-Frame-Options "SAMEORIGIN" + http-response set-header X-Content-Type-Options "nosniff" + http-response set-header Referrer-Policy "strict-origin-when-cross-origin" + http-response set-header Cross-Origin-Resource-Policy "same-origin" + server vaultwarden vaultwarden.incus:80 check