Skip to content

Instantly share code, notes, and snippets.

@jeffersonsouza
Created January 15, 2022 14:15
Show Gist options
  • Save jeffersonsouza/7c08c6b487bd61a56407879dcfd028b7 to your computer and use it in GitHub Desktop.
Save jeffersonsouza/7c08c6b487bd61a56407879dcfd028b7 to your computer and use it in GitHub Desktop.
HaProxy Security Headers configs
frontend 443
# Security Headers
http-response del-header server
http-response del-header link # wordpress specific
http-response del-header x-powered-by
http-response set-header Strict-Transport-Security "max-age=15768000; includeSubDomains; preload;"
http-response set-header X-Frame-Options "SAMEORIGIN"
http-response set-header X-XSS-Protection "1; mode=block"
http-response set-header X-Content-Type-Options "nosniff"
http-response set-header Referrer-Policy no-referrer-when-downgrade
http-response set-header X-Hosting "https://sre.yoursite.com";
http-response set-header X-Ninja "SRE Team";
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment