2026-05-14 03:12:22 +00:00
|
|
|
http:
|
|
|
|
|
middlewares:
|
|
|
|
|
crowdsec-bouncer:
|
2026-05-15 17:40:23 +00:00
|
|
|
enabled: true
|
|
|
|
|
crowdsecMode: stream
|
|
|
|
|
crowdsecLapiKey: '{{ env "CROWDSEC_BOUNCER_API_KEY" }}'
|
|
|
|
|
crowdsecLapiHost: "crowdsec:8080"
|
|
|
|
|
crowdsecLapiScheme: "http"
|
|
|
|
|
crowdsecAppsecEnabled: true
|
|
|
|
|
crowdsecAppsecHost: "crowdsec:7422"
|
|
|
|
|
crowdsecAppsecFailureBlock: true
|
|
|
|
|
crowdsecAppsecUnreachableBlock: true
|
2026-05-14 03:21:52 +00:00
|
|
|
|
|
|
|
|
security-headers:
|
|
|
|
|
headers:
|
|
|
|
|
stsSeconds: 31536000
|
|
|
|
|
stsIncludeSubdomains: true
|
|
|
|
|
stsPreload: true
|
|
|
|
|
forceSTSHeader: true
|
|
|
|
|
contentTypeNosniff: true
|
|
|
|
|
browserXssFilter: true
|
|
|
|
|
referrerPolicy: "strict-origin-when-cross-origin"
|
|
|
|
|
permissionsPolicy: "camera=(), microphone=(), geolocation=()"
|
2026-05-14 17:24:19 +00:00
|
|
|
customFrameOptionsValue: "SAMEORIGIN"
|
|
|
|
|
|
|
|
|
|
rate-limit:
|
|
|
|
|
rateLimit:
|
|
|
|
|
average: 100 # requests per second sustained
|
|
|
|
|
burst: 50 # allowed spike above average
|
|
|
|
|
period: 1s
|