Skip to content

Commit

Permalink
(docker) making security settings of traefik on par with nginx
Browse files Browse the repository at this point in the history
  • Loading branch information
rigelk committed Jun 4, 2018
1 parent 049539e commit 1dd5983
Showing 1 changed file with 23 additions and 0 deletions.
23 changes: 23 additions & 0 deletions support/docker/production/config/traefik.toml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,29 @@ defaultEntryPoints = ["http", "https"]
[entryPoints.https]
address = ":443"
[entryPoints.https.tls]
MinVersion = "VersionTLS12"
CurvePreferences = [
"CurveP521",
"CurveP384",
"CurveP256"
]
PreferServerCipherSuites = true
CipherSuites = [
"TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305",
"TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305",
"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384",
"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256",
"TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA",
"TLS_RSA_WITH_AES_256_GCM_SHA384",
"TLS_RSA_WITH_AES_256_CBC_SHA"
]
FrameDeny = false # here we don't want to deny frames since we have an embed
STSIncludeSubdomains = true
STSSeconds = 315360000
STSPreload = true
ContentTypeNosniff = true
BrowserXssFilter = true


# Enable ACME (Let's Encrypt): automatic SSL.
[acme]
Expand Down

0 comments on commit 1dd5983

Please sign in to comment.