Inside my docker-compose.yml I define my Traefik route like so:
labels:
- 'traefik.enable=true'
- 'traefik.docker.network=traefik'
- 'traefik.http.routers.nginx.entrypoints=http'
- 'traefik.http.routers.nginx.rule=Host(`${DOMAIN}`) || Host(`www.${DOMAIN}`)'
- 'traefik.http.routers.nginx.middlewares=redirect@file'
- 'traefik.http.routers.nginx-https.rule=Host(`${DOMAIN}`) || Host(`www.${DOMAIN}`)'
- 'traefik.http.routers.nginx-https.tls=true'
- 'traefik.http.routers.nginx-https.tls.certresolver=${DNS_PROVIDER}'
- 'traefik.http.routers.nginx-https.tls.domains[0].main=${DOMAIN}'
- 'traefik.http.routers.nginx-https.tls.domains[1].main=www.${DOMAIN}'
- 'traefik.http.routers.nginx.service=nginx'
- 'traefik.http.services.nginx.loadbalancer.server.port=80'
- 'traefik.http.services.nginx.loadBalancer.passHostHeader=true'
- 'traefik.http.middlewares.https_redirect.redirectscheme.scheme=https'
- 'traefik.http.middlewares.https-redirect.redirectscheme.scheme=https'
- 'traefik.http.middlewares.https-redirect.headers.customrequestheaders.X-Forwarded-Proto=https'
- 'traefik.http.routers.nginx.middlewares=https-redirect'
- 'traefik.http.middlewares.https_redirect.redirectscheme.permanent=true'
- 'traefik.http.routers.http_catchall.rule=HostRegexp(`{any:.+}`)'
- 'traefik.http.routers.http_catchall.entrypoints=http'
- 'traefik.http.routers.http_catchall.middlewares=https_redirect'
- 'traefik.http.middlewares.https-redirect.headers.customresponseheaders.Set-Cookie=Path=/; HttpOnly; Secure'
- 'traefik.http.middlewares.https-redirect.headers.customresponseheaders.X-Powered-By=PHP'
- 'traefik.http.middlewares.https-redirect.headers.customresponseheaders.HTTPServer=PHP'
I try to set a global traefik.yaml:
tls:
options:
default:
minVersion: VersionTLS12
sniStrict : true
cipherSuites:
- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305
- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305
mintls13:
minVersion: VersionTLS13
http:
middlewares:
all-sites:
redirectScheme:
scheme: https
permanent: true
rateLimit:
average: 100
brust: 50
headers:
frameDeny: true
sslRedirect: true
accessControlAllowMethods:
- GET
- POST
contentTypeNosniff: true
browserXssFilter: true
stsPreload: true
stsIncludeSubdomains: true
sslForceHost: true
sslRedirec: true
I see these get loaded by Traefik in the logs:
"customResponseHeaders\":{\"HTTPServer\":\"PHP\",\"Set-Cookie\":\"Path=/; HttpOnly; Secure\",\"X-Powered-By\":\"PHP\"}},\
But, when I run a whatweb I see:
[200 OK] Cookies[...._session,Path,XSRF-TOKEN], Country[UNITED STATES][US], HTML5, HTTPServer[nginx], HttpOnly[...._session,Path], IP[x.xx.xxx.xx], PHP[7.4.21], PasswordField[password], Strict-Transport-Security[max-age=63072000], Title[......], UncommonHeaders[x-content-type-options], X-Frame-Options[SAMEORIGIN], X-Powered-By[PHP/7.4.21], X-XSS-Protection[1; mode=block], nginx
Inside my nginx I have:
add_header X-Frame-Options "SAMEORIGIN";
add_header X-XSS-Protection "1; mode=block";
add_header X-Content-Type-Options "nosniff";
add_header X-Real-IP "$remote_user";
add_header 'Access-Control-Allow-Origin' $allow_origin;
client_max_body_size 10M;
# RFC 6797
add_header Strict-Transport-Security "max-age=63072000" always;
set_real_ip_from 172.18.0.0/24;
real_ip_header X-Forwarded-For;
# Disallow
add_header Set-Cookie "Path=/; HttpOnly; Secure";
# Remove info disclosure
server_tokens off;
# SWEET32 - TLSv1.2 defualt enabled
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers off;
But only certain headers are taking effect on certain files and I really can't work out what I'm doing wrong to just try and remove the server tokens and add my custom security headers. Any help appreciated.