NAME

IO::K8s::Traefik::V1alpha1::Headers - Headers holds the headers middleware configuration.

VERSION

version 1.108

accessControlAllowCredentials

AccessControlAllowCredentials defines whether the request can include user credentials.

accessControlAllowHeaders

AccessControlAllowHeaders defines the Access-Control-Request-Headers values sent in preflight response.

accessControlAllowMethods

AccessControlAllowMethods defines the Access-Control-Request-Method values sent in preflight response.

accessControlAllowOriginList

AccessControlAllowOriginList is a list of allowable origins. Can also be a wildcard origin "*".

accessControlAllowOriginListRegex

AccessControlAllowOriginListRegex is a list of allowable origins written following the Regular Expression syntax (https://golang.org/pkg/regexp/).

accessControlExposeHeaders

AccessControlExposeHeaders defines the Access-Control-Expose-Headers values sent in preflight response.

accessControlMaxAge

AccessControlMaxAge defines the time that a preflight request may be cached.

addVaryHeader

AddVaryHeader defines whether the Vary header is automatically added/updated when the AccessControlAllowOriginList is set.

allowedHosts

AllowedHosts defines the fully qualified list of allowed domain names.

browserXssFilter

BrowserXSSFilter defines whether to add the X-XSS-Protection header with the value 1; mode=block.

contentSecurityPolicy

ContentSecurityPolicy defines the Content-Security-Policy header value.

contentSecurityPolicyReportOnly

ContentSecurityPolicyReportOnly defines the Content-Security-Policy-Report-Only header value.

contentTypeNosniff

ContentTypeNosniff defines whether to add the X-Content-Type-Options header with the nosniff value.

customBrowserXSSValue

CustomBrowserXSSValue defines the X-XSS-Protection header value. This overrides the BrowserXssFilter option.

customFrameOptionsValue

CustomFrameOptionsValue defines the X-Frame-Options header value. This overrides the FrameDeny option.

customRequestHeaders

CustomRequestHeaders defines the header names and values to apply to the request.

customResponseHeaders

CustomResponseHeaders defines the header names and values to apply to the response.

featurePolicy

Deprecated: FeaturePolicy option is deprecated, please use PermissionsPolicy instead.

forceSTSHeader

ForceSTSHeader defines whether to add the STS header even when the connection is HTTP.

frameDeny

FrameDeny defines whether to add the X-Frame-Options header with the DENY value.

hostsProxyHeaders

HostsProxyHeaders defines the header keys that may hold a proxied hostname value for the request.

isDevelopment

IsDevelopment defines whether to mitigate the unwanted effects of the AllowedHosts, SSL, and STS options when developing. Usually testing takes place using HTTP, not HTTPS, and on localhost, not your production domain. If you would like your development environment to mimic production with complete Host blocking, SSL redirects, and STS headers, leave this as false.

permissionsPolicy

PermissionsPolicy defines the Permissions-Policy header value. This allows sites to control browser features.

publicKey

PublicKey is the public key that implements HPKP to prevent MITM attacks with forged certificates.

referrerPolicy

ReferrerPolicy defines the Referrer-Policy header value. This allows sites to control whether browsers forward the Referer header to other sites.

sslForceHost

Deprecated: SSLForceHost option is deprecated, please use RedirectRegex instead.

sslHost

Deprecated: SSLHost option is deprecated, please use RedirectRegex instead.

sslProxyHeaders

SSLProxyHeaders defines the header keys with associated values that would indicate a valid HTTPS request. It can be useful when using other proxies (example: "X-Forwarded-Proto": "https").

sslRedirect

Deprecated: SSLRedirect option is deprecated, please use EntryPoint redirection or RedirectScheme instead.

sslTemporaryRedirect

Deprecated: SSLTemporaryRedirect option is deprecated, please use EntryPoint redirection or RedirectScheme instead.

stsIncludeSubdomains

STSIncludeSubdomains defines whether the includeSubDomains directive is appended to the Strict-Transport-Security header.

stsPreload

STSPreload defines whether the preload flag is appended to the Strict-Transport-Security header.

stsSeconds

STSSeconds defines the max-age of the Strict-Transport-Security header. If set to 0, the header is not set.

SUPPORT

Issues

Please report bugs and feature requests on GitHub at https://github.com/pplu/io-k8s-p5/issues.

CONTRIBUTING

Contributions are welcome! Please fork the repository and submit a pull request.

AUTHORS

  • Torsten Raudssus <getty@cpan.org>

  • Jose Luis Martinez Torres <jlmartin@cpan.org>

COPYRIGHT AND LICENSE

This software is Copyright (c) 2018-2026 by Jose Luis Martinez Torres <jlmartin@cpan.org>.

This is free software, licensed under:

The Apache License, Version 2.0, January 2004