diff --git a/.kontinuous/values.yaml b/.kontinuous/values.yaml index 9914ee8d8..01d1aecde 100644 --- a/.kontinuous/values.yaml +++ b/.kontinuous/values.yaml @@ -4,13 +4,13 @@ app: containerPort: 3000 imagePackage: app # implicit probesPath: /api/healthz - ingress: - annotations: - nginx.ingress.kubernetes.io/configuration-snippet: | - more_set_headers "Content-Security-Policy: default-src 'none'; connect-src 'self' https://*.gouv.fr; font-src 'self'; img-src 'self'; prefetch-src 'self' https://*.gouv.fr; script-src 'self' https://*.gouv.fr; frame-src 'self' https://*.gouv.fr; style-src 'self' 'unsafe-inline'"; - more_set_headers "X-Frame-Options: deny"; - more_set_headers "X-XSS-Protection: 1; mode=block"; - more_set_headers "X-Content-Type-Options: nosniff"; + # ingress: + # annotations: + # nginx.ingress.kubernetes.io/configuration-snippet: | + # more_set_headers "Content-Security-Policy: default-src 'none'; connect-src 'self' https://*.gouv.fr; font-src 'self'; img-src 'self'; prefetch-src 'self' https://*.gouv.fr; script-src 'self' https://*.gouv.fr; frame-src 'self' https://*.gouv.fr; style-src 'self' 'unsafe-inline'"; + # more_set_headers "X-Frame-Options: deny"; + # more_set_headers "X-XSS-Protection: 1; mode=block"; + # more_set_headers "X-Content-Type-Options: nosniff"; jobs: runs: