All snippets

Caddy

Security headers in Caddy

Place the header block inside your site block. Review each policy against the features your site needs before deploying it.

example.com {
    encode zstd gzip

    header {
        X-Content-Type-Options nosniff
        X-Frame-Options DENY
        Referrer-Policy strict-origin-when-cross-origin
        Permissions-Policy "camera=(), microphone=(), geolocation=()"
        -Server
    }

    reverse_proxy app:3000
}