Skip to content

Commit 3b85996

Browse files
Enforce a Strict SameSite policy on SALT API
1 parent dfd8271 commit 3b85996

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

salt/metalk8s/addons/ui/deployed/ingress.sls

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,11 @@ metadata:
2828
nginx.ingress.kubernetes.io/rewrite-target: '/$2'
2929
nginx.ingress.kubernetes.io/use-regex: "true"
3030
nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
31+
# Add strict SameSite policy for Salt API
32+
nginx.ingress.kubernetes.io/configuration-snippet: |
33+
if ($proxy_host = "salt-api") {
34+
proxy_cookie_path / "/; SameSite=Strict; HttpOnly; Secure";
35+
}
3136
spec:
3237
ingressClassName: "nginx-control-plane"
3338
rules:

0 commit comments

Comments
 (0)