]> Frank Brehm's Git Trees - pixelpark/hiera.git/commitdiff
fbb-www - create cdm vHost and move some Headers
authorPhilipp Dallig <philipp.dallig@pixelpark.com>
Thu, 13 Jul 2017 09:36:16 +0000 (11:36 +0200)
committerPhilipp Dallig <philipp.dallig@pixelpark.com>
Thu, 13 Jul 2017 09:36:16 +0000 (11:36 +0200)
customer/fbb-www/production.yaml
customer/fbb-www/test.yaml

index 75197dfb4f2ef603f43a103610bab50312e54b06..51dcde9c857ef5450db57e82d07de2e23789b3b9 100644 (file)
@@ -186,6 +186,13 @@ infra::profile::apache::pp_vhosts:
     ssl: false
     docroot_owner: apache
     docroot_group: apache
+    setenvif:
+      - 'HTTPS on X-Forwarded-Proto=https'
+      - 'HTTPS on HTTPS=on'
+    headers:
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
   download-berlin-airport:
     docroot: '/var/www/download-berlin-airport'
     servername: download.berlin-airport.de
@@ -200,6 +207,13 @@ infra::profile::apache::pp_vhosts:
     docroot_owner: web
     docroot_group: fbb
     docroot_mode: '0775'
+    setenvif:
+      - 'HTTPS on X-Forwarded-Proto=https'
+      - 'HTTPS on HTTPS=on'
+    headers:
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
   media-berlin-airport:
     docroot: '/var/www/media-berlin-airport'
     servername: media.berlin-airport.de
@@ -209,6 +223,13 @@ infra::profile::apache::pp_vhosts:
     ssl: false
     docroot_owner: presse.upload
     docroot_group: fbb
+    setenvif:
+      - 'HTTPS on X-Forwarded-Proto=https'
+      - 'HTTPS on HTTPS=on'
+    headers:
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
   domain-catcher:
     ssl: false
     default_vhost: true
@@ -479,6 +500,24 @@ infra::profile::apache::pp_vhosts:
         rewrite_rule:
           - '^/.*$ http://www.berlin-airport.de/de/ [R=301,NE,L]'
 
+  cdm-berlin-airport:
+    docroot: '/var/www/cdm-berlin-airport'
+    servername: cdm.berlin-airport.de
+    serveraliases:
+      - cdm01.berlin-airport.de
+      - cdm02.berlin-airport.de
+    ssl: false
+    docroot_owner: apache
+    docroot_group: apache
+    #wird benoetigt weil die docroot auf einen symlink zeigt
+    manage_docroot: false
+    setenvif:
+      - 'HTTPS on X-Forwarded-Proto=https'
+      - 'HTTPS on HTTPS=on'
+    headers:
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
   berlin-airport:
     docroot: '/var/www/berlin-airport'
     servername: prd-www-fbb.pixelpark.net
index 0d31b978957940a1511a01f4fa59b2fd5336b0b8..60483cfbe9c602e0c78004baf28a7549a7a4bfdc 100644 (file)
@@ -266,6 +266,13 @@ infra::profile::apache::pp_vhosts:
     ssl: false
     docroot_owner: apache
     docroot_group: apache
+    setenvif:
+      - 'HTTPS on X-Forwarded-Proto=https'
+      - 'HTTPS on HTTPS=on'
+    headers:
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
   download-berlin-airport:
     docroot: '/var/www/download-berlin-airport'
     servername: tstdownload.berlin-airport.de
@@ -280,6 +287,13 @@ infra::profile::apache::pp_vhosts:
     docroot_owner: web
     docroot_group: fbb
     docroot_mode: '0775'
+    setenvif:
+      - 'HTTPS on X-Forwarded-Proto=https'
+      - 'HTTPS on HTTPS=on'
+    headers:
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
   media-berlin-airport:
     docroot: '/var/www/media-berlin-airport'
     servername: tstmedia.berlin-airport.de
@@ -289,6 +303,24 @@ infra::profile::apache::pp_vhosts:
     ssl: false
     docroot_owner: presse.upload
     docroot_group: fbb
+  cdm-berlin-airport:
+    docroot: '/var/www/cdm-berlin-airport'
+    servername: tstcdm.berlin-airport.de
+    serveraliases:
+      - tstcdm01.berlin-airport.de
+      - tstcdm02.berlin-airport.de
+    ssl: false
+    docroot_owner: apache
+    docroot_group: apache
+    #wird benoetigt weil die docroot auf einen symlink zeigt
+    manage_docroot: false
+    setenvif:
+      - 'HTTPS on X-Forwarded-Proto=https'
+      - 'HTTPS on HTTPS=on'
+    headers:
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
   berlin-airport:
     docroot: '/var/www/berlin-airport'
     servername: tst-www-fbb.pixelpark.net